Lead Infrastructure Engineer
$31,200–$31,200 year
On-siteBengaluru, Karnataka, India
Job Summary
Lead computer security incident response activities for highly complex events, conducting technical investigations and post-incident digital forensics to identify causes and recommend mitigation strategies. Provide security consulting on large internal projects to ensure conformity with corporate information security policies and standards. Design, document, test, and maintain highly complex security solutions across networking, cryptography, cloud, and endpoint domains while reviewing and correlating security logs. Identify vulnerabilities, perform risk assessments, and evaluate remediation alternatives to drive automation and operational excellence. Lead a team to achieve objectives while influencing all levels of professionals within a regulated financial services environment.
Required Qualifications
- 5+ years of Information Security Engineering experience, or equivalent demonstrated through one or a combination of the following: work experience, training, military experience, education
- 5+ years of overall technology engineering experience
- 5+ years of hands-on experience in Cloud Security Engineering, Cloud Governance, Cloud Platform Security, or related disciplines
- Professional cloud certifications in AWS or GCP or Azure
- Good Understanding of Python Programming
- Experience working in large-scale regulated environments, preferably within Financial Services or highly regulated industries
- Strong understanding of Cloud Native Application Protection Platforms (CNAPP), CSPM, CWPP, and Cloud Infrastructure Entitlement Management (CIEM) solutions
- Experience with Kubernetes, OpenShift, and container security best practices
- Experience designing enterprise-scale cloud governance and security programs
- Strong analytical and problem-solving capabilities with a focus on automation, scalability, and operational excellence
- Demonstrated ability to influence technical direction, lead strategic initiatives, and drive adoption of cloud security standards across multiple engineering organizations
- Strong ownership mindset, collaboration skills, and ability to deliver results in a fast-paced enterprise environment
- Strong hands-on experience with AWS security services and governance capabilities, including IAM, Organizations, SCPs, Security Hub, GuardDuty, CloudTrail, Config, KMS, and related cloud-native security services
- Hands-on experience with at least two public cloud platforms among AWS, Azure, and GCP
- Advanced expertise in Infrastructure-as-Code (IaC) and Policy-as-Code (PaC) technologies, including: Terraform, HashiCorp Sentinel, Azure Policy, GCP Organization Policies, Open Policy Agent (OPA) / Rego
- Strong understanding of policy lifecycle management, cloud governance, posture management, drift management, exception management, and policy enforcement strategies
- Proven experience implementing cloud control frameworks and translating regulatory, compliance, and security requirements into enforceable technical controls
- Deep understanding of Defense-in-Depth architecture and implementation of preventive, detective, corrective, and reporting controls
- Strong knowledge of Cloud Security Posture Management (CSPM), cloud security governance, compliance monitoring, vulnerability management, and security reporting
- Hands-on experience designing and implementing automated remediation solutions using cloud-native services, Infrastructure-as-Code, scripting, and CI/CD pipelines
- Strong understanding of cloud networking and security controls, including network segmentation, perimeter security, private connectivity, Zero Trust principles, and workload isolation
- Deep expertise in GCP security capabilities, including: Security Command Center (SCC),VPC Service Controls (VPC-SC),GCP Organization Policies, Access Levels, Ingress and Egress Controls, Service Perimeters, Data Exfiltration Protection
- Proven experience troubleshooting VPC-SC access issues through analysis of Cloud Audit Logs, policy violations, service perimeter configurations, and governance controls
- Strong understanding of cloud-native data protection controls, including: Encryption at Rest and In Transit, Key Management Systems (KMS),Hardware Security Modules (HSM),Secrets Management, Certificate Management, Cryptographic Key Lifecycle Governance
- Experience implementing and maintaining identity and access management controls, privileged access models, authentication, authorization, and federation patterns
- Good knowledge of DevOps and SDLC practices, including: GitHub, GitOps, Branching Strategies, Release Management, CI/CD Pipelines, Infrastructure Delivery Automation
- Experience integrating security controls into developer workflows and enterprise cloud operating models
- Excellent verbal, written, and interpersonal communication skills with the ability to communicate technical concepts to both technical and business audiences
- Must be able to lift 50 lbs
- Must be available for weekend shifts
- Valid driver's license
Desired Qualifications
- 5+ years of overall technology engineering experience, including 5+ years of hands-on experience in Cloud Security Engineering, Cloud Governance, Cloud Platform Security, or related disciplines
- Professional cloud certifications in AWS or GCP or Azure
- Good Understanding of Python Programming
- Experience working in large-scale regulated environments, preferably within Financial Services or highly regulated industries
- Strong understanding of Cloud Native Application Protection Platforms (CNAPP), CSPM, CWPP, and Cloud Infrastructure Entitlement Management (CIEM) solutions
- Experience with Kubernetes, OpenShift, and container security best practices
- Experience designing enterprise-scale cloud governance and security programs
- Strong analytical and problem-solving capabilities with a focus on automation, scalability, and operational excellence
- Demonstrated ability to influence technical direction, lead strategic initiatives, and drive adoption of cloud security standards across multiple engineering organizations
- Strong ownership mindset, collaboration skills, and ability to deliver results in a fast-paced enterprise environment
- Strong hands-on experience with AWS security services and governance capabilities, including IAM, Organizations, SCPs, Security Hub, GuardDuty, CloudTrail, Config, KMS, and related cloud-native security services
- Hands-on experience with at least two public cloud platforms among AWS, Azure, and GCP
- Advanced expertise in Infrastructure-as-Code (IaC) and Policy-as-Code (PaC) technologies, including: Terraform, HashiCorp Sentinel, Azure Policy, GCP Organization Policies, Open Policy Agent (OPA) / Rego
- Strong understanding of policy lifecycle management, cloud governance, posture management, drift management, exception management, and policy enforcement strategies
- Proven experience implementing cloud control frameworks and translating regulatory, compliance, and security requirements into enforceable technical controls
- Deep understanding of Defense-in-Depth architecture and implementation of preventive, detective, corrective, and reporting controls
- Strong knowledge of Cloud Security Posture Management (CSPM), cloud security governance, compliance monitoring, vulnerability management, and security reporting
- Hands-on experience designing and implementing automated remediation solutions using cloud-native services, Infrastructure-as-Code, scripting, and CI/CD pipelines
- Strong understanding of cloud networking and security controls, including network segmentation, perimeter security, private connectivity, Zero Trust principles, and workload isolation
- Deep expertise in GCP security capabilities, including: Security Command Center (SCC),VPC Service Controls (VPC-SC),GCP Organization Policies, Access Levels, Ingress and Egress Controls, Service Perimeters, Data Exfiltration Protection
- Proven experience troubleshooting VPC-SC access issues through analysis of Cloud Audit Logs, policy violations, service perimeter configurations, and governance controls
- Strong understanding of cloud-native data protection controls, including: Encryption at Rest and In Transit, Key Management Systems (KMS),Hardware Security Modules (HSM),Secrets Management, Certificate Management, Cryptographic Key Lifecycle Governance
- Experience implementing and maintaining identity and access management controls, privileged access models, authentication, authorization, and federation patterns
- Good knowledge of DevOps and SDLC practices, including: GitHub, GitOps, Branching Strategies, Release Management, CI/CD Pipelines, Infrastructure Delivery Automation
- Experience integrating security controls into developer workflows and enterprise cloud operating models
- Excellent verbal, written, and interpersonal communication skills with the ability to communicate technical concepts to both technical and business audiences
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.