Cyber Security Cloud Engineer

3 weeks ago


New Delhi, India ERM Full time

Our Cyber Security team is actively enhancing our cloud presence and advancing digital transformation efforts. While many of our services have already transitioned to the cloud, we're continuously migrating from on-premise setups and developing new digital products and services. Embracing DevSecOps practices ensures that this evolution occurs securely. To bolster our Cyber Team's capabilities, we seek an adept Cyber Security Cloud Engineer to join us

Description:

Reporting into the cloud security engineering team, the Cyber Security Cloud Engineer plays a critical role in overseeing and driving a broad range of activities and a trustworthy, confident, and influential character is therefore essential. We have a small security operations team operating globally, and the successful candidate will be expected to have a broad range of experience, be self-motivated and work alongside cloud operations engineers and several globally distributed development teams to ensure that security is implemented correctly and to deliver to our Cyber Security Strategy and roadmap.

This global role is responsible for providing advice and assurance on secure cloud deployments to new and existing environments. Validating that cloud services and applications are designed, developed and implemented to the highest security standards. In addition, the Cyber Security Cloud Engineer will be responsible for the ongoing operational implementation of ERM’s cloud security posture management.

The role will deliver and continuously revise our framework and supporting ISMS artefacts including standards, baseline configuration and procedure documentation required to maintain our framework against a changing threat landscape. The role will provide security expertise within working groups and forums in support of governance and compliance activities. The role will assure that all IT solutions and services being delivered are compliant with our ISMS and that all exceptions and risks are documented and managed. The role will be responsible for regularly cloud security assessments against best practice frameworks. The role will also support business growth initiatives and innovations by keeping up to date with new security offerings and enhancements to maintain our risk posture.

The predominant infrastructure within ERM aligns with Azure utilizing the Microsoft stack. However, we concurrently support numerous projects hosted on AWS platforms. It is imperative for us to uphold consistent security measures across all environments. Therefore, proficiency in AWS is considered advantageous, as it facilitates the application of equivalent security controls across our diverse technological landscape Several of the solutions use containers so an understanding of containers and the security implications would be helpful.

About You:

At least 3 years practical hands-on experience managing and implementing Microsoft Azure environments and security tools such as Defender for Cloud, perhaps working purely in an infrastructure capacity or also with development teams to help secure their applications. You will also be able to discuss technical requirements and then turn them into practical applications of security and compliance tooling.

Working knowledge and experience in implementing and maintaining security, industry, and regulatory compliance frameworks and drivers such as Azure Security Benchmark V3, NIST CSF, ISO27001 and CIS v8.

Strong team member engagement skills. Diligent, delivery-focused, and able to manage multiple work streams simultaneously.

Ideally, holds Microsoft Certified: Azure Security Engineer Associate or higher. We would support you in maintaining and working towards these certifications.

Responsibilities

Lead efforts to promote cloud security principles across ERM's technology delivery teams and collaborate with cross-functional teams to enhance our Cyber Security posture. Interpret business requirements into technical deliverables and clearly communicate security risks to relevant stakeholders ranging from business leaders to analysts. Prioritize, implement, and track remediation efforts based on ongoing recommendations from Defender for Cloud Configure logging for cloud resources to integrate with our corporate SIEM. Manage and enhance our Azure Active Directory (AAD) policies to control user access and privileges effectively. Monitor and provide configuration review/enhancements on network security groups (NSGs), Application Security Groups (ASGs), Azure Firewalls and other cloud based network security tooling. Support the delivery of ERM’s Cyber Strategy and Roadmap, leading on major Cyber Security initiatives such as embedding security controls into deployment lifecycles, designing threat modelling processes, defining security hardening standards and defining ERM’s cloud security standards. Ensure that new cloud resources are integrated into the existing ERM vulnerability management framework and lead the remediation of identified findings. Provide subject matter expertise on Cybersecurity engineering to other technology and business teams, as well as governance forums. Create and maintain comprehensive security documentation including standards, baseline configuration and procedures. Lead the security governance for cloud-based systems at ERM, highlighting non-compliance from corporate standards and providing system/service owners with remediation guidance. Support incident investigations and remediation activities. Proactively monitor changes in the threat landscape and adapt tools to combat emerging threats. Proactively maintain awareness in latest cyber security cloud practices, processes and technologies.

Skills, Qualifications and Capabilities Description:

We are looking for someone who can demonstrate the below: Solid foundation in cybersecurity and information security principles Demonstrated proficiency in problem-solving, adept in quickly grasping new technology stacks, and a collaborative mindset for cross-functional teamwork Familiarity with leading compliance assessments and remediation of environments against security frameworks and industry best practices, including CIS, NIST, and ISO27001 Extensive hands-on experience with Microsoft Security solutions, encompassing Defender for Cloud, Sentinel, 365 Defender, and Azure Active Directory. Thorough understanding of network security concepts, spanning NSGs, firewalls, and VPNs. Proficient in scripting languages such as KQL and PowerShell, with a track record of practical application. A firm understanding of Zero Trust Principles with practical implementation experience

Useful Skills or Interests:

Any of these are a bonus, but not necessary to apply Microsoft certifications such as Azure Security Engineer Associate AZ-500 Cybersecurity Architect Expert SC-100 Security Operations Analyst Associate SC-200 Microsoft Identity and Access Administrator SC-300 AWS experience Experience of SAST and SCA tooling such as GitHub Advanced Security in CI/CD pipelines Experience securing containerized applications. Experience of implementing automated compliance and security checks via Azure Policies or other tooling Familiarity with Git-based source control Configuration alignment of Operating systems, software or services to Center for Internet Security (CIS) benchmarks Experience managing infrastructure with infrastructure as code tools, specifically Terraform. Experience working in a DevSecOps operating model and knows how best to facilitate change in delivery teams to adopt this model of working. Soft Skills: Excellent written and verbal communication skills Determination and motivation to succeed. Enthusiastic, with a positive ‘can-do’ attitude Ability to effectively prioritize and execute tasks in a high-pressure environment. Gains the respect of colleagues and is a team player focused on results over personal preferences. Highly self-directed, with keen attention to detail Has strong communication, project and time management skills. Experience working both independently and in a team-oriented, collaborative environment. Flexible and adaptable in learning and understanding new technologies. Proven analytical and problem-solving abilities. Strong orientation towards customer service

  • Delhi, Delhi, India Novalink Solutions LLC Full time

    Job DescriptionThe Security Cloud Engineer will assist the Cybersecurity Team by supporting Gwinnett County Security staff in their efforts to protect county systems. This position will be responsible for developing and maturing Microsoft Defender products and various other Cloud based products.Minimum Qualifications:Previous experience in various Microsoft...


  • Delhi, India Novalink Solutions LLC Full time

    Job DescriptionThe Security Cloud Engineer will assist the Cybersecurity Team by supporting Gwinnett County Security staff in their efforts to protect county systems. This position will be responsible for developing and maturing Microsoft Defender products and various other Cloud based products.Minimum Qualifications:·Previous experience in various...


  • Delhi, India Cyber Security Council for Operations & Intelligence Full time

    Job Title: Senior Cyber Security TrainerPosition Overview:We are seeking an experienced Senior Cyber Security Trainer with a proven track record in corporate training. The ideal candidate will have 6-8 years of hands-on experience in the field of cybersecurity along with exceptional teaching skills. The role involves designing curriculum, delivering training...


  • Delhi, India Teradyne Full time

    Our PurposeTERADYNE, where experience meets innovation and driving excellence in every connection. We are fueled by creativity and diversity of thought and in our workforce. Our employees are challenged to innovate and learn something new every day.We cultivate a culture of inclusion for all employees that respects their individual strengths, views, and...


  • Delhi, Delhi, India Teradyne Full time

    Our PurposeTERADYNE, where experience meets innovation and driving excellence in every connection. We are fueled by creativity and diversity of thought and in our workforce. Our employees are challenged to innovate and learn something new every day.We cultivate a culture of inclusion for all employees that respects their individual strengths, views, and...

  • Cyber Security

    2 months ago


    Delhi, Delhi, India Technoledge India Full time

    **1**. To teach high-quality and in-person training in Cyber Security and Ethical Hacking **2**. Good Understanding of information security audit, penetration testing, risk analysis, security breach analysis, cyber forensics, incident handling methods, Network Security, Cloud Security, Exploit Writing, Web Application Security, Server Security and System...


  • Delhi, Delhi, India Tekvaly Full time

    Job Description :As a Cyber Security Engineer, you will be responsible for safeguarding our systems and networks against security threats. You will work closely with IT teams to design and implement security protocols, conduct vulnerability assessments, and respond to security incidents. Your expertise in cyber security will be crucial in maintaining the...


  • Delhi, India DriveSec Technologies Full time

    Company Description DriveSec Technologies is a leading organization that empowers and enables companies to drive security and enhance workplace, infrastructure, and technological security processes. Our mission is to bridge the gap between technical teams and business teams, fostering a shift-left culture and mindset for secure growth. We prioritize a...


  • Delhi, Delhi, India Altered Security Full time

    We are looking for top Azure Cloud Security Researchers (Remote) with demonstrable expertise to join our team of expertsAltered Security is an information security startup with focus on edtech, hands-on learning and focused security assessments. It has offices in India and Singapore.We are experts in information security training, cyber ranges, online labs...


  • Delhi, India DriveSec Technologies Full time

    Company DescriptionDriveSec Technologies is a leading organization that empowers and enables companies to drive security and enhance workplace, infrastructure, and technological security processes. Our mission is to bridge the gap between technical teams and business teams, fostering a shift-left culture and mindset for secure growth. We prioritize a...


  • delhi, India CONMED Corporation Full time

    The Cyber Security Engineer is responsible for understanding security tooling platforms, appropriate configuration & deployment of respective tools to ensure detection, prevention, and response capabilities to the organization. The Cyber Engineer is also responsible to ensure CONMED continues to remain compliant with GDPR, CCPA, HIPAA, and SOX (along with...


  • Delhi, Delhi, India CONMED Corporation Full time

    The Cyber Security Engineer is responsible for understanding security tooling platforms, appropriate configuration & deployment of respective tools to ensure detection, prevention, and response capabilities to the organization.The Cyber Engineer is also responsible to ensure CONMED continues to remain compliant with GDPR, CCPA, HIPAA, and SOX (along with...


  • Delhi, India Altered Security Full time

    We are looking fortop Azure Cloud Security Researchers (Remote)with demonstrable expertise to join our team of experts!Altered Security is an information security startup with focus on edtech, hands-on learning and focused security assessments. It has offices in India and Singapore.We are experts in information security training, cyber ranges, online labs...


  • delhi, India Altered Security Full time

    We are looking for top Azure Cloud Security Researchers (Remote) with demonstrable expertise to join our team of experts!Altered Security is an information security startup with focus on edtech, hands-on learning and focused security assessments. It has offices in India and Singapore.We are experts in information security training, cyber ranges, online...


  • Delhi, India Altered Security Full time

    We are looking fortop Azure Cloud Security Researchers (Remote)with demonstrable expertise to join our team of experts!Altered Security is an information security startup with focus on edtech, hands-on learning and focused security assessments. It has offices in India and Singapore.We are experts in information security training, cyber ranges, online labs...


  • delhi, India Altered Security Full time

    We are looking for top Azure Cloud Security Researchers (Remote) with demonstrable expertise to join our team of experts!Altered Security is an information security startup with focus on edtech, hands-on learning and focused security assessments. It has offices in India and Singapore.We are experts in information security training, cyber ranges, online...


  • Delhi, India QuEST Global Services Pte. Ltd Full time

    Quest Global is an organization at the forefront of innovation and one of the world’s fastest growing engineering services firms with deep domain knowledge and recognized expertise in the top OEMs across seven industries. We are a twenty-five-year-old company on a journey to becoming a centenary one, driven by aspiration, hunger and humility.We are looking...


  • Delhi, India QuEST Global Services Pte. Ltd Full time

    Quest Global is an organization at the forefront of innovation and one of the world’s fastest growing engineering services firms with deep domain knowledge and recognized expertise in the top OEMs across seven industries. We are a twenty-five-year-old company on a journey to becoming a centenary one, driven by aspiration, hunger and humility.We are looking...


  • New Delhi, India Paradise Placement Consultancy Full time

    Job Description:We have an urgent opening for the position ofCyber Security TrainerFor a reputed Company for theNew Delhilocation.Job Description:Conduct pre-scheduled seminars and trainings for college students and corporate employees.Conduct Training sessions on Cyber Security, Web Application Security and concepts of VAPT.Enhancing Course plans,...


  • Delhi, India Altered Security Full time

    This position isnot for SOC/SIEM candidates .We are looking fortop Azure Cloud Security Researchers (Remote)with demonstrable expertise to join our team of experts!Altered Security is an information security startup with focus on edtech, hands-on learning and focused security assessments. It has offices in India and Singapore.We are experts in information...