
Lead Security Engineer – Cloud Security, Architecture
Posted Jul 21

Posted Jul 21
This is a fully remote position, open to applicants in India.
• Proven expertise in cloud security architecture across AWS/GCP/Azure, with a focus on designing secure and scalable cloud environments emphasizing identity, network security, encryption, and compliance best practices.
• Significant experience in performing security architecture reviews for distributed systems and cloud-native applications, identifying potential design risks at an early stage, and suggesting secure, scalable architectural patterns that align with business and engineering objectives.
• Lead and execute both manual and automated penetration testing across applications, APIs, and cloud services.
• Facilitate threat modeling and secure architecture evaluations across application and infrastructure layers.
• Work collaboratively with Infra/DevOps teams on cloud network architecture, including design of VPCs, security groups, routing, and segmentation.
• Design and provide guidance on cloud-native security controls such as IAM hardening, role boundaries, secrets management, and least privilege access.
• Assess and enhance the security posture of Kubernetes and container environments (covering runtime, image, and network layers).
• Implement secure-by-default patterns throughout the SDLC, CI/CD processes, and Infrastructure-as-Code practices.
• Monitor emerging threats, CVEs, and vulnerabilities pertinent to our technology stack (web, cloud, infrastructure).
• Shape internal security tools, automation pipelines, and security review methodologies.
• Act as a security consultant for engineering, SRE, and product teams on significant projects.
• Over 8 years of experience in Application Security, Product Security, or Cloud Security, with a strong emphasis on securing large-scale cloud-native applications.
• Extensive hands-on experience in **threat modeling**, **secure architecture reviews**, and **penetration testing**.
• Familiarity with the **OWASP Top 10**, STRIDE, and contemporary security frameworks.
• Proficient with tools such as **Burp Suite, ZAP, Snyk, Metasploit, Semgrep**.
• Ability to read and analyze code in languages such as **JavaScript, Go, PHP**, or **Node.js**.
• Working knowledge of **cloud security principles**, preferably with AWS.
• Competitive salary and performance-based bonuses.
• Comprehensive health, dental, and vision insurance.
• Flexible working hours and remote work opportunities.
• Professional development programs and continuous learning opportunities.
• A collaborative and inclusive work environment.
SPD Technology
Totara
Vesta Software Group
Elfonze Technologies
Get handpicked remote jobs straight to your inbox weekly.