About the job
Reporting to: Senior IT Security Manager
About the Role
We are seeking a proactive and skilled Cloud Security Analyst who possesses extensive expertise in the realms of cloud-native and container security. This pivotal position focuses on safeguarding expansive, multi-cloud, and Kubernetes-centric environments.
In this role, you will be instrumental in establishing security protocols, enforcing robust baselines, and enhancing our detection and response frameworks. You will collaborate closely with DevOps, Networking, and SOC teams to integrate security throughout every layer of our design and automation processes.
Key Responsibilities
Enhance and streamline cloud-native security measures including IAM, network security (WAF, VPC), and data protection (KMS, Vault).
Implement and oversee CSPM, CNAPP, and CWPP solutions to ensure a continuous security posture across multi-cloud and Kubernetes settings.
Incorporate cloud telemetry (GCP Audit Logs, AWS CloudTrail, Azure Monitor, Kubernetes audit logs) into SIEM/SOAR platforms for consolidated visibility.
Design and enforce cloud security architecture and guardrails in accordance with Zero Trust and Least Privilege principles.
Develop and uphold Security-as-Code practices using Terraform, CloudFormation, or Bicep, including policy-as-code frameworks.
Manage and improve the security posture of containerized environments (GKE, AKS, EKS), focusing on image, registry, and runtime security.
Fortify Kubernetes clusters utilizing RBAC, NetworkPolicies, Admission Controllers, and secure configurations.
Lead cloud security incident response operations including triage, containment, and forensic investigations.
Continuously assess emerging threats, vulnerabilities, and attack vectors within cloud-native ecosystems.
Required Qualifications
Experience
5+ years of experience in Information Security.
At least 3 years of experience specifically in Cloud Security.
A minimum of 2 years working with Kubernetes/container security.
Cloud Expertise
Hands-on experience with at least two major cloud platforms (preferably GCP and Azure; AWS/OCI experience is a plus).
Container & Kubernetes Security
In-depth understanding of Kubernetes security controls (RBAC, Secrets, Ingress, TLS).
Familiarity with container runtime security and orchestration tools.
Technical Skills
Proficient in scripting languages (Python preferred; Bash or Go is a plus).
Working knowledge of Infrastructure as Code (IaC) and automation methodologies.
Security Frameworks & Compliance
Familiarity with ISO 27001, SOC 2, NIST, and CIS Benchmarks.

