Role Description
Design and implement cloud security architecture across Azure, AWS, and OCI environments.
Configure and manage Microsoft Defender for Cloud, Defender for Endpoint (Plan 2), and Sentinel SIEM.
Implement and tune Azure Firewall, WAF policies (OWASP rules), and DDoS Protection.
Manage AWS security services including GuardDuty, Security Hub, Inspector, AWS Config, and Macie.
Configure OCI Cloud Guard, Security Zones, and Vulnerability Scanning Service (VSS).
Enforce security baselines, CIS Benchmarks, and regulatory compliance controls.
Implement EDR solutions and manage endpoint security posture across hybrid environments.
Design and review network security including NSGs, Security Groups, Security Lists, and NVA traffic inspection.
Integrate SIEM/SASE solutions and support SOC operations with detection and response runbooks.
Conduct security risk assessments, threat modelling, and security architecture reviews.
Prepare governance documentation, security artefacts, and executive-level security reporting.
Required Skills
6+ years of security engineering experience with 3+ years of cloud security experience in Azure, AWS, or OCI.
Hands-on experience with Microsoft Defender for Cloud, Microsoft Sentinel, and Defender for Endpoint.
Strong knowledge of cloud-native security services across at least two major cloud providers.
Experience with SIEM platforms, threat detection, and incident response.
Strong understanding of network security including Firewalls, WAF, IDS/IPS, and Zero Trust principles.
Familiarity with compliance frameworks including CIS, NIST, ISO 27001, and SOC 2.
Microsoft Certified: Security Operations Analyst (SC-200) or Azure Security Engineer (AZ-500) preferred.
AWS Security Specialty or OCI Security Professional certification is a strong asset.
Nice to Have
Experience with SASE solutions such as Zscaler, Palo Alto Prisma, or Netskope.
Primary Skill
Cloud Security Management