|
• Architecture & Design: Design, build, and deploy secure, scalable, and resilient cloud infrastructures across public cloud platforms (AWS, OCI).
• Identity & Access Management (IAM): Design and manage robust cloud IAM policies, ensuring the principle of least privilege is strictly enforced across all environments.
• DevSecOps Integration: Integrate security tools and automated vulnerability scanning (SAST/DAST, SCA) directly into CI/CD pipelines. Implement Infrastructure as Code (IaC) security scanning (CSPM).
• Security Automation & Incident Response: Develop automated scripts and workflows to detect, alert, and remediate cloud security misconfigurations and threats in real-time. Assist the SOC team with cloud-specific incident investigation and forensics.
• Vulnerability & Threat Management: Conduct regular cloud security assessments, threat modeling, and configuration audits. Monitor and manage security alerts from CNAPP, CSPM, and CWPP platforms.
• Compliance & Governance: Ensure cloud infrastructure meets regulatory standards (SOC 2, ISO 27001, PCI-DSS, DPDP). Implement and monitor adherence to CIS Benchmarks.
• Collaboration & Mentorship: Partner with engineering teams to provide security guidance during the software development lifecycle (SDLC). Conduct security awareness training regarding cloud best practices for internal teams.
|