…

Security Lead

CLOUDSUFI · IT Services & Consulting

  • -, India
  • On-site
  • Posted 2 days ago
  • Cybersecurity

About the job

Experience: 8-12

Role : Full-Time Individual Contributor (IC)

Reporting to : Solution Architect / Program Manager

Location : Remote

Shift : 12x5

Experience : 8-10 Years

About Us

CLOUDSUFI is a Silicon Valley-based specialist Data Engineering & Cloud Technologies player with top-tier clients, favorable revenue mix, strong financial performance, and robust management. We pride ourselves in helping in the Data Discovery, Insights and Monetization for organizations. We offer quality of work, opportunities to learn new platforms/technologies that will help young engineers put themselves ahead in their careers compared to their peers in the IT Services industry. CLOUDSUFI is a Data Science and Product Engineering company building Products/Solutions for Technology and Enterprise industries leveraging the advent of Cloud Hyper Scalers and AI/ML, NLP technologies.

The organization is built to scale with strong external/ internal tech capabilities and governance standards. Started in 2019, CLOUDUSUFI is a family of 250 members working towards a common goal of making the enterprise data dance.

To know more, please visit https://cloudsufi.com

Our Values

We are a passionate and empathetic team that prioritizes human values. Our purpose is to elevate the quality of lives for our family, customers, partners and the community.

Equal Opportunity Statement

CLOUDSUFI is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. All qualified candidates receive consideration for employment without regard to race, colour, religion, gender, gender identity or expression, sexual orientation and national origin status. We provide equal opportunities in employment, advancement, and all other areas of our workplace. Please explore more at https://www.cloudsufi.com/

ABOUT YOU

5+ years’ experience with AWS orchestration via Terraform script
5+ years’ experience with CloudWatch/CloudTrail/Guard Duty
5+ years’ experience with AWS WAF
4+ years’ experience with CloudFlare
3+ years’ experience with DataDog
Experience with PagerDuty
Ability to make nuanced threat assessments
Experience in SOPHOS.
Significant experience with PCI, SOC2, SOX, HIPAA, or other compliance regimes
Experience in Infrastructure As Code – Ansible / Terraform/ CloudFormation
Hands-on experience implementing various security tools in CI/CD pipeline
Strong experience with any cloud service provider (AWS Preferred)
Implement and oversee technological upgrades, improvements and major changes to the cloud security environment.
Develop solutions, install/configure/integrate IT tools and security processes within an application or organization to help improve the overall IT security posture.
Set up Static and Dynamic Code Analysis tools, review the results and explain any gaps and potential impact to the teams (development and operations).
Penetration testing and container security.
Evaluate and analyze threat, vulnerability, impact and risk to security issues discovered from security assessments.
Assess current technology architecture for vulnerabilities, weaknesses and for possible upgrades or improvement
Creating and managing security strategies
Oversee information security audits, whether performed by organization or third-party personnel
Develop, maintain and publish up-to-date information security policies, standards and guidelines.
Preferred Certification - AWS Security/CISSP/CISM (Certified Information Security Manager)

ABOUT THE ROLE

Work independently with vendors and collaborate with colleagues
Experience negotiating remediation timelines and/or remediate found issues independently
Ability to implement vendor platforms within CI/CD pipelines
Experience managing/responding to incidents, collecting evidence, and making decisions.
Working with vendors and HM Teams to deploy criteria within WAF and fine tuning it according to applications’ needs
Multitasking and continuous ability to provide a high level of concentration for assigned projects.
Good working knowledge of AWS security in general and familiarity of the AWS native security tools
The candidate should be experienced and articulate, who is not going to get discouraged, despite meeting roadblocks, and will continue promoting security within the company.
Ability to create DevSecOps security requirements while working on a project
Ability to articulate security requirements during the Architecture meetings and working hand in hand with HM Applications and DevOps Principal Engineers