Source description
About the role
Core Responsibilities 1. Cloud Security Architecture & Governance Strategy & Compliance: Define and implement the multi-cloud security strategy, policies, and standards aligned with BFSI regulations and frameworks like NIST CSF, ISO 27001, and CSA CCM. Cloud Security Implementation: Architect and manage security controls across AWS and GCP, leveraging native services and third-party tools. Technology Leadership: Implement and optimize core cloud security technologies: IAM, Encryption, CASB, NSG/Cloud Firewalls, and SIEM correlation. Advanced Controls: Evaluate, deploy, and manage advanced cloud solutions, including CNAPP, Zero Trust Architecture, and Cloud Workload Protection for all environments (native and lift & shift). Automation: Drive security automation initiatives across cloud infrastructure-as- code (IaC) and network provisioning. 2. Secure Design Review (SDR) & Assurance Secure Design Reviews: Lead mandatory technical design reviews and security assessments across the entire project lifecycle, specifically covering: o BRD/PRD (Business/Product Requirements): Review for inherent security risks and ensure security and privacy requirements are explicitly captured (e.g., non-repudiation, data retention limits). o FRS/BRS (Functional/Business Requirements): Validate that defined business logic prevents misuse cases and meets compliance requirements. o HLD (High-Level Design): Review the overall system architecture, including cloud resource selection, service segmentation, and regional deployment strategy for data residency compliance. o DFD (Data Flow Diagrams): Analyze data flows to ensure sensitive data is protected at every transition point (in-transit encryption, secure APIs, tokenization). Threat Modeling: Execute structured Threat Modeling (e.g., using STRIDE) during the design phase to proactively identify and mitigate architectural risks and fraud vectors. DevSecOps Integration: Act as the primary security gate, embedding security requirements into the SDLC and DevSecOps pipeline. Provide prescriptive guidance on secure coding, tokenization, data masking, and cryptographic controls. Risk Sign-Off: Document all identified design risks and mitigation plans, providing the mandatory security sign-off before UAT or production go-live. 3. Leadership & Stakeholder Management Team Leadership: Lead, mentor, and guide the Information Security team members focused on cloud technologies and security assurance. Reporting: Communicate cloud security posture, design risks, and project progress effectively to the CISO. Oversight: Responsible for overall management and coordination of all cloud security and SDR-related projects. Required Skills & Qualifications Experience: Minimum 6+ years of progressive experience in Information Security, including 4+ years of core experience in Cloud Security and Secure Design/Architecture roles within the BFSI sector. Technical Expertise: Deep, hands-on knowledge of security across AWS, Azure, and GCP. Expertise in application security, API security, and securing high-value financial platforms. Certifications (Highly Desirable): CSSLP, CCSP, or relevant AWS/Azure/GCP Security Specialty certifications. Skills: Exceptional analytical skills, experience translating complex BFSI regulatory risks into actionable technical controls, and strong executive communication abilities.
More at AXIS DIRECT