<p style="margin: 0in;"><span style="color: black;"><span style="font-size: 15pt;"><strong>Job Title: Cloud Security Engineer </strong></span></span></p><p style="margin: 0in;"><span style="color: black;"><strong>Location: Offshore, India</strong></span></p><p style="margin: 0in;"><span style="color: black;"><strong>Experience: 8-10 years</strong></span></p><p style="margin: 0in 0in 9pt;"> </p><p style="margin: 0in 0in 11.2pt;"><span style="color: black;"><span style="font-size: 15pt;"><strong>Role Overview</strong></span></span></p><p style="margin: 0in 0in 9pt;"><span style="color: black;">We are seeking a highly skilled Cloud Security Engineer to design, implement, and maintain robust security controls for AWS cloud environments. This role is critical in securing the migration of banking infrastructure from on-premises data centers to AWS, ensuring compliance with financial regulations, data protection standards, and industry best practices.</span></p><p style="margin: 0in 0in 9pt;"> </p><p style="margin: 0in 0in 9pt;"><span style="color: black;">The candidate must have deep expertise in AWS security services, cloud security posture management, and data protection strategies within highly regulated environments such as banking or financial services.</span></p><p style="margin: 0in 0in 9pt;"> </p><p style="margin: 0in 0in 11.2pt;"><span style="color: black;"><span style="font-size: 15pt;"><strong>Key Responsibilities</strong></span></span></p><p style="margin: 0in 0in 9pt;"> </p><p style="margin: 0in 0in 10.5pt;"><span style="color: black;"><span style="font-size: 13.5pt;"><strong> Cloud Security Architecture & Migration</strong></span></span></p><ul style="list-style-type: disc; padding-left: 47.6px;"><li><p><span style="color: black;">Implement and secure AWS architectures for migrating on-premises banking workloads.</span></p></li><li><p><span style="color: black;">Perform threat modeling and risk assessments for migration strategies (rehost, replatform, refactor).</span></p></li><li><p><span style="color: black;">Define secure landing zones using AWS best practices (multi-account strategy, segmentation).</span></p></li><li><p><span style="color: black;">Ensure secure connectivity (VPN, Direct Connect) between on-prem and AWS environments.</span></p></li><li><p><span style="color: black;">Collaborate with infrastructure and DevOps teams to embed security into migration pipelines.</span></p></li></ul><p style="margin: 0in 0in 9pt;"> </p><p style="margin: 0in 0in 9pt;"> </p><p style="margin: 0in 0in 10.5pt;"><span style="color: black;"><span style="font-size: 13.5pt;"><strong>AWS Cloud Security Controls</strong></span></span></p><ul style="list-style-type: disc; padding-left: 48px;"><li><p><span style="color: black;">Implement and manage AWS-native security services, including:</span></p><ul style="list-style-type: circle; padding-left: 48px;"><li><p><span style="color: black;">Identity & Access Management (IAM) with least privilege access</span></p></li><li><p><span style="color: black;">AWS Organizations and Service Control Policies (SCPs)</span></p></li><li><p><span style="color: black;">AWS Key Management Service (KMS) for encryption</span></p></li><li><p><span style="color: black;">AWS CloudTrail, CloudWatch, GuardDuty, Security Hub</span></p></li></ul></li><li><p><span style="color: black;">Establish strong access control mechanisms (RBAC/ABAC, MFA enforcement).</span></p></li><li><p><span style="color: black;">Harden compute, storage, and network layers (EC2, S3, RDS, VPC).</span></p></li><li><p><span style="color: black;">Experience in banking/financial services or other regulated industries.</span></p></li><li><p><span style="color: black;">Strong understanding of:</span></p><ul style="list-style-type: circle; padding-left: 48px;"><li><p><span style="color: black;">Data protection and privacy regulations</span></p></li><li><p><span style="color: black;">Secure migration strategies and risks</span></p></li></ul></li><li><p><span style="color: black;">Ensure adherence to banking and financial regulatory requirements.</span></p></li><li><p><span style="color: black;">Work closely with GRC teams to align cloud security with enterprise policies</span></p></li></ul><p style="margin: 0in 0in 10.5pt;"> </p><p style="margin: 0in 0in 10.5pt;"><span style="color: black;"><span style="font-size: 13.5pt;"><strong>Data Security & Protection</strong></span></span></p><ul style="list-style-type: disc; padding-left: 48px;"><li><p><span style="color: black;">Design and enforce data protection strategies for sensitive banking data:</span></p><ul style="list-style-type: circle; padding-left: 48px;"><li><p><span style="color: black;">Encryption at rest and in transit</span></p></li><li><p><span style="color: black;">Tokenization, masking, and anonymization</span></p></li></ul></li><li><p><span style="color: black;">Implement secure key lifecycle management and HSM integration if required.</span></p></li><li><p><span style="color: black;">Define data classification and data loss prevention (DLP) controls.</span></p></li></ul><p style="margin: 0in 0in 9pt;"> </p><p style="margin: 0in 0in 10.5pt;"><span style="color: black;"><span style="font-size: 13.5pt;"><strong>Cloud Security Posture Management (CSPM)</strong></span></span></p><ul style="list-style-type: disc; padding-left: 47.6px;"><li><p><span style="color: black;">Implement and manage CSPM tools (e.g., AWS Security Hub, Prisma Cloud, Wiz, Orca).</span></p></li><li><p><span style="color: black;">Continuously monitor for misconfigurations, vulnerabilities, and compliance gaps.</span></p></li><li><p><span style="color: black;">Automate remediation using Infrastructure as Code (IaC) and security tooling.</span></p></li></ul><p style="margin: 0in 0in 10.5pt;"> </p><p style="margin: 0in 0in 10.5pt;"><span style="color: black;"><span style="font-size: 13.5pt;"><strong>Automation</strong></span></span></p><ul style="list-style-type: disc; padding-left: 47.6px;"><li><p><span style="color: black;">Integrate security into CI/CD pipelines (SAST, DAST, dependency scanning).</span></p></li><li><p><span style="color: black;">Define guardrails using Infrastructure as Code (Terraform, CloudFormation).</span></p></li><li><p><span style="color: black;">Automate security checks and policy enforcement (e.g., using AWS Config rules).</span></p></li><li><p><span style="color: black;">Enable secure secrets management (AWS Secrets Manager, Parameter Store).</span></p></li></ul><p style="margin: 0in 0in 11.2pt;"> </p><p style="margin: 0in 0in 11.2pt;"><span style="color: black;"><span style="font-size: 15pt;"><strong>Required Skills & Experience</strong></span></span></p><ul style="list-style-type: disc; padding-left: 48px;"><li><p><span style="color: black;">Strong hands-on experience with AWS cloud security services.</span></p></li><li><p><span style="color: black;">Deep understanding of:</span></p><ul style="list-style-type: circle; padding-left: 48px;"><li><p><span style="color: black;">IAM, VPC security, encryption, network segmentation</span></p></li><li><p><span style="color: black;">Cloud-native logging and monitoring</span></p></li></ul></li><li><p><span style="color: black;">Experience with CSPM and vulnerability management tools.</span></p></li><li><p><span style="color: black;">Familiarity with hybrid cloud environments (on-prem + AWS).</span></p></li><li><p><span style="color: black;">Proficiency in scripting (Python, Bash) and IaC (Terraform/CloudFormation).</span></p></li><li><p><span style="color: black;">Strong analytical and problem-solving skills.</span></p></li><li><p><span style="color: black;">Ability to work cross-functionally with infrastructure, DevOps, and compliance teams.</span></p></li><li><p><span style="color: black;">Excellent communication skills for technical and non-technical stakeholders.</span></p></li></ul><p style="margin: 0in 0in 11.2pt;"> </p><p style="margin: 0in 0in 11.2pt;"><span style="color: black;"><span style="font-size: 15pt;"><strong>Preferred Qualifications</strong></span></span></p><ul style="list-style-type: disc; padding-left: 47.6px;"><li><p><span style="color: black;">AWS Certifications (e.g., AWS Certified Security – Specialty).</span></p></li><li><p><span style="color: black;">Experience with zero trust architecture and micro-segmentation.</span></p></li><li><p><span style="color: black;">Exposure to container and Kubernetes security (EKS).</span></p></li><li><p><span style="color: black;">Knowledge of SIEM/SOAR platforms.</span></p></li></ul><p> </p>
<br>At Zensar, we’re <i>“experience-led everything”</i>. We are committed to conceptualizing, designing, engineering, marketing, and managing digital solutions and experiences for over 130 leading enterprises. We are a company driven by a bold purpose: <i>Together, we shape experiences for better futures</i>. Whether for our clients, our people, or the world around us, this belief powers everything we do. At the heart of our culture is <i>ONE with Client</i> - a set of four core values that reflect who we are and how we work: <i>One Zensar, Nurturing, Empowering, and Client Focus</i>.<br><br> Part of the $4.8 billion RPG Group, we’re a community of 10,000+ innovators across 30+ global locations, including Milpitas, Seattle, Princeton, Cape Town, London, Zurich, Singapore, and Mexico City. Explore <a href="https://www.zensar.com/careers/" target="_blank">Life at Zensar</a> and join us to <a href="https://www.youtube.com/embed/i2NZsiQqVnU?autoplay=1&fs=1" target="_blank">Grow. Own. Achieve. Learn.</a> to be the best version of yourself.<br><br> We believe the best work happens when individuality is celebrated, growth is encouraged, and well-being is prioritized. We are an equal employment opportunity (EEO) and affirmative action employer, committed to creating an inclusive workplace. All qualified applicants will be considered without regard to race, creed, color, ancestry, religion, sex, national origin, citizenship, age, sexual orientation, gender identity, disability, marital status, family medical leave status, or protected veteran status.