FIND_THE_RIGHTJOB.
Hyderabad, Pakistan
Role Proficiency:
Act under guidance of DevOps; leading more than 1 Agile team.
Outcomes:
Measures of Outcomes:
Outputs Expected:
Automated components :
Configured components:
Scripts:
Training/SOPs :
Measure Process Efficiency/Effectiveness:
Operations:
Skill Examples:
Knowledge Examples:
The Role The Security Engineer role is an innovative, self-driven team player who will be able to educate, provide guidance and advisory on hardening cloud infrastructure primarily. This individual will be an advocate for implementations that reinforce the security infrastructure. The Ideal candidate combines technical acumen with an ability to drive by influence and communicate clearly. Technically, this person will be security generalist with one or more areas of deep expertise in application security, infrastructure security in cloud environment . Key Responsibilities • Security Engineer for the infrastructure security, will help to build a solid Security Infrastructure reputation in the field. In this role candidate is expected to have expertise to have hands-on mitigation cloud non-compliances preferably AWS. • Candidate is expected to have 3+ years of experience in DevSecOps and overall 6+ years’ experience. • Drive the technology risk management program and conduct security risk assessments across the organization. Rank security risks, articulate risk in terms of business impact, recommend reasonable strategies to mitigate risks, appropriately document findings of assessments, and present to risk owners and management stakeholders. • Manage the common control framework (CCF),CIS & NIST and evaluate control compliance in accordance with evaluation timelines, provide feedback, recommendations for gaps for identified gaps and issues, and document corrective action plans to remediate identified deficiencies. • Identify and resolve security issues across the cloud infrastructure. • Work with DevOps team to harden Containers /streamline infrastructure deployments in line with organization policies. • Continuous monitoring of cloud compliance and advise DevOps teams on mitigation and contribute to terraform scripting for IaaC • Design, implement, and manage network policies within Kubernetes to enhance security controls. • Create /update and maintain threat model for infrastructure projects/software. • Manual and Automated secure code review,terraforms, Automation • Adversarial security analysis using cutting edge tools /open-source tools knowledge and manual effort. • Influence your team’s and Engineering process, priorities, and choices to improve outcomes. • Experience in security controls and IT security framework, audits, control assessments, or risk assessments Required skills and Experience. • Plan, research, and design security architectures • Skills in Cloud infrastructure risks and compliance (Preferably AWS) • Knowledge in cryptography, public key infrastructure, OWASP, NIST, CIS benchmark, DevSecOps • Candidate with expertise in CI/CD pipeline design, integration, Terraform scripting, Apache Kafka, API security. • Scripting knowledge in Ruby, Scala, Java • Expertise in code review (Tool & manual) • Expertise in Containerization, vulnerability management, AWS cloud services security Preferred Qualification • 8+ years of experience working in an information security role. • Experience deploying services in a multi-cloud environment. • Good understanding and hands on skills in AWS cloud infrastructure • Experience in hands-on penetration testing of applications, API • Any Cloud certification (preferably AWS), designing networks, Kubernetes, Kafka solution architecture knowledge. • Good knowledge in Network protocols, cloud services • Candidate with expertise in application security, Scala , Terraform , NIST, CIS benchmark , threat model methodologies , STRIDE /MITRE
Devops,Aws,Terraform
Similar jobs
No similar jobs found
© 2025 Qureos. All rights reserved.