Cloud Security Architect – Azure & Multi-Cloud 5 - 10 Years | Job Location : Mumbai
Summary
The Cloud Security Architect will lead security reviews, architecture assurance, and risk assessments for cloud environments, primarily focusing on Microsoft Azure. The role involves implementing security-by-design principles, managing CSPM/CNAPP solutions, and collaborating with DevOps teams to integrate security into CI/CD pipelines.
Position: Lead Analyst – Information Security
Location: Mumbai
Experience: 5–10+ years
Role Overview
We are looking for an experienced Information Security professional with strong expertise in Cloud Security, Cloud Architecture, and IT Infrastructure. The role will focus on end-to-end cloud security solution reviews, security architecture assurance, cloud security posture management, compliance, risk assessment, and secure cloud development practices.
Strong hands-on experience with Microsoft Azure is required. Experience across AWS/GCP and exposure to AI Security will be an added advantage.
Key Responsibilities
- Conduct end-to-end security reviews of cloud technology solutions across Azure, AWS, M365, SaaS, PaaS and IaaS, ensuring security-by-design principles.
- Perform technical assessments of on-premises and cloud solutions to identify misconfigurations, vulnerabilities, deviations from best practices, and potential attack vectors.
- Evaluate cloud security solutions against threat models, risk assessments, and frameworks such as NIST CSF, CSA CCM, ISO 27001 and CIS Benchmarks.
- Provide security architecture recommendations and guidance to Risk, Information Security and Enterprise IT leadership.
- Lead Cloud Security Posture Management (CSPM) reviews using CNAPP platforms covering CSPM, CIEM, cloud workload and container security.
- Conduct cloud compliance assessments against standards such as GDPR, HIPAA, PCI DSS and SOC 2.
- Review cloud security policies, procedures, hardening standards and configurations against organizational and industry best practices.
- Partner with Enterprise IT and DevOps teams to embed security across the SDLC and CI/CD pipelines.
- Review Infrastructure as Code (IaC) templates and automation scripts and provide recommendations for secure implementation.
- Participate in cloud attack path analysis and recommend preventative and detective security controls.
- Track security vulnerabilities and misconfigurations and work with relevant teams to ensure timely remediation.
- Contribute to the continuous improvement of cloud security governance frameworks and processes.
- Provide subject matter expertise for cloud security incident response and forensic readiness.
Required Experience
- 5–10+ years of progressive experience in Information Security, with 4–7+ years specifically focused on Cloud Security architecture, engineering and security reviews.
- Strong hands-on experience with cloud security services across Microsoft Azure, AWS and/or GCP.
- Strong IT Infrastructure and Cloud Security background.
- Experience in security assessments, penetration testing and/or vulnerability management in cloud environments.
- Proven experience designing and reviewing secure cloud architectures for complex enterprise environments.
Technical Skills
- Strong understanding of IaaS, PaaS, SaaS and the Cloud Shared Responsibility Model.
- Cloud security frameworks: NIST CSF, CSA CCM, ISO 27001, CIS Benchmarks and OWASP Cloud Top 10.
- Hands-on experience with CNAPP/CSPM/CIEM/CWP solutions such as Prisma Cloud, Wiz, Tenable, Lacework, Microsoft or CrowdStrike Cloud Security.
- Strong Cloud IAM knowledge: Azure AD/Entra ID, AWS IAM, GCP IAM, Conditional Access, MFA, SSO, PIM/PAM.
- Cloud Network Security: VPC/VNet, network segmentation, WAF, NGFW, security groups/NSGs, VPN and Private Link.
- Data Security and Encryption: Azure Key Vault, AWS KMS, Google Cloud KMS and related cloud-native security services.
- Application Security: secure coding, API security, serverless security and DevSecOps.
- IaC Security: Terraform, CloudFormation, ARM Templates, Bicep and Policy-as-Code.
- Container Security: Docker, Kubernetes, admission controllers and network policies.
- Strong understanding of cloud compliance and GRC processes.
Soft Skills
- Strong analytical and problem-solving capabilities with excellent attention to detail.
- Ability to communicate complex security risks and concepts to both technical and non-technical stakeholders.
- Excellent written and verbal communication skills.
- Ability to work independently and collaboratively across distributed teams while managing multiple priorities.
Certifications – Preferred
Cloud Security:
- (ISC)² CCSP
- AWS Certified Security – Specialty
- Microsoft Certified: Azure Security Engineer Associate (AZ-500)
- Google Professional Cloud Security Engineer
- Certificate of Cloud Security Knowledge (CCSK)
General Security:
- (ISC)² CISSP
- CISM
Key Focus: Cloud Security Architecture | Azure | AWS/GCP | CSPM/CNAPP | IAM | Cloud Infrastructure Security | DevSecOps | IaC Security | Compliance & Governance | Cloud Risk & Attack Path Analysis