Join our team as a Senior Cloud Security Engineer in Pune, Maharashtra, India. In this full-time, on-site opportunity, you will be part of the CCoE infrastructure security team. Your responsibilities include participating in AWS and on-premises infrastructure security engineering, conducting security assessments, and implementing mitigation strategies. We are looking for someone with deep expertise in AWS services, scripting skills, and knowledge of container security systems. A Bachelor's Degree in CS, IT, or EE with 3.5-5 years of experience is required.
The Senior Cloud Security Engineer will be part of CCoE infrastructure security team in Pune. As a Senior Cloud Security Engineer, you will participate in AWS and on-premises infrastructure security engineering aspect including various security systems rollouts, review vulnerabilities, conduct various threat analysis and work on mitigation approach strategy. Collaborate with multiple other CCoE, Enterprise and Software Development team/s for security assessment, planning of mitigation approach and implementations.
Responsibilities
- Serve as a cloud security subject matter expert by providing guidance on industry best practices and defense-in-depth strategy.
- Continuously review and improve security and operation control to enforce various aspect of ZS security policies.
- Perform technical risk assessments of new technology and cloud services and ensure the solution meets secure architecture designs.
- Proactively identify issues and recommend configuration settings supporting solutions to mitigate security gaps. Identify automation opportunities and implement them.
- Participate in various internal and external compliance and security assessments like MLPS, SOC2, ISO as needed.
- Participate and own cloud security incident response, in depth investigations and forensic analysis. Drive security incidents investigations and resolution.
- Review and take appropriate action on alerts from internal SIEM tools requiring log correlation, log analysis, identifying malicious behavior, misconfigurations and tracking systems state changes.
- Collaborate closely with Software Development and architecture team to address security vulnerabilities and provide expert recommendations for effective mitigation strategies.
- Review security insights, in-built dashboards and penetration testing results and reports and enact mitigation efforts across all systems.
- Work closely and collaborate with the ZS SOC team for various security operational aspect.
- Update and configure software with the latest patches and security settings to ensure the proper defenses are present.
- Configure security software and tools, analyze security requirements, and recommend improvements.
- Help define, review, and enact security policies and practices.
- Stay apprised of latest AWS security threats, vulnerabilities, industry best practices and proactively make recommendations to improve ZS’s security posture. Conduct PoC and evaluations of new and relevant security tools and services.
- Provide analysis and trending of security log data from heterogeneous security systems and services.
- Review and create SOPs, run books, document sophisticated security processes and guidelines, contributing to the development of comprehensive security policies and standards specific to AWS.
- Train and mentor juniors in the team, encourage and develop security mindset.
Qualifications:
- Bachelor's Degree in CS, IT or EE with record of high academic achievement
- 3.5-5 years of experience in Cloud Security Engineering
- AWS certification like AWS Certified Solutions Architect and AWS Certified Security – Specialty is preferred.
- Deep expertise and knowledge of AWS services (Security Hub, Inspector, Guard duty, Shield, AWS WAF, Config, Cognito, Secrets Manager, Certificate Manager, KMS, IAM, VPC, CloudFront, Elastic Load Balancer etc.). Should have knowledge of container security systems like Sysdig or Prisma.
- Must have experience in scripting using Python, Boto3, PowerShell, Bash/Shell.
- Deep working experience in scaled AWS environments and exposure to multiple AWS services
- Good understanding and knowledge of Web Applications and cloud hosting architecture including server based, serverless and containers.
- Good knowledge of CI/CD tools like JetBrains TeamCity, SVN, Bitbucket etc.
- Good knowledge of Windows and Linux operating system administration.
- Good understanding of containerization and orchestration technologies like Docker, EKS and ECS.
- Basic knowledge of RDBMS and database technologies like SQL server, PostgreSQL.
- Basic knowledge of web server software like IIS or Apache Tomcat
- Knowledge of DevOps methodology
- Experience of working in ITIL based environment