Verified today
Cloud Security Engineer
About the role
Cloud Security Engineer at HighRadius responsible for IAM, key management, and security automation across Azure, AWS, GCP. Leads implementation of IAM operations, SCPs, Azure Policies, and enterprise identity governance. Operates Azure Key Vault, AWS KMS, and HashiCorp Vault, enforcing cryptographic standards and TLS lifecycles. Designs cloud security baselines per CIS, NIST, ISO27001, configures Wiz, Prisma, and cloud-native firewalls. Manages Fortigate firewalls, NAT, VPN, IPS, and Zero Trust segmentation. Automates infrastructure with Terraform modules and Ansible playbooks, supports Kubernetes secret management. Maintains SOPs, runbooks, compliance docs, and audit support. Requires 5‑7 years experience, strong identity protocols, cloud IAM, Vault, Kubernetes, Linux, and Fortigate expertise.
What you’ll do
- Execute IAM provisioning, troubleshooting, RBAC/ABAC config, recertifications
- Manage AWS SCPs, enforce governance guardrails
- Build Azure Policies, initiatives, assignments per compliance
- Support IAM across Azure AD/Entra ID, AWS IAM, GCP IAM, Identity Center
- Assist IAM incident response, Level 2 escalations
- Operate Azure Key Vault, AWS KMS, key rotation, policies, certificates
- Enforce RSA, AES, ECC, TLS lifecycles, secure key access
- Implement CIS, NIST, ISO27001 baselines, guardrails
- Configure Wiz, Prisma for posture, cloud-native firewalls, NSGs
- Set up cloud-native firewalls, NSGs, routing, segmentation
- Manage Fortigate firewalls, policies, NAT, VPN, routing
- Oversee IPS/IDS, threat profiles, HA Active/Passive
- Support segmentation, micro‑segmentation, Zero Trust enforcement
- Review firewall rules, change management, impact assessments
- Analyze traffic, logs with FortiAnalyzer tools
- Develop Terraform modules for IAM, KMS, vault, firewall, controls
- Create Ansible playbooks for secret rollout, cert deployments, firewall config
- Support Kubernetes secret management, RBAC, service accounts, Vault injector
- Maintain SOPs, runbooks, architecture diagrams, compliance docs
- Support audits, security reviews, posture reporting
What you’ll bring
- Hands‑on Terraform & Ansible automation
- 5‑7 years experience in cloud security
- Deep knowledge of SAML, OAuth2, OIDC, LDAP, Kerberos
- Proficient with Azure AD/Entra ID, AWS IAM, GCP IAM
- Expertise in HashiCorp Vault, Azure Key Vault, AWS KMS
- Kubernetes RBAC, secrets, workload identity management
- PKI, TLS certificates, cryptographic primitives
- Linux admin RHEL/CentOS/Rocky Linux
- Fortigate firewall, NAT, VPN, IPS, URL filtering
Nice to have
Certifications: Azure Security Engineer, AWS Security, GCP Security, Fortinet NSE, AWS Security Specialty