Padmi
Cyara logo
Cyara

agentic AI testing · customer experience assurance

Sr. Security Engineer - Cloud Security

IN · OnsitePosted 5 months ago
SecuritySeniorHybrid
Apply at Cyara

Opens the source posting on jobs.lever.co

Source description

About the role

View original

Cloud Architecture & Design – Designing secure-by-default cloud architectures and integrations, ensuring all new infrastructure meets rigorous security standards before deployment.

Identity & Access Management (IAM) – Designing and reviewing cloud IAM strategies by defining roles, least-privilege policies, service accounts, and access boundaries across AWS, Azure, and GCP.

Cloud Configuration Hardening – Locking down storage buckets, network security groups, load balancers, databases, and managed services to prevent accidental exposure and ensure compliance.

DevSecOps & CI/CD Security – Securing the software supply chain by reviewing pipeline permissions, secrets handling, and artifact signing to prevent unauthorized deployments to production.

Threat Modeling & Risk Assessment – Conductin threat modeling sessions with architects to identify structural risks (e.g., compromised roles) and defining security requirements for new features.

Security Automation & Policy-as-Code – AWS‑centric security automation by developing Terraform guardrails, enforcing Policy-as-Code through OPA/Conftest and AWS Service Control Policies (SCPs), and building AWS-native auto‑remediation workflows using AWS Config, EventBridge, Lambda, and SSM Automation to ensure continuous compliance and enforcement of cloud security standards.

Security Monitoring & Alert Triage – Managing the intake of alerts from CSPM, SIEM, and cloud-native tools (GuardDuty, Defender, SCC), distinguishing real threats from operational noise.

Cloud Incident Response – Leading investigations into cloud-specific incidents, including compromised credentials, suspicious API calls, crypto-mining activity, or exposed resources.

Vulnerability Management – Running and analyzing scans for cloud workloads (VMs, containers, serverless) and prioritizing remediation based on contextual risk rather than generic CVSS scores.

Logging & Audit Readiness – Ensuring cloud audit logs are enabled, immutable, centralized, and readily available for forensic investigations and compliance audits.

Cross-Functional Advisory – Serving as a subject matter expert for developer, infrastructure, and platform teams, translating complex security requirements into practical, engineering-focused guidance.

More at Cyara

Related open roles

View all roles