Job Title : AWS Cloud Security Engineer
Location : Bangalore (Hybrid – 3 days in office)
Experience Required : 5+ years
Role Overview
We are seeking a dedicated AWS Cloud Security Engineer to bolster our Network Security and Technology Risk team in Bangalore. In this position, you will be pivotal in securing our AWS cloud infrastructure, ensuring compliance, enabling secure deployment, and driving automation to scale security effectively. Your expertise will guide the organization in navigating evolving cloud threats while championing DevSecOps practices.
Key Responsibilities
- Design, implement, and maintain robust security controls and best practices within AWS environments.
- Integrate security into CI / CD pipelines using DevSecOps methodologies, including SAST / DAST scans and automated pipelines enforcement.
- Identify, assess, and resolve cloud misconfigurations, and facilitate corrective remediation with relevant teams.
- Leverage infrastructure-as-code (Terraform, CloudFormation) to manage secure deployments and enforce guardrails.
- Participate in vulnerability management through tools like CSPM (Cloud Security Posture Management) and adhere to frameworks like CIS, AWS Well-Architected, and NIST.
- Automate security tasks using scripting languages (Python, Go, Bash) to improve repeatability and reliability.
- Maintain and audit IAM policies, roles, and segmentation to uphold least privilege principles.
- Respond to security incidents and conduct regular compliance assessments and remediation tracking.
Qualifications & Expertise
Experience : 5+ years in cloud security, with deep hands-on experience in AWS.Certifications (desired) :AWS Certified Security – SpecialtyAWS Certified Solutions Architect or DevOps EngineerTechnical Skills :Infrastructure as Code : Terraform, CloudFormationDevSecOps : CI / CD integration, security scanning (SAST / DAST)Security frameworks & tools : CIS Benchmarks, CSPM, AWS Well-ArchitectedScripting : Python, Go, BashNetworking & IAM security fundamentalsSoft Skills :Critical thinking, incident response, collaboration with DevOps / security teams.