Key Responsibilities :
Cloud Security Management :
- Design, implement, and manage security controls and policies across AWS, Azure, and GCP environments.
- Continuously assess and enhance the Cloud Security Posture (CSPM) using tools such as Prisma Cloud, Wiz, Orca, Lacework, or Microsoft Defender for Cloud.
- Configure and manage CWPP, CNAPP, and CIEM solutions to ensure comprehensive protection across workloads, identities, and applications.
- Automate cloud security monitoring, alerting, and remediation using Infrastructure as Code (IaC) and policy enforcement tools.
- Integrate security controls within DevOps pipelines (CI / CD) to ensure continuous compliance and secure deployment practices.
Threat Detection & Incident Response :
Monitor cloud infrastructure for security threats, vulnerabilities, and misconfigurations.Support incident detection, investigation, triage, containment, and remediation of cloud-related security events.Collaborate with SOC and Incident Response teams to analyze logs, alerts, and threat intelligence related to cloud activity.Implement security analytics, leveraging tools such as SIEM (Splunk, Sentinel, QRadar) and XDR platforms.Governance, Risk & Compliance :
Ensure compliance with regulatory standards such as ISO 27001, SOC 2, GDPR, PCI-DSS, and NIST frameworks.Define and enforce cloud security policies, IAM best practices, and least privilege principles.Participate in periodic security reviews, risk assessments, and cloud architecture evaluations.Develop and maintain documentation for cloud security standards, architecture diagrams, and incident response playbooks.Continuous Improvement & Collaboration :
Stay current with emerging cloud threats, vulnerabilities, and best practices.Work closely with DevOps, Cloud Engineering, and Application teams to embed security by design.Conduct security awareness sessions and share insights on cloud-native protection strategies.Recommend innovative approaches for improving visibility, automation, and compliance across the cloud ecosystem.Technical Skills & Tools Expertise :
Core Cloud Platforms :
AWS (IAM, Security Hub, GuardDuty, CloudTrail, Config, KMS, Shield) Azure (Security Center, Defender for Cloud, Sentinel, Key Vault, Azure Policy) GCP (Security Command Center, IAM, Cloud Armor, KMS, Cloud Audit Logs)Security Solutions & Frameworks :
Hands-on experience with CSPM, CWPP, CNAPP, and CIEM tools (e.g., Prisma Cloud, Wiz, Orca, Check Point CloudGuard, Lacework).Familiarity with SIEM / SOAR tools (Splunk, Azure Sentinel, IBM QRadar, Chronicle).Experience with DevSecOps tools :
GitHub Actions, Jenkins, Terraform, Ansible, or CloudFormation for policy-as-code and automation.Strong knowledge of identity and access management (IAM), encryption, and key management.Proficiency in network security, VPC design, firewall configuration, and container security (Kubernetes, EKS, AKS, GKE).Scripting & Automation :
Experience in Python, PowerShell, or Bash for automating security workflows.Familiarity with Infrastructure as Code (IaC) tools such as Terraform or CloudFormation for secure provisioning.(ref : hirist.tech)