Talent.com
FIL India Business and Research Services Private
Fidelity International - Cloud Security Engineer - iAMFIL India Business and Research Services Private • Bangalore
Fidelity International - Cloud Security Engineer - iAM

Fidelity International - Cloud Security Engineer - iAM

FIL India Business and Research Services Private • Bangalore
24 days ago
Job description

Job Description :

We are seeking an experienced Cloud Security Engineer to join our Enterprise Engineering team and play a key role in securing our cloud-native platforms and enterprise infrastructure. This position is responsible for designing, implementing, and maintaining security controls across multi-cloud environments while ensuring that security is embedded throughout the software development lifecycle.

As a Cloud Security Engineer, you will partner with Cloud Engineering, DevOps, Platform Engineering, Infrastructure, Architecture, and Application Development teams to implement security-by-design principles, strengthen cloud governance, and protect enterprise workloads deployed across AWS, Microsoft Azure, and Google Cloud Platform (GCP).

The ideal candidate will have strong expertise in cloud security architecture, DevSecOps, identity and access management, container security, Kubernetes, CI/CD security, infrastructure as code, and security automation.

Key Responsibilities :

- Design, implement, and maintain enterprise cloud security architectures across AWS, Microsoft Azure, and Google Cloud Platform (GCP).

- Develop and enforce cloud security standards, policies, and best practices aligned with enterprise security requirements.

- Integrate security controls into cloud-native application development and DevSecOps pipelines.

- Build and automate security controls across infrastructure, applications, containers, and Kubernetes platforms.

- Collaborate with engineering teams to embed security throughout the Software Development Life Cycle (SDLC).

- Perform cloud security architecture reviews and provide security recommendations for new applications and services.

- Design and implement Identity and Access Management (IAM) strategies, including least privilege access, role-based access control (RBAC), and privileged access management.

- Secure Kubernetes clusters and containerized workloads by implementing runtime protection, image scanning, and policy enforcement.

- Review and secure Infrastructure as Code (IaC) deployments using Terraform, ARM, CloudFormation, or similar technologies.

- Implement cloud-native security services, including encryption, key management, secrets management, logging, and monitoring.

- Configure and manage cloud security tools such as AWS Security Hub, Azure Defender/Microsoft Defender for Cloud, GuardDuty, Azure Sentinel, Security Command Center, and related services.

- Identify cloud security risks through continuous assessments, vulnerability scanning, and configuration reviews.

- Perform threat modeling and security risk assessments for cloud applications and infrastructure.

- Implement security monitoring, alerting, and incident response capabilities across cloud environments.

- Investigate and remediate cloud security incidents, vulnerabilities, and misconfigurations.

- Support compliance initiatives by ensuring adherence to security standards and regulatory requirements.

- Collaborate with governance, risk, and compliance teams during security audits.

- Develop security dashboards, metrics, and reporting for engineering and leadership teams.

- Mentor engineering teams on secure cloud development and security best practices.

- Stay updated with evolving cloud security technologies, emerging threats, and industry standards.

Required Skills :

- Strong experience securing enterprise cloud environments on AWS, Microsoft Azure, and Google Cloud Platform (GCP).

- Hands-on expertise in Cloud Security Architecture and Cloud Security Engineering.

- Strong understanding of cloud networking concepts, including Virtual Networks (VPC/VNet), subnets, routing, VPNs, load balancers, and firewalls.

- Expertise in Identity and Access Management (IAM), Multi-Factor Authentication (MFA), Single Sign-On (SSO), and Role-Based Access Control (RBAC).

- Experience implementing DevSecOps practices and integrating security into CI/CD pipelines.

- Hands-on experience with container security and Kubernetes security.

- Experience with Docker, Kubernetes, and container orchestration security.

- Strong understanding of Infrastructure as Code (Terraform, AWS CloudFormation, Azure ARM/Bicep).

- Experience implementing cloud logging, monitoring, and security observability.

- Familiarity with Cloud Security Posture Management (CSPM) and Cloud Workload Protection Platforms (CWPP).

- Knowledge of vulnerability management, penetration testing remediation, and security hardening.

- Experience implementing encryption, key management, certificate management, and secrets management.

- Strong scripting skills using PowerShell, Python, Bash, or similar languages.

- Experience with security governance, compliance, and cloud security frameworks.

- Excellent analytical, troubleshooting, and problem-solving skills.

Technical Skills :

1. Cloud Platforms :

- Amazon Web Services (AWS)

- Kubernetes

- Docker

- Kubernetes Security

- Container Security

2. DevSecOps :

- CI/CD Security

- GitHub Actions

- Azure DevOps

- Jenkins

3. Infrastructure & Automation :

- Terraform

- AWS CloudFormation

- Azure ARM/Bicep

- Infrastructure as Code (IaC)

- Python

- PowerShell

- Bash

4. Security Tools :

- AWS Security Hub

- Amazon GuardDuty

- Prisma Cloud (preferred)

- Wiz (preferred)

5. Monitoring & Compliance :

- SIEM

Preferred Qualifications :

- Bachelor's or Master's degree in Computer Science, Cyber Security, Information Technology, Engineering, or a related discipline.

- Professional certifications such as :

1. AWS Certified Security Specialty

2. Microsoft Certified : Azure Security Engineer Associate (AZ-500)

3. Google Professional Cloud Security Engineer

4. Certified Information Systems Security Professional (CISSP)

5. Certified Cloud Security Professional (CCSP)

6. Certified Kubernetes Security Specialist (CKS)

7. CompTIA Security+ (preferred)

- Experience working within large enterprise or financial services environments.

- Exposure to modern cloud-native architectures, microservices, and platform engineering.

Soft Skills :

- Strong analytical and critical thinking abilities.

- Excellent communication and stakeholder management skills.

- Ability to influence engineering teams on secure development practices.

- Strong collaboration and cross-functional teamwork.

- High attention to detail and commitment to security excellence.

- Ability to manage multiple priorities in a fast-paced environment.

- Continuous learning mindset with a passion for emerging cloud security technologies.

(ref:hirist.tech)
Create a job alert for this search

Fidelity International - Cloud Security Engineer - iAM • Bangalore

Similar jobs

Cyber Security Engineer

Novo NordiskBengaluru, Republic Of India, IN

Key responsibilities Performing regional internal audit in compliance with ISO/IEC 27001 (ISMS) requirements Planning, organizing and reviewing all Information Security Management System (ISMS) rel... Show more

 • Promoted

Engineer, Information Security_iam_keycloak_fullstack

ABBBengaluru, Republic Of India, IN

At ABB, we help industries run leaner and cleaner—and every person here makes that happen.You’ll be empowered to lead, supported to grow, and proud of the impact we create together.Join us and help... Show more