Position Summary
About Redaptive :
Redaptive helps large companies modernize their infrastructure with no upfront capital. We fund and execute energy and equipment upgrades across their real estate portfolios, then measure the results so they can reinvest savings into growth. We call it Infrastructure Monetization.
Our company culture is exciting, collaborative, and fast paced. We are passionate about changing the world and helping our customers become more environmentally sustainable and profitable. From decarbonizing facilities to modernizing critical infrastructure, our work delivers measurable impact for our customers, communities, and the planet. We are looking for team members who are driven, passionate, and want to take on a diverse set of challenges to help grow a great company.
Founded in 2015 and headquartered in Denver, Colorado, Redaptive is comprised of over 350 employees and operates across 12,000+ sites in over 10 countries. Redaptive, Inc. is an equal employment opportunity employer, and all qualified applicants will receive consideration for employment. For more information, visit www.redaptive.com.
Redaptive is seeking a highly skilled Cloud Security Specialist to join our team in Pune. This critical position offers an exceptional opportunity to shape and lead Redaptive's cloud security strategy while working with cutting-edge technologies in a dynamic, mission-driven organization. The ideal candidate will combine technical expertise with a collaborative approach to embed security throughout our cloud infrastructure and development processes.
Responsibilities And Duties
AWS Security Architecture & Strategy :
- Design and implement comprehensive security architectures for Redaptive's AWS cloud environments
- Develop cloud security roadmaps aligned with business objectives and compliance requirements
- Establish security standards, policies, and procedures for AWS deployments
- Evaluate and recommend security enhancements to strengthen the cloud security posture
- Lead security aspects of cloud migration initiatives and new AWS service adoptions
- Implement zero-trust security principles in cloud architecture designs
- Provide expert guidance on AWS security best practices to stakeholders across the organization
- Establish metrics to measure the effectiveness of cloud security controls
Security Automation & CI / CD Integration
Develop and maintain security as code implementations for AWS environmentsIntegrate security controls and checks into CI / CD pipelinesAutomate security scanning, compliance verification, and remediation processesImplement infrastructure as code (IaC) security practices for AWS CloudFormation and TerraformCreate automated security testing frameworks for cloud resourcesDevelop custom security rules and policies for automated enforcementCollaborate with DevOps teams to ensure security requirements are met throughout the development lifecycleDesign and implement automated incident response playbooks for cloud security eventsCloud Security Monitoring & Operations
Configure and manage cloud security monitoring solutions including AWS Security Hub, GuardDuty, and CloudTrailImplement and tune cloud-native SIEM solutions for comprehensive security visibilityDevelop and maintain cloud security dashboards and reporting mechanismsPerform advanced cloud security investigations and threat huntingRespond to and remediate cloud security incidentsConduct cloud security posture assessments and vulnerability managementImplement and manage cloud security logging and audit mechanismsDevelop and maintain cloud security incident response proceduresIdentity & Access Management
Design and implement AWS IAM policies, roles, and permission boundaries following least privilege principlesDevelop automated solutions for identity lifecycle management in cloud environmentsImplement and manage privileged access management for AWS resourcesConfigure and maintain AWS Single Sign-On and federation with corporate identity providersDesign and implement secure service-to-service authentication mechanismsConduct regular access reviews and implement automated compliance checksDevelop and maintain IAM security frameworks and governance processesImplement automated detection and remediation of IAM policy violationsCompliance & Risk Management
Ensure AWS environments meet relevant regulatory requirements and industry standards (e.g., SOC 2, ISO 27001, NIST)Develop and implement cloud security compliance frameworks and controlsPerform cloud security risk assessments and develop risk treatment plansLead cloud-focused security aspects of compliance audits and assessmentsImplement technical controls to meet compliance requirementsDevelop and maintain cloud security documentation for compliance purposesDesign and implement data protection controls for regulated information in the cloudPartner with legal and compliance teams on regulatory and contractual security requirementsDevSecOps Collaboration
Work closely with DevOps teams to implement security throughout the cloud deployment lifecycleProvide guidance on secure cloud architecture and configurationDevelop security requirements and acceptance criteria for cloud deploymentsReview infrastructure as code for security considerationsParticipate in sprint planning and retrospectives to integrate security into agile processesConduct security knowledge transfer sessions for development and operations teamsCollaborate on resolving security findings and implementing remediationChampion a DevSecOps culture across the organizationRequired Abilities And Skills
Advanced expertise with AWS security services including GuardDuty, Security Hub, IAM, KMS, and CloudTrailStrong understanding of cloud security frameworks (AWS Well-Architected Framework, NIST CSF, CSA CCM)Hands-on experience implementing security controls in CI / CD pipelinesExpert knowledge of infrastructure as code (IaC) security for AWS CloudFormation and / or TerraformExperience with cloud security posture management (CSPM) tools and processesStrong understanding of identity and access management principles in cloud environmentsExperience with automated security testing and continuous security validationProficiency in scripting and programming (Python, Bash, etc.) for security automationExcellent understanding of network security, containerization security, and serverless securityIn-depth knowledge of DevSecOps principles and practicesExcellent written and verbal communication skillsPreferred Abilities And Skills
Experience with multi-cloud security strategies and implementationsKnowledge of regulatory compliance requirements relevant to cloud environmentsExperience with container security (Docker, Kubernetes, ECS, EKS)Background in implementing Zero Trust architecture in AWS environmentsExperience with AWS automated incident response and remediationKnowledge of cloud-native security tools and platformsExperience with Hashicorp Vault or similar secrets management solutionsBackground in implementing security for data lakes and analytics platformsExperience with cloud workload protection platforms (CWPP)Knowledge of serverless security best practicesExperience with cloud security in the energy efficiency or sustainability industriesBackground in threat modeling for cloud architecturesExperience working with global teams and offshore development modelsEducation Requirements
Bachelor's degree in Cybersecurity, Computer Science, or related field; Master's degree preferredMinimum of 7+ years of experience in cybersecurity, with at least 5 years focused on cloud securityRelevant security certifications (AWS Certified Security - Specialty, CCSP, CISSP, or equivalent)Travel
0% of travel time expected for the position, where the travel occurs, such as locally or in specific countries or states, and whether the travel is overnight.
The Perks!
Equity plan participationMedical and Personal Accident InsuranceSupport on Hybrid working – Equipment & RelocationFlexible Time OffContinuous LearningAnnual bonus, subject to company and individual performanceThe company is an Equal Opportunity Employer, drug free workplace, and complies with Labor Laws as applicable. All duties and responsibilities are essential functions and requirements and are subject to possible modification to reasonably accommodate individuals with disabilities. The requirements listed in this document are the minimum levels of knowledge, skills, or abilities.
Redaptive is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees.
Skills Required
Network Security