- Company Name
- Tekshapers
- Job Title
- Cloud Security (W2)
- Job Description
-
**Job Title:** Cloud Security Engineer (W2)
**Role Summary:**
Design, implement, and maintain infrastructure‑as‑code (IaC) security scanning, firewall policies, and risk management across AWS, Azure, and GCP environments. Ensure compliance with NIST, CIS, ISO 27001, and other industry standards.
**Expectations:**
Apply 7+ years of cloud/security experience to safeguard IaC artifacts, firewall rules, and overall cloud architecture. Deliver documentation for internal and external audits.
**Key Responsibilities:**
- Integrate IaC security scanners (Checkov, TFSec, Snyk IaC, Terraform Validator) into CI/CD pipelines.
- Analyze scan findings for Terraform, CloudFormation, ARM templates; remediate issues and develop custom policy rules.
- Design native firewall rules for AWS (Security Groups, NACLs), Azure (NSGs), GCP (VPC Firewall).
- Optimize, consolidate, and risk‑tune firewall configurations to minimize attack surface.
- Conduct routine reviews and audits of firewall settings and access controls.
- Align security controls with NIST, CIS, ISO 27001, and support audit evidence preparation.
**Required Skills:**
- Deep expertise in IaC tools: Terraform, CloudFormation, ARM, and related automation.
- Strong knowledge of cloud-native firewall services for AWS, Azure, GCP.
- Proficiency with security scanners: Checkov, Prisma Cloud, Aqua, Snyk, etc.
- Automation scripting in PowerShell, Bash, Python.
- Ability to create and enforce custom security policies.
**Required Education & Certifications:**
- Bachelor's degree in Computer Science, Cybersecurity, or related field.
- Preferred certifications: AWS/Azure/GCP Security Specialty, CISSP, CCSP, Terraform Associate.