Security Engineer
احفظ هذه الوظيفة وحافظ على تنظيم بحثك
قم بإنشاء حساب مجاني لحفظ الوظائف وإنشاء التنبيهات والعودة إلى هذه القائمة من لوحة التحكم الخاصة بك.
The Cloud Security Engineer is responsible for securing Avrioc's cloud-native infrastructure,
applications, and workloads hosted in AWS and Azure. The role designs and enforces proactive
security controls across the full cloud stack, monitors and responds to threats, integrates
security into CI/CD pipelines, and manages firewall and perimeter defenses using AWS and
Azure native and third‑party tooling, strengthening the organization's cloud security posture in
line with industry best practice and enterprise governance standards
Key Responsibilities & Accountabilities:- Design, implement, and manage secure cloud architectures across AWS and Azure environments, adhering to industry best practices, security frameworks, and enterprise governance standards.
- Manage AWS Control Tower and Landing Zone Accelerator environments, including account governance, Service Control Policies (SCPs), Guardrails, AWS Config Rules, and AWS Organizations security controls.
- Design and implement Azure Landing Zones, Management Groups, Azure Policy, Azure Blueprints, and enterprise governance frameworks.
- Implement, configure, and manage cloud-native security services, including:
- AWS: GuardDuty, Security Hub, Inspector, Macie, IAM Access Analyzer, AWS Config, CloudTrail, AWS WAF, Shield, Firewall Manager, KMS, and Secrets Manager.
- Define and manage operational processes for cloud security monitoring, alert triage, incident response, ticketing, and remediation through SIEM/SOAR platforms such as Microsoft Sentinel, Elastic SIEM, and Microsoft Defender XDR, and ITSM platforms including Jira and ServiceNow.
- Provision and manage cloud infrastructure hands‑on using Infrastructure as Code (IaC) with Terraform, AWS CloudFormation, Azure ARM Templates, or Bicep.
- Implement IaC security controls by integrating automated security scanning, policy validation, compliance checks, and infrastructure misconfiguration detection into CI/CD pipelines using industry-standard tools and best practices.
- Conduct cloud security incident investigations, forensic analysis, and Root Cause Analysis (RCA), working closely with engineering teams to implement permanent corrective actions.
- Perform vulnerability management across cloud infrastructure, virtual machines, containers, Kubernetes clusters, serverless workloads, storage services, databases, and cloud-native applications.
- Implement cloud identity and access security using AWS IAM, IAM Identity Center, Microsoft Entra ID, Privileged Identity Management (PIM), Role-Based Access Control (RBAC), Conditional Access, Multi‑Factor Authentication (MFA), and Zero Trust security
- Design and secure cloud networking components including VPC/VNet, Security Groups, ExpressRoute, Application Load Balancers, and Network Load Balancers.
- Develop and maintain cloud security dashboards, KPIs/KRIs, operational runbooks, architecture diagrams, compliance reports, and standard operating procedures.
- AWS Certified Security — Specialty
- Microsoft Certified: Azure Security Engineer Associate (AZ‑500)
- Certified Cloud Security Professional (CCSP)
- GIAC Cloud Security Automation (GCSA)
- CISSP or other relevant cloud security certifications