Job Summary
Cloud security SME
Key Responsibilities
IAM Architecture & Governance: Design, implement, and govern enterprise cloud IAM frameworks across multi-cloud systems. Architect complex role-based access control (RBAC), attribute-based access control (ABAC), and conditional access policies to enforce absolute least-privilege access.Identity Federation & Single Sign-On (SSO): Architect and maintain enterprise directory integrations, hybrid identity synchronization, and SSO implementations using protocols like SAML 2.0, OIDC, and OAuth 2.0 via identity providers (e.g., Okta, Microsoft Entra ID, AWS IAM Identity Center).Cloud Security Posture Management (CSPM): Take technical ownership of cloud security posture tools to continuously monitor infrastructure. Proactively identify, prioritize, and remediate cloud misconfigurations, overly permissive policies, and compliance drifts (CIS Benchmarks, SOC2, ISO 27001).Secrets & Keys Management: Architect enterprise-wide strategies for secrets management, cryptographic key lifecycles, and certificate rotation using cloud-native tools or centralized vaults (e.g., HashiCorp Vault, AWS Secrets Manager, Azure Key Vault).Automated Threat Detection & CIEM: Deploy Cloud Infrastructure Entitlement Management (CIEM) tools to detect anomalies like privilege escalation risks and unused permissions. Integrate cloud security telemetry (e.g., AWS CloudTrail, Azure Activity Logs) into centralized SIEM/SOAR platforms.DevSecOps & Policy as Code: Partner with DevOps teams to integrate identity and security checks directly into the deployment pipeline. Embed security compliance early by authoring automated guardrails using Policy as Code (e.g., Open Policy Agent - OPA, AWS SCPs, Azure Policies).
Skill Requirements
Experience: 8+ years of dedicated professional experience in cybersecurity engineering, with at least 5+ years focusing strictly on cloud security and IAM architecture.Cloud Platform Mastery: Advanced, production-proven experience securing major public cloud infrastructure, specifically AWS, Microsoft Azure, or Google Cloud Platform (GCP).Deep Protocol Knowledge: In-depth engineering mastery of modern identity protocols (OAuth 2.0, SAML, OIDC, SCIM), API security architectures, and JSON/YAML-based policy syntax.Automation & Scripting: Strong capability to automate security configurations and audit tasks using scripting languages such as Python, PowerShell, or Bash, along with Infrastructure as Code (Terraform).Workload Security: Strong understanding of cloud-native computing security basics, including container security, serverless functions, and microservices architecture protection.
Other Requirements
NA