Source description
About the role
Cloud Architecture & Design – Designing secure-by-default cloud architectures and integrations, ensuring all new infrastructure meets rigorous security standards before deployment.
Identity & Access Management (IAM) – Designing and reviewing cloud IAM strategies by defining roles, least-privilege policies, service accounts, and access boundaries across AWS, Azure, and GCP.
Cloud Configuration Hardening – Locking down storage buckets, network security groups, load balancers, databases, and managed services to prevent accidental exposure and ensure compliance.
DevSecOps & CI/CD Security – Securing the software supply chain by reviewing pipeline permissions, secrets handling, and artifact signing to prevent unauthorized deployments to production.
Threat Modeling & Risk Assessment – Conductin threat modeling sessions with architects to identify structural risks (e.g., compromised roles) and defining security requirements for new features.
Security Automation & Policy-as-Code – AWS‑centric security automation by developing Terraform guardrails, enforcing Policy-as-Code through OPA/Conftest and AWS Service Control Policies (SCPs), and building AWS-native auto‑remediation workflows using AWS Config, EventBridge, Lambda, and SSM Automation to ensure continuous compliance and enforcement of cloud security standards.
Security Monitoring & Alert Triage – Managing the intake of alerts from CSPM, SIEM, and cloud-native tools (GuardDuty, Defender, SCC), distinguishing real threats from operational noise.
Cloud Incident Response – Leading investigations into cloud-specific incidents, including compromised credentials, suspicious API calls, crypto-mining activity, or exposed resources.
Vulnerability Management – Running and analyzing scans for cloud workloads (VMs, containers, serverless) and prioritizing remediation based on contextual risk rather than generic CVSS scores.
Logging & Audit Readiness – Ensuring cloud audit logs are enabled, immutable, centralized, and readily available for forensic investigations and compliance audits.
Cross-Functional Advisory – Serving as a subject matter expert for developer, infrastructure, and platform teams, translating complex security requirements into practical, engineering-focused guidance.
More at Cyara
