Padmi

Cloud & Infrastructure Security Architect

HyderabadPosted 30 days ago
CybersecuritySenior
Apply at KORE AI INC

Opens the source posting on ats.rippling.com

Source description

About the role

View original

Cloud & Infrastructure Security Architect

Kore.ai is a pioneering force in enterprise AI transformation, empowering organisations through our comprehensive agentic AI platform. With innovative offerings across "AI for Service," "AI for Work," and "AI for Process," we're enabling over 400+ Global 2000 companies to fundamentally reimagine their operations, customer experiences and employee productivity.

Our end-to-end platform enables enterprises to build, deploy, manage, monitor, and continuously improve agentic applications at scale. We've automated over 1 billion interactions every year with voice and digital AI in customer service, and transformed employee experiences for tens of thousands of employees through productivity and AI-driven workflow automation.

Recognised as a leader by Gartner, Forrester, IDC, ISG, and Everest, Kore.ai has secured Series D funding of $150M, including strategic investment from NVIDIA to drive Enterprise AI innovation. Founded in 2014 and headquartered in Florida, we maintain a global presence with offices in India, UK, Germany, Korea, and Japan.

Position / Title

Cloud & Infrastructure Security Architect

Location: Hyderabad

Experience: 8–10+ years

Position Summary

About the Role

We are looking for a Cloud & Infrastructure Security Architect to serve as the security authority across our multi-cloud environment. You will define the security architecture standards our infrastructure must meet, govern continuous audit and assurance to ensure zero gaps, and drive measurable improvement in cloud security posture across AWS, Azure, and GCP. This is a hands-on architecture role with real ownership — you will shape how our cloud environments are secured, not just advise on it.

RESPONSIBILITIES**: **,

Cloud Security Architecture & Standards

  • Define and own the cloud security architecture across AWS, Azure, and GCP — establishing the authoritative security baseline, guardrails, and standards the environment must meet.
  • Drive secure landing zone architecture — account and subscription structure, network segmentation, logging pipelines, and security control inheritance.
  • Lead security architecture reviews and sign-offs for new cloud infrastructure designs, platform changes, and cloud migration initiatives.
  • Define multi-cloud IAM architecture — least privilege design, role federation, cross-account trust models, service principal governance, and privileged access management.
  • Architect secrets management standards across AWS Secrets Manager, Azure Key Vault, and GCP Secret Manager — covering rotation, access governance, and audit requirements.
  • Publish reusable, secure reference architectures and approved cloud service patterns that embed security into infrastructure decisions by default.

CONTINUOUS AUDIT, ASSURANCE & POSTURE MANAGEMENT

  • Own the continuous cloud security audit program — systematically evaluating the live environment against defined standards to detect gaps, drift, and deviations before they become incidents.
  • Govern Cloud Security Posture Management (CSPM) — interpret findings, triage by exploitability and business risk, enforce remediation SLAs, and drive posture improvement to measurable outcomes.
  • Conduct deep-dive security audits — IAM privilege analysis, network exposure reviews, encryption gap assessments, logging completeness checks, and workload configuration audits.
  • Define and enforce cloud security benchmarks aligned to CIS Foundations (AWS, Azure, GCP), NIST SP 800-144, and CSA CCM — with clear pass/fail criteria measured continuously.
  • Maintain the cloud security risk register — open gaps, accepted risks with rationale, remediation timelines, and closure evidence — reported to the CISO on a defined cadence.
  • Conduct adversarial validation using cloud attack simulation (Pacu, Stratus Red Team) to verify that controls and detection hold under real attack conditions.

Kubernetes & Container Security

  • Own end-to-end Kubernetes security architecture at CKS depth — cluster hardening standards, workload isolation, admission control, network policy, secrets management, and runtime protection.
  • Define and enforce Kubernetes security standards: Pod Security Admission, RBAC governance, admission controllers (OPA/Gatekeeper, Kyverno), network policies, and control plane hardening.
  • Conduct regular Kubernetes security audits — CIS Kubernetes Benchmark assessments, RBAC privilege analysis, etcd security, API server reviews, and node-level gap detection.
  • Define container image security standards — base image governance, vulnerability scanning (Trivy, Aqua, Snyk), image signing (Cosign/Notary), and registry access controls.
  • Own runtime security architecture — deployment standards for Falco or Sysdig, coverage audits, and container escape/anomaly detection validation.
  • escape/ Kubernetes CVE triage and response — assess impact on cluster configurations and drive resolution to closure.

IAC Security & Policy-as-code

  • Review and approve Infrastructure-as-Code templates — Terraform, AWS CDK, Bicep, and Helm charts — identifying misconfigurations, over-permissive IAM, exposed endpoints, and encryption gaps before deployment.
  • Define IaC security standards and reusable secure modules — pre-approved, security-hardened building blocks that make secure deployment the default.
  • Define IaC scanning standards and security gate requirements for CI/CD pipelines (Checkov, tfsec, Terrascan) with clear pass/fail criteria and remediation guidance.
  • Own the policy-as-code framework — define security policies automatically evaluated against every infrastructure change and continuously audit compliance.

Zero Trust & Network Security

  • Define and drive Zero Trust Architecture across cloud environments — identity-based access, micro-segmentation standards, service mesh security, and continuous verification principles.
  • Design cloud network security standards — VPC/VNet architecture, security group governance, private endpoint requirements, egress controls, and east-west traffic inspection.
  • Define service mesh security requirements (Istio, Linkerd) — mTLS enforcement, traffic policy standards, and observability integration
  • Conduct network security audits to identify deviations from approved architecture — exposed services, missing private endpoints, segmentation gaps.

Serverless & Cloud-native Security

  • Define security architecture standards for serverless workloads across AWS Lambda, Azure Functions, and GCP Cloud Functions — execution role minimisation, event source trust, and data protection requirements.
  • Audit serverless and cloud-native deployments — identifying SSRF-to-metadata risks, over-permissive execution roles, insecure event triggers, and dependency risks.
  • Define security standards for cloud-native managed services — databases, message queues, object storage, API gateways — with mandatory encryption, access control, and audit logging requirements.

Threat Detection & Cloud Incident Response

  • Design the cloud threat detection architecture — define detection requirements, tool selection (GuardDuty, Defender for Cloud, GCP SCC, Falco), and alert pipeline into SIEM and SOC workflows.
  • Audit detection coverage — validate live detection configuration against designed architecture, identify blind spots, and drive tuning to close gaps.
  • Define cloud incident response playbooks for key scenarios: IAM compromise, data exposure, cryptomining, lateral movement, and container escape.
  • Design SIEM integration architecture — cloud log ingestion standards, detection use case requirements, and alert pipeline design, ensuring cloud threats surface operationally.
  • Conduct cloud attack simulations (Pacu, Stratus Red Team) to validate detection and response readiness under adversarial conditions.

Required Skills & Experience

  • 8–10+ years of progressive experience in cloud security, infrastructure security, or platform security architecture — with proven ownership of architecture design, posture management, and audit governance.
  • Expert-level, multi-cloud security knowledge across AWS, Azure, and GCP — including deep familiarity with native security services, IAM models, and security tooling on each platform.
  • Kubernetes security expertise at CKS depth — cluster hardening, admission control, RBAC governance, network policy, runtime security, and secrets management architecture.
  • Strong CSPM governance experience — owning the full posture management cycle from finding through triage, remediation SLA enforcement, drift detection, and maturity reporting.
  • Hands-on IaC security review experience — Terraform, CDK, Bicep, or Helm — including policy-as-code design and scanning tool governance (Checkov, tfsec, Terrascan).
  • Cloud threat detection architecture experience with GuardDuty, Defender for Cloud, or GCP SCC — detection engineering, coverage gap analysis, and SIEM integration.
  • Cloud attack simulation experience (Pacu, Stratus Red Team) — used to adversarially validate architectural controls and detection coverage
  • Zero Trust Architecture design experience — micro-segmentation, service mesh (mTLS), identity-based access, and network security in cloud environments.
  • Serverless security experience across AWS Lambda, Azure Functions, and GCP Cloud Functions.
  • Strong scripting capability in Python and/or Bash for audit automation, posture checks, and custom gap detection.
  • Excellent communication skills — able to present cloud security posture, risk, and architecture decisions clearly to both technical audiences and executive stakeholders.

Nice to have

Experience with Security Operations Center (SOC) workflows and SIEM platforms (Splunk, Microsoft Sentinel, IBM QRadar, or Chronicle) — particularly cloud log ingestion, detection use case design, and alert-to-SOC pipeline architecture

Familiarity with cloud security maturity frameworks — CSA CCM, CIS Controls, NIST CSF — and experience using them to produce measurable improvement roadmaps

Exposure to AI/ML workload security in cloud environments — data pipeline security, model serving infrastructure, and cloud-hosted AI service controls

Experience supporting enterprise customer security reviews, RFP/RFI responses, or third-party security assessments in a customer-facing capacity

Background in regulated environments with exposure to frameworks such as SOC 2, ISO 27001, or NIST

Certifications

The following certifications are preferred. Candidates who demonstrate equivalent hands-on depth without a specific certification will be considered.

CertificationFull NameLevel
CKSCertified Kubernetes Security SpecialistPreferred
AWS Security SpecialtyAWS Certified Security – SpecialtyPreferred
AZ-500Azure Security Engineer AssociatePreferred
CKACertified Kubernetes AdministratorAdvantageous
CCSPCertified Cloud Security Professional (ISC2)Advantageous
GCP Security EngineerGoogle Professional Cloud Security EngineerAdvantageous
GCIA / GCIHGIAC Intrusion Analyst / Incident HandlerAdvantageous — SOC background
OSCP / PNPTOffensive Security / Practical Network PentestAdvantageous

Core Technologies & Tools

Cloud PlatformsAWS, Microsoft Azure, GCP — native security services, IAM, logging, detection, and CSPM on each
CSPM & PosturePrisma Cloud, Wiz, Prowler, Lacework, AWS Security Hub, Defender for Cloud, GCP Security Command Center
Kubernetes SecurityCKS-level: OPA/Gatekeeper, Kyverno, Falco, Sysdig, Trivy, Aqua Security, Cosign, kube-bench, External Secrets Operator
Container SecurityTrivy, Aqua Security, Snyk Container, Docker Scout, image signing (Cosign/Notary), registry security
IaC SecurityCheckov, tfsec, Terrascan, KICS — Terraform, AWS CDK, Bicep, Helm
Secrets ManagementHashiCorp Vault, AWS Secrets Manager, Azure Key Vault, GCP Secret Manager
Cloud IAMAWS IAM Analyzer, Azure Entra ID / PIM, GCP Workload Identity / IAM Recommender
Threat DetectionAWS GuardDuty, Microsoft Defender for Cloud, GCP SCC, Falco — detection engineering and SIEM integration
SIEM / SOCSplunk, Microsoft Sentinel, IBM QRadar, Chronicle — cloud log ingestion and detection use case design
Attack SimulationPacu, Stratus Red Team, CloudGoat — adversarial validation of controls and detection coverage
Zero Trust / NetworkIstio, Linkerd, Cilium (eBPF), ZTNA/SASE — service mesh, micro-segmentation, mTLS
ScriptingPython, Bash — audit automation, posture checks, custom gap detection
Maturity FrameworksCSA CCM, CIS Benchmarks (AWS/Azure/GCP/K8s), NIST CSF, NIST SP 800-144

Why Join Us?

At Kore.ai, you won't be maintaining quality for conventional software—you'll be defining what quality means for an entirely new category of platform technology that enables enterprise-scale agentic applications. Your work will directly influence how the world's leading organizations build, deploy, and trust AI systems, establishing standards that could transform the industry.

Join us in building not just a better platform, but the frameworks that ensure enterprise agentic applications deliver on their transformative promise safely, effectively, and responsibly at scale.

Education Qualification

GraduateinEngineeringORMastersinComputer Applications

Apply now

Common Shared Services

Hyderabad, India

Share on:

Apply now

Terms of service Privacy Cookies Powered by Rippling

One address, no account. We’ll tell you when matching roles go live.

More at KORE AI INC

Related open roles

View all roles