Cloud Security Consultant - Information Compliance Security : CNAPP, CSPM & Multi-Cloud Exp -8 - 12 Yrs | Job Location : Gurgaon, Mumbai
WNSGlobalServices144 Cloud Security Consultant - Information Compliance Security : CNAPP, CSPM & Multi-Cloud Exp -8 - 12 Yrs | Job Location : Gurgaon, Mumbai
Key Responsibilities
End-to-End Cloud Security Solution Review & Design Assurance
- Conduct comprehensive design and architecture reviews of end-to-end cloud technology solutions, including cloud platforms (M365, Azure, AWS) and SaaS, PaaS, and IaaS implementations, ensuring security by design.
- Perform in-depth technical assessments of implemented technology solutions (on-premises and cloud) to identify misconfigurations, deviations from best practices, and potential attack vectors.
- Evaluate cloud security solutions against threat models, risk assessments, and industry-recognized frameworks (e.g., NIST CSF, CSA CCM, ISO 27001, CIS Benchmarks).
- Provide expert security recommendations and architectural guidance to Risk, InfoSec, and Enterprise IT leadership, as well as to client-facing processes.
Cloud Security Posture Management & Compliance Assurance
- Lead and execute Cloud Security Posture Management (CSPM) reviews using CNAPP (Cloud-Native Application Protection Platform) tools to assess cloud security posture, cloud identity protection (CIEM), workload protection, and container security.
- Run regular compliance scans of cloud resources against standards such as HIPAA, GDPR, PCI DSS, and SOC 2, and drive continuous improvement of compliance posture.
- Review and provide feedback on cloud security policies, procedures, and hardening documents, ensuring alignment with CIS benchmarks and organizational InfoSec policies.
- Conduct cloud risk assessments to identify threats, vulnerabilities, and misconfigurations that could impact IT operations and sensitive data.
Secure Cloud Development & Operations Practices
- Collaborate with Enterprise IT and DevOps teams to embed security throughout the SDLC and CI/CD pipelines.
- Review Infrastructure as Code (IaC) templates and automation scripts for security flaws, guiding teams on secure IaC best practices.
- Participate in cloud attack path analysis to understand adversary techniques and design preventative and detective controls.
- Ensure CIS and other security best practices are rigorously applied across new and existing applications, products, and cloud infrastructure.
Security Governance & Remediation Oversight
- Partner with cross-functional teams to track and drive remediation of identified security vulnerabilities and misconfigurations.
- Contribute to the continuous improvement of cloud security governance frameworks and processes.
- Act as a subject matter expert for incident response and forensic readiness related to cloud security incidents.
- Collaborate on cloud attack path analysis across teams.
Experience
- 8–12+ years of progressive experience in Information Security, with at least 5–7 years focused specifically on cloud security architecture, engineering, and review.
- Extensive hands-on experience with security services and features across major cloud providers (Azure, AWS, GCP).
- Demonstrable experience performing security assessments, penetration testing, or vulnerability management within cloud environments.
- Proven experience designing and reviewing secure cloud architectures for complex enterprise solutions.
Technical Expertise
- Strong understanding of cloud computing principles (IaaS, PaaS, SaaS) and the Shared Responsibility Model.
- Expertise in cloud security frameworks and standards: NIST CSF, CSA CCM, ISO 27001, CIS Benchmarks, OWASP Cloud Top 10.
- Hands-on proficiency with leading CNAPP platforms (e.g., Prisma Cloud, Wiz, Tenable, Lacework, Microsoft, CrowdStrike Cloud Security) for CSPM, CIEM, cloud workload protection, and container security.
- Strong grasp of Identity and Access Management (IAM) in the cloud: Azure AD, AWS IAM, GCP IAM, conditional access policies, MFA, SSO, PIM/PAM.
- Advanced knowledge of network security in the cloud: VPC/VNet design, network segmentation, firewalls (WAF, NGFW), security groups/NSGs, VPNs, and private links.
- Expertise in data security and encryption, including securing data at rest and in transit using native cloud encryption services (KMS, Key Vault, Cloud KMS).
- Understanding of application security in the cloud, including secure coding practices, API security, serverless function security, and DevSecOps integration.
- Ability to review and secure Infrastructure as Code (Terraform, CloudFormation, ARM templates, Bicep) and policy-as-code implementations.
- Knowledge of containerization (Docker, Kubernetes) and associated security best practices and tools.
Compliance & Governance
- In-depth knowledge of regulatory compliance requirements (GDPR, HIPAA, PCI DSS, SOC 2, ISO 27001) and their application in cloud environments.
- Experience with GRC (Governance, Risk, and Compliance) tools and processes for cloud.
Analytical & Communication Skills
- Exceptional analytical and problem-solving skills with meticulous attention to detail.
- Strong ability to articulate complex security concepts and risks to technical and non-technical audiences alike.
- Excellent written and verbal communication skills for documentation, reports, and presentations.
- Ability to work independently and collaboratively within a distributed team, managing multiple priorities effectively.
Certifications (Highly Preferred)
Cloud Security Certifications:
- (ISC)² Certified Cloud Security Professional (CCSP)
- AWS Certified Security – Specialty
- Microsoft Certified: Azure Security Engineer Associate (AZ-500)
- Google Professional Cloud Security Engineer
- Certificate of Cloud Security Knowledge (CCSK)
General Security Certifications:
- (ISC)² CISSP (Certified Information Systems Security Professional)
- CISM (Certified Information Security Manager)
Skills
- API
- Api Security
- Automation
- AWS
- Azure
- Azure AD
- Bicep
- CI/CD
- Cism
- Cissp
- Cloud
- Cloud Native
- Cloud Security
- CloudFormation
- Container Security
- Containerization
- Crowdstrike
- DevOps
- DevSecOps
- Docker
- Firewall
- GCP
- Gdpr
- Hipaa
- IAM
- Infrastructure as Code
- ISO 27001
- Kubernetes
- Network Security
- Nist
- OWASP
- Pci Dss
- Penetration Testing
- Regulatory Compliance
- SaaS
- SDLC
- Secure Coding
- Serverless
- SOC 2
- SSO
- Terraform
- Vault
- VPC
- WAF