Key Responsibilities
Evaluate cloud configurations and governance across AWS, Azure, and GCP.
Assess minimum security baselines and control effectiveness in multi-cloud environments.
Support audit walkthroughs and evidence validation for serverless functions (AWS Lambda, Azure Functions), container platforms (EKS / AKS), and services like S3, RDS.
Interpret CI / CD pipeline configurations and DevSecOps tooling (e.g., Jenkins, Harness, Snyk, HashiCorp Vault).
Collaborate with architecture and engineering teams to validate control designs and remediation actions.
Review IAM roles, network segmentation, and API security controls.
Contribute to audit planning, issue verification, and management response drafting.
Required Skills & Experience
8-12 Years of experience in across cloud platforms, security architecture, and DevSecOps practices, with a strong understanding of audit lifecycle and regulatory alignment.
Hands-on experience with cloud-native technologies and multi-cloud strategy.
Strong grasp of DevSecOps principles, CI / CD pipelines, and secure deployment practices.
Familiarity with audit frameworks, control testing, and regulatory compliance.
Exposure to cloud oversight dashboards, conformance packs, and security assurance methodologies (e.g., CSAM).
Ability to interpret technical artefacts and communicate findings to audit and business stakeholders.
Internal Audit • Gurgaon, Haryana, India