We are seeking a skilled Cloud Security Engineer with Application Security expertise to join our security architecture team. This role focuses on designing, implementing, and maintaining secure cloud environments and applications across cloud platforms, with a strong emphasis on Azure. The ideal candidate will have experience with cloud-native security tools, DevSecOps, and compliance frameworks.
Requirements
- Design and implement security controls for cloud infrastructure (Azure, AWS, GCP).
- Develop and maintain security architecture patterns (e.g., hub-and-spoke, Zero Trust).
- Integrate security tools such as Wiz, Microsoft Defender for Cloud, Silverfort, and Terraform.
- Conduct threat modeling and risk assessments for cloud-native services.
- Collaborate with IAM, SOC, and GRC teams to align cloud security with enterprise policies.
- Perform secure code reviews, static/dynamic analysis, and vulnerability assessments.
- Integrate security into CI/CD pipelines using tools like Snyk, Checkmarx, or Veracode.
- Guide development teams on secure coding practices and OWASP Top 10.
- Design and implement API security strategies including OAuth2, OpenID Connect, and mTLS.
- Support remediation of application vulnerabilities and provide technical guidance.
- Map cloud and application security controls to compliance frameworks (NIST 800-53, SOC 2, CIS).
- Assist in audits and evidence collection for regulatory compliance.
- Maintain documentation of security architecture, policies, and procedures.