Security Architecture & Leadership
- Design and implement secure cloud security architecture across Azure and AWS.
- Define and enforce security best practices for API integrations, IAM policies, and encryption.
- Take the lead in security discussions with engineering, compliance, and IT teams.
- Act as a trusted security advisor, influencing key security decisions.
Risk Assessment & Compliance
- Conduct risk assessments, identify security vulnerabilities, and define mitigation strategies.
- Ensure SOC 2, ISO 27001, GDPR, and NIST 800-53 compliance across cloud and enterprise environments.
- Collaborate with compliance teams to prepare for security audits and regulatory assessments.
IAM & Secure Authentication
- Implement role-based access control (RBAC), least privilege policies, and MFA.
- Design secure authentication mechanisms using Azure AD, OAuth 2.0, SAML, and federated identity models.
- Lead IAM security strategy discussions, ensuring alignment with enterprise security frameworks.
Cloud Security & Infrastructure Hardening
- Configure and manage Azure Security Center, AWS Security Hub, and cloud-native security tools.
- Implement network security controls, including firewalls, IDS/IPS, and encryption.
- Drive DevSecOps initiatives, integrating security automation into CI/CD pipelines.
Incident Response & Security Operations
- Develop and implement incident response playbooks for cloud and enterprise security.
- Monitor security events using SIEM platforms such as Microsoft Sentinel or Splunk.
- Work with engineering teams to automate security event detection and remediation.
Cross-Functional Collaboration & Leadership
- Provide technical mentorship to junior security engineers.
- Work closely with the CISO, compliance teams, and enterprise architects to align security with business objectives.
- Lead security awareness initiatives to improve security posture across teams.
Required Skills & Qualifications
- 5+ years of experience in cybersecurity, cloud security, and enterprise security architecture.
- Hands-on experience with Azure and AWS security, including IAM, encryption, and compliance.
- Strong understanding of SOC 2, ISO 27001, GDPR, and NIST 800-53.
- Proven ability to lead security initiatives, influence decision-making, and provide mentorship.
- Expert-level knowledge of IAM security: Azure AD, AWS IAM, SAML, OAuth 2.0, MFA, RBAC.
- Experience working with SIEM platforms (Microsoft Sentinel, Splunk, QRadar).
- Hands-on experience implementing security automation in DevSecOps environments.
- Ability to own security discussions, guide teams, and take the lead when required.
Preferred Qualifications
- Experience implementing Zero Trust Security frameworks.
- Knowledge of container security (Kubernetes, Docker).
- Certifications (preferred but not required): CISSP, CISM, CCSP, AWS Security, Azure Security Engineer.