Search by job, company or skills

Security Architect

  • Posted 17 hours ago
  • Be among the first 10 applicants

Job Description

Project Role : Security Architect

Project Role Description : Define the cloud security framework and architecture, ensuring it meets the business requirements and performance goals. Document the implementation of the cloud security controls and transition to cloud security-managed operations.

Must have skills : Amazon Web Services (AWS) Security

Good to have skills : NA

Minimum 3 Year(s) Of Experience Is Required

Educational Qualification : 15 years full time education

Summary:

We are looking for an AWS IAM Engineer with experience to provide L2/L3 operational support across IAM, SSO, MFA, RBAC, and PAM services. The role requires strong troubleshooting skills, a sound understanding of AWS identity services, and the ability to manage access policies, handle incidents, and deliver clear operational reporting.

Roles & Responsibilities:

Operations and service delivery

  • Handle incidents, service requests and change requests across the AWS security service portfolio, meeting agreed response and resolution service levels.
  • Triage and action findings, alerts and policy violations, escalating to the client or to vendor support where required.
  • Deliver planned changes within approved maintenance windows, including firewall and WAF rule changes, policy updates and configuration amendments.
  • Produce daily operational reports and maintain runbooks, standard operating procedures and knowledge articles.
  • Participate in problem management, contributing root cause analysis for major incidents within agreed timelines.

Technical ownership

  • Administer AWS WAF rule groups and conditions, tune rules to reduce false positives and false negatives, and manage Firewall Manager security policies.
  • Maintain AWS Config rules, including custom rules, organisation and organisational unit rules, and multi-account deployment.
  • Operate AWS Security Hub, including central configuration policies, service integrations and findings workflow.
  • Manage AWS GuardDuty findings and suppression rules, protection plans, runtime monitoring and cross-account aggregation.
  • Administer AWS IAM roles, policies and permission boundaries perform access reviews, credential reporting and key rotation.
  • Support AWS KMS and Secrets Manager operations, including key policy, rotation and access control.
  • Maintain AWS CloudTrail configuration across accounts, including data events, retention and downstream log integrations.
  • Operate AWS Shield Advanced and AWS Certificate Manager, including certificate lifecycle and renewal monitoring.
  • Manage Palo Alto VM-Series firewalls deployed on AWS and maintain AWS Security Group rule sets.

Essential Skills And Experience


  • AWS WAF — rule groups, conditions, rule tuning, Firewall Manager security policies.
  • AWS Config — managed and custom rules, trigger and evaluation modes, organisation, OU and multi-account rules, configuration history and retention.
  • AWS Security Hub — central configuration policies, integration with GuardDuty, Inspector and Macie, findings management.
  • AWS GuardDuty — findings analysis, suppression rules, protection plans, cross-region and cross-account aggregation.
  • AWS IAM — roles, policies, permission boundaries, Access Analyzer, credential reports, access key and secret key rotation.
  • AWS KMS and AWS Secrets Manager — customer managed keys, symmetric and asymmetric encryption, key and secret rotation, access control.
  • AWS CloudTrail — multi-account trails, data events, log retention and aggregation.
  • AWS Shield Advanced and AWS Certificate Manager.
  • AWS Security Groups and network security concepts in a VPC context.
  • Working within an ITIL service management framework — incident, change and problem management, ideally on ServiceNow.
  • Depth across AWS WAF, Config, Security Hub and IAM is the core requirement. Candidates with particular strength in identity and key management — IAM, federated identity, IAM Identity Center and KMS — should highlight this, as a subset of the positions is weighted that way.

Professional & Technical Skills:

  • Federated identity with AWS — OIDC and SAML identity providers, IAM Identity Center including Active Directory integration.
  • Automated remediation using EventBridge and Lambda.
  • Infrastructure as code and scripting — Terraform, CloudFormation, Python or Boto3.
  • Palo Alto VM-Series and Panorama on public cloud.
  • AWS CloudHSM.
  • Log and monitoring platforms — CloudWatch, Splunk, Dynatrace.
  • Regulated industry experience, particularly life sciences or pharmaceutical, and familiarity with GxP or CIS benchmark controls.

Additional Information:

  • The candidate should have minimum 6 years of experience in AWS Administration.
  • This position is based at our Bengaluru office.
  • A 15 years full time education is required.






More Info

Job Type:
Industry:
Employment Type:

About Company

Job ID: 152933597

Similar Jobs

Bengaluru, India

Skills:

CloudformationCloudwatchTerraformAWS IAMDynatraceAWS Security HubSplunkPythonPalo Alto VM-SeriesAWS Certificate ManagerAWS KMSAWS Shield AdvancedAWS CloudTrailAWS ConfigAWS WAFAWS Secrets ManagerAWS SecurityBoto3AWS GuardDuty

Bengaluru, India

Skills:

SamlHipaaGdprOauthLdapAWSPAMDigital CertificatesIamGcpEncryptionMicrosoft AzureSsoNIST-CSFRisk Mitigation StrategiesMFASecrets ManagementCIS ControlsActive DirectoryOpenID ConnectSoxZero Trust Security Models

Bengaluru, India

Skills:

API securityIso 27001SamlAWSUK Cyber EssentialsOAuth 2.0data governance for training pipelinessecure SDLC practicesIAM policiescloud security architectureprompt injection mitigationSOC 2Kubernetes securityserverless security patternsencryption strategiesNIST CSFVPC designinfrastructure-as-code securityapplication security principlesAI ML security conceptsISO IEC 42001NIST AI RMFOIDCmodel security

Beware of Scammers

We don’t charge money for job offers