Role : Cloud Security Specialist (Vulnerability & Risk Management)
Location : Bangalore (Hybrid)
Experience : 7-10 the Role :
We are looking for a proactive and detail-oriented Cloud Security Specialist to join our InfoSec team. The candidate will focus on detecting vulnerabilities and misconfigurations across AWS and other cloud environments, ensuring they are remediated by respective teams within defined SLAs. This role emphasizes visibility, governance, and collaboration rather than hands-on implementation.
Key Responsibilities :
- Monitor and manage vulnerabilities and configuration findings from CSPM tools (e.g., Wiz (preferred), Prisma Cloud, AWS Security Hub).
- Collaborate with DevOps and cloud engineering teams to implement secure cloud configurations, including IAM policies, encryption, logging, and monitoring tools.
- Collaborate with DevOps, Infra, and Application teams to drive timely remediation.
- Establish preventative guardrails and IaC controls to reduce risk at a deployment stage.
- Partner with infrastructure, application, and DevOps teams to track and close findings within defined SLAs
- Track, document, and report risk status and closure metrics.
- Identify patterns or recurring misconfigurations and recommend preventive controls.
- Support compliance and audit requirements through accurate risk reporting.
- Communicate effectively with senior stakeholders and provide clear risk articulation.
Required Skills :
Hands-on experience in AWS Cloud Security (understanding IAM, S3, EC2, VPC, Security Groups, etc.)Working knowledge of CSPM tools and vulnerability management tools (e.g., Wiz, Qualys, Tenable).Proficiency with infrastructure-as-code (IaC) security.Strong understanding of security best practices for cloud environments.Excellent communication, stakeholder management, and presentation skills.Experience driving cross-team collaboration and tracking remediation to closure.Good understanding of CI / CD, DevOps, CloudOpsStrong project management skills and experience in managing security projects, including planning, execution, monitoring, and reporting on project progress and outcomes.Nice to Have :
Familiarity with GCP or Azure cloud environments.Basic scripting (Python / PowerShell) for automation or reporting.AWS Security Specialty or CCSP certification.Focus area :
Detecting vulnerabilities and cloud misconfigurations (not implementing controls directly).Working with stakeholders (Cloud, DevOps, Application teams) to ensure remediation is completed.Driving governance, reporting, and closure tracking.Environment : Multi-cloud (primarily AWS)Tools : CSPM tools (like Wiz (preferred), Prisma Cloud, Defender for Cloud, etc.)
Soft skills : Strong communication, proactive attitude, stakeholder management (especially Senior / C level)
(ref : hirist.tech)