أبلاي إيدج ابدأ البحث عن عمل

Security Engineer

Avrioc Technologies · Abu Dhabi Emirate, United Arab Emirates

قدّم وتابع مع أبلاي إيدج
Job Description:The Cloud Security Engineer is responsible for securing Avrioc's cloud-native infrastructure,applications, and workloads hosted in AWS and Azure. The role designs and enforces proactivesecurity controls across the full cloud stack, monitors and responds to threats, integratessecurity into CI/CD pipelines, and manages firewall and perimeter defenses using AWS andAzure native and third-party tooling, strengthening the organization's cloud security posture inline with industry best practice and enterprise governance standardsKey Responsibilities & Accountabilities:Design, implement, and manage secure cloud architectures across AWS and Azureenvironments, adhering to industry best practices, security frameworks, and enterprisegovernance standards.• Manage AWS Control Tower and Landing Zone Accelerator environments, including accountgovernance, Service Control Policies (SCPs), Guardrails, AWS Config Rules, and AWSOrganizations security controls.• Design and implement Azure Landing Zones, Management Groups, Azure Policy, AzureBlueprints, and enterprise governance frameworks.• Implement, configure, and manage cloud-native security services, including:◦ AWS: GuardDuty, Security Hub, Inspector, Macie, IAM Access Analyzer, AWS Config,CloudTrail, AWS WAF, Shield, Firewall Manager, KMS, and Secrets Manager.◦ Azure: Microsoft Defender for Cloud, Microsoft Sentinel, Azure Firewall, Azure DDoSProtection, Azure Key Vault, Azure Policy, Microsoft Entra ID (Azure AD), and MicrosoftDefender for Identity.• Define and manage operational processes for cloud security monitoring, alert triage,incident response, ticketing, and remediation through SIEM/SOAR platforms such asMicrosoft Sentinel, Elastic SIEM, and Microsoft Defender XDR, and ITSM platformsincluding Jira and ServiceNow.• Provision and manage cloud infrastructure hands-on using Infrastructure as Code (IaC) withTerraform, AWS CloudFormation, Azure ARM Templates, or Bicep.• Implement IaC security controls by integrating automated security scanning, policyvalidation, compliance checks, and infrastructure misconfiguration detection into CI/CDpipelines using industry-standard tools and best practices.• Conduct cloud security incident investigations, forensic analysis, and Root Cause Analysis(RCA), working closely with engineering teams to implement permanent corrective actions.• Perform vulnerability management across cloud infrastructure, virtual machines,containers, Kubernetes clusters, serverless workloads, storage services, databases, andcloud-native applications.• Implement cloud identity and access security using AWS IAM, IAM Identity Center,Microsoft Entra ID, Privileged Identity Management (PIM), Role-Based Access Control(RBAC), Conditional Access, Multi-Factor Authentication (MFA), and Zero Trust securityprinciples.• Design and secure cloud networking components including VPC/VNet, Security Groups,NSGs, NACLs, Transit Gateway, Azure Virtual WAN, Private Link, VPN, Direct Connect,ExpressRoute, Application Load Balancers, and Network Load Balancers.• Develop and maintain cloud security dashboards, KPIs/KRIs, operational runbooks,architecture diagrams, compliance reports, and standard operating procedures.Certifications (preferred)• AWS Certified Security — Specialty• Microsoft Certified: Azure Security Engineer Associate (AZ-500)• Certified Cloud Security Professional (CCSP)• GIAC Cloud Security Automation (GCSA)• Certified Kubernetes Security Specialist (CKS) or Certified Kubernetes Administrator (CKA)• CISSP or other relevant cloud security certifications