Cloud Security Lead
Posted Updated
# Infrastructure Governance & Resilience Lead
## Company Overview
*Not specified.*
## Job Summary
The **Infrastructure Governance & Resilience Lead** is responsible for ensuring the **real-time security posture** of the cloud platform and applications. This role involves detecting, validating, and responding to vulnerabilities, threats, and misconfigurations. Acting as an independent security control function, the lead ensures that all infrastructure and platforms built and operated by engineering teams remain **secure, resilient**, and **free from exploitable risks**. The position plays a critical role in maintaining the organization's security integrity and supporting compliance and audit requirements.
## Responsibilities
- **Cloud Security Posture Management:** Own and operate cloud security platforms such as Prisma, Qualys, and Sentinel One to continuously monitor infrastructure, workloads, and configurations. Drive timely remediation of vulnerabilities and misconfigurations to ensure no insecure or non-compliant workloads exist.
- **Threat Detection & Response:** Manage security monitoring and threat detection ecosystems using platforms like Chronicle. Detect, investigate, and coordinate responses to security incidents, anomalies, and potential breaches. Develop and implement incident response playbooks in collaboration with SRE and Platform teams.
- **Identity & Access Validation:** Validate identity and access controls across the platform, including IAM configurations, role definitions, and privileged access mechanisms. Ensure privileged access is secure, compliant, and fully traceable through systems such as CyberArk.
- **Security Remediation Validation:** Act as the technical validator for all security-related fixes, ensuring vulnerabilities and risks are fully addressed. Revalidate fixes and confirm no residual risks remain before closing issues.
- **Proactive Risk Management:** Continuously identify potential risks, weak configurations, and emerging threat vectors. Provide recommendations to platform engineering teams to improve architecture, controls, and overall security posture.
- **Collaboration & Governance:** Raise findings to Platform and SRE teams for remediation and track them to closure. Support governance teams by providing evidence, validation, and insights required for audits and compliance.
## Qualifications
- 10–15 years of experience in **cloud security, cybersecurity operations, or threat management** roles.
- Strong expertise in **cloud security posture management tools** (e.g., Prisma, Qualys), **SIEM platforms**, and **vulnerability management**.
- Experience implementing **Zero Trust** and **identity security frameworks**.
- Knowledge of security in **BFSI (Banking, Financial Services, and Insurance)** or other **regulated environments**.
- Proficiency in **security incident detection, investigation, and response**.
- Deep understanding of **identity and access management (IAM)**, privileged access controls, and security validation processes.
- Familiarity with **security compliance standards** and audit processes.
## Preferred Skills
- Experience working in **regulated industries** such as BFSI.
- Strong analytical and **evidence-driven** approach to security validation.
- Ability to operate independently as a **control function** while collaborating effectively with engineering teams.
- Excellent communication skills for reporting findings and providing security insights.
- Knowledge of **cloud security frameworks** such as **Zero Trust**.
## Experience
- **10 to 15 years** of relevant experience in **cloud security, cybersecurity operations, or threat management**.
- Proven track record in **security monitoring, incident response, and vulnerability management**.
- Experience working in **regulated environments** like BFSI is preferred.
## Environment
- The role involves working in a **collaborative, fast-paced environment** focused on **cloud security and infrastructure resilience**.
- The position may require **remote, in-office, or hybrid work arrangements** depending on organizational policies.
- The role involves **interacting with cross-functional teams** including Platform Engineering, SRE, and Governance.
## Salary
*Not specified.*
## GrowthOpportunities
*Not specified.*
## Benefits
*Not specified.*