Sutherland

Lead Cloud Security Engineer

Sutherland Hyderabad, Telangana, India

IT Services and IT Consulting · 10,001+ employees

8 h ago
security Principal (10+ yrs) Full-time India
Log in to apply, save this posting, or score it against your profile with AI.

About the role

Design and govern secure, scalable cloud architectures and security standards across multi-cloud environments. Manage cloud security posture, threat modeling, and incident response while providing technical leadership to the security team.

What they look for

Cloud Security Azure AWS OCI GCP IAM CSPM CWPP SIEM Zero Trust Threat Modeling Incident Response Vulnerability Management Compliance Security Architecture Leadership

Requirements

Requires 10+ years of experience in Information Security with at least 5+ years in cloud security implementation and governance. Expertise in multi-cloud environments (Azure, OCI, AWS, GCP) and knowledge of security frameworks like NIST, ISO 27001, and SOC 2 is essential.

Full description

Company Description

Sutherland is an experience-led digital transformation company. Our mission is to deliver exceptionally engineered experiences for customers and employees today, that continue to delight tomorrow. For over 37 years, we have cared for our clients' customers, delivering measurable results and accelerating growth.

Job Description

Position Summary

We are seeking an experienced Lead Cloud Security Engineer with 10+ years of experience in Information Security and at least 5+ years in Cloud Security implementation, and governance of security controls across multi-cloud environments (Azure, OCI, AWS, GCP). The role focuses on cloud security architecture, compliance, security operations, threat management, and continuous improvement of the organization's cloud security posture.

Key Responsibilities

  • Design and govern secure, scalable cloud architectures, security standards, policies, guardrails, and landing zones across multi-cloud environments.
  • Own and enhance the Cloud Security Posture Management (CSPM) program, ensuring alignment with NIST, ISO 27001, CIS Benchmarks, SOC 2, PCI-DSS, GDPR, and Cloud Security Alliance frameworks.
  • Perform threat modeling, security architecture reviews, risk assessments, and defining remediation strategies.
  • Implement and manage cloud security controls including IAM, MFA, PAM, SSO, Zero Trust, CSPM, and Cloud Workload Protection (CWPP).
  • Monitor cloud environments for threats, vulnerabilities, and misconfigurations, drive remediation with platform and application teams.
  • Investigate and respond to cloud security incidents, support forensic investigations, and integrate cloud logs into SIEM platforms.
  • Detect, investigate, and respond to cloud-based security incidents.
  • Analyze logs from cloud-native services such as Defender for Cloud, OCI Cloud Guard, AWS CloudTrail, Azure Monitor, and GCP Logging.
  • Support vulnerability management (Tannable), EDR  (Sentinel One), Stellar  XDR and Cyber AI Behavior Analytics , Defender for Office 365 email security monitoring solutions.
  • Ensure audit readiness, compliance reporting, and maintenance of cloud security documentation, standards, and procedures.
  • Provide technical leadership, mentor security engineers, and collaborate with business and technology stakeholders to strengthen cloud security capabilities.

Required Skills & Experience

  • Strong hands-on experience securing Azure, OCI, and AWS and GCP environments.
  • Expertise in IAM, cloud-native security services, CSPM, CWPP, SIEM, Zero Trust, and cloud security operations.
  • Experience with threat modeling, security architecture reviews, incident response, vulnerability management, and compliance assessments.
  • Knowledge of ISO 27001, NIST, CIS Benchmarks, SOC 2, PCI-DSS, and GDPR.
  • Experience with Tenable, SentinelOne, cloud logging, and security monitoring platforms.
  • Strong communication, stakeholder management, and leadership skills.

Qualifications

Position Summary

We are seeking an experienced Lead Cloud Security Engineer with 10+ years of experience in Information Security and at least 5+ years in Cloud Security implementation, and governance of security controls across multi-cloud environments (Azure, OCI, AWS, GCP). The role focuses on cloud security architecture, compliance, security operations, threat management, and continuous improvement of the organization's cloud security posture.

Key Responsibilities

  • Design and govern secure, scalable cloud architectures, security standards, policies, guardrails, and landing zones across multi-cloud environments.
  • Own and enhance the Cloud Security Posture Management (CSPM) program, ensuring alignment with NIST, ISO 27001, CIS Benchmarks, SOC 2, PCI-DSS, GDPR, and Cloud Security Alliance frameworks.
  • Perform threat modeling, security architecture reviews, risk assessments, and defining remediation strategies.
  • Implement and manage cloud security controls including IAM, MFA, PAM, SSO, Zero Trust, CSPM, and Cloud Workload Protection (CWPP).
  • Monitor cloud environments for threats, vulnerabilities, and misconfigurations, drive remediation with platform and application teams.
  • Investigate and respond to cloud security incidents, support forensic investigations, and integrate cloud logs into SIEM platforms.
  • Detect, investigate, and respond to cloud-based security incidents.
  • Analyze logs from cloud-native services such as Defender for Cloud, OCI Cloud Guard, AWS CloudTrail, Azure Monitor, and GCP Logging.
  • Support vulnerability management (Tannable), EDR  (Sentinel One), Stellar  XDR and Cyber AI Behavior Analytics , Defender for Office 365 email security monitoring solutions.
  • Ensure audit readiness, compliance reporting, and maintenance of cloud security documentation, standards, and procedures.
  • Provide technical leadership, mentor security engineers, and collaborate with business and technology stakeholders to strengthen cloud security capabilities.

Required Skills & Experience

  • Strong hands-on experience securing Azure, OCI, and AWS and GCP environments.
  • Expertise in IAM, cloud-native security services, CSPM, CWPP, SIEM, Zero Trust, and cloud security operations.
  • Experience with threat modeling, security architecture reviews, incident response, vulnerability management, and compliance assessments.
  • Knowledge of ISO 27001, NIST, CIS Benchmarks, SOC 2, PCI-DSS, and GDPR.
  • Experience with Tenable, SentinelOne, cloud logging, and security monitoring platforms.
  • Strong communication, stakeholder management, and leadership skills.

Additional Information

All your information will be kept confidential according to EEO guidelines.

Similar roles