Padmi

Cloud SDR (Security Design Review)

MumbaiPosted 1 month ago
CybersecuritySenior
Apply at AXIS DIRECT

Opens the source posting on naukri.com

Source description

About the role

View original

Core Responsibilities 1. Cloud Security Architecture & Governance Strategy & Compliance: Define and implement the multi-cloud security strategy, policies, and standards aligned with BFSI regulations and frameworks like NIST CSF, ISO 27001, and CSA CCM. Cloud Security Implementation: Architect and manage security controls across AWS and GCP, leveraging native services and third-party tools. Technology Leadership: Implement and optimize core cloud security technologies: IAM, Encryption, CASB, NSG/Cloud Firewalls, and SIEM correlation. Advanced Controls: Evaluate, deploy, and manage advanced cloud solutions, including CNAPP, Zero Trust Architecture, and Cloud Workload Protection for all environments (native and lift & shift). Automation: Drive security automation initiatives across cloud infrastructure-as- code (IaC) and network provisioning. 2. Secure Design Review (SDR) & Assurance Secure Design Reviews: Lead mandatory technical design reviews and security assessments across the entire project lifecycle, specifically covering: o BRD/PRD (Business/Product Requirements): Review for inherent security risks and ensure security and privacy requirements are explicitly captured (e.g., non-repudiation, data retention limits). o FRS/BRS (Functional/Business Requirements): Validate that defined business logic prevents misuse cases and meets compliance requirements. o HLD (High-Level Design): Review the overall system architecture, including cloud resource selection, service segmentation, and regional deployment strategy for data residency compliance. o DFD (Data Flow Diagrams): Analyze data flows to ensure sensitive data is protected at every transition point (in-transit encryption, secure APIs, tokenization). Threat Modeling: Execute structured Threat Modeling (e.g., using STRIDE) during the design phase to proactively identify and mitigate architectural risks and fraud vectors. DevSecOps Integration: Act as the primary security gate, embedding security requirements into the SDLC and DevSecOps pipeline. Provide prescriptive guidance on secure coding, tokenization, data masking, and cryptographic controls. Risk Sign-Off: Document all identified design risks and mitigation plans, providing the mandatory security sign-off before UAT or production go-live. 3. Leadership & Stakeholder Management Team Leadership: Lead, mentor, and guide the Information Security team members focused on cloud technologies and security assurance. Reporting: Communicate cloud security posture, design risks, and project progress effectively to the CISO. Oversight: Responsible for overall management and coordination of all cloud security and SDR-related projects. Required Skills & Qualifications Experience: Minimum 6+ years of progressive experience in Information Security, including 4+ years of core experience in Cloud Security and Secure Design/Architecture roles within the BFSI sector. Technical Expertise: Deep, hands-on knowledge of security across AWS, Azure, and GCP. Expertise in application security, API security, and securing high-value financial platforms. Certifications (Highly Desirable): CSSLP, CCSP, or relevant AWS/Azure/GCP Security Specialty certifications. Skills: Exceptional analytical skills, experience translating complex BFSI regulatory risks into actionable technical controls, and strong executive communication abilities.

One address, no account. We’ll tell you when matching roles go live.

More at AXIS DIRECT

Related open roles

View all roles