Minfy
Website:
minfytech.com
Job details:
Job Description – Associate Cloud Security Engineer
Location: [Specify: e.g., Hyderabad / Hubli]
Experience: 1–4 years
Role Overview
The Associate Cloud Security Engineer plays a key role in supporting cloud security operations for multiple managed service clients. The role involves continuous monitoring, vulnerability management, incident response, and governance to ensure a compliant and secure multi-cloud ecosystem (AWS, Azure, and GCP).
The ideal candidate will work closely with the cloud operations and service delivery teams to identify risks, enforce security baselines, and contribute to automation and continuous improvement initiatives.
Key Responsibilities
Cloud Security Monitoring & Incident Management
- Monitor and respond to security alerts from client environments using tools such as AWS Security Hub, Azure Defender, and SIEM platforms (e.g., Sentinel, Splunk, QRadar).
- Perform initial triage, analysis, and escalation of incidents as per defined SOPs and SLAs.
- Collaborate with Cloud Operations and L3 teams for remediation and root cause analysis.
- Track incident metrics and prepare daily/weekly security reports for clients.
Vulnerability & Compliance Management
- Conduct scheduled vulnerability scans using Qualys, Tenable, or AWS Inspector.
- Support vulnerability remediation tracking and ensure SLA compliance.
- Maintain and report compliance status against CIS, NIST, ISO 27001, and client-specific baselines.
- Ensure proper patch compliance and assist in risk reporting dashboards.
Identity & Access Management
- Review and manage IAM policies, role assignments, and MFA enforcement across client environments.
- Assist in periodic access reviews and compliance reporting.
- Ensure adherence to least-privilege and zero-trust principles.
Automation & Process Enhancement
- Support automation of repetitive tasks such as policy checks and remediation using scripts (Python, PowerShell, or Terraform).
- Work with the DevOps and CloudOps teams to integrate security checks within CI/CD pipelines.
- Contribute to process improvement initiatives and knowledge base updates.
Governance, Reporting & Client Support
- Maintain accurate documentation of incidents, compliance evidence, and configurations.
- Generate monthly security posture and compliance reports for client reviews.
- Participate in client governance calls to present security insights and improvement actions.
- Support internal and client audits with required evidence and logs.
Required Skills & Competencies
- Foundational knowledge of cloud security concepts and services in AWS, Azure, or GCP.
- Familiarity with security frameworks: CIS Benchmarks, ISO 27001, NIST, SOC 2.
- Understanding of firewalls, VPNs, IDS/IPS, endpoint protection, and encryption concepts.
- Exposure to SIEM, vulnerability management, and security compliance tools.
- Basic scripting ability in Python, PowerShell, or Bash for automation.
- Strong analytical and problem-solving mindset.
- Good written and verbal communication for client-facing discussions.
Preferred Qualifications
- Bachelor’s degree in Computer Science, IT, Cybersecurity, or equivalent.
- Certifications (any of the following preferred):
- AWS Certified Cloud Practitioner / Security Specialty (Associate level)
- Microsoft SC-900 / AZ-900
- CompTIA Security+
- Google Associate Cloud Engineer
- Exposure to tools such as Prisma Cloud, GuardDuty, Defender for Cloud, Tenable, Qualys, or CrowdStrike.
Click on Apply to know more.