Job Summary:
The Cloud Security Engineer is responsible for designing, implementing, and managing multi-cloud network security controls across Azure and Google Cloud Platform (GCP). This role focuses on delivering secure infrastructure using Terraform-based Infrastructure-as-Code (IaC) integrated with modern CI/CD pipelines such as Azure DevOps and GitHub Actions. The engineer will build secure, automated cloud environments, support Kubernetes deployments using GitOps frameworks, and ensure enterprise-grade security controls across cloud infrastructure while supporting incident response and operational stability.
Key Responsibilities:
• Design, implement, and manage cloud-native network security controls across Azure and GCP environments
• Configure and maintain Azure Network Security Groups (NSGs) and GCP security controls such as VPC Service Controls (VPC-SC), Cloud Armor, and Next-Gen Firewall (NGFW) with IPS/IDS
• Develop, maintain, and scale Terraform-based Infrastructure-as-Code modules for cloud infrastructure and security policies
• Build and manage CI/CD automation pipelines using Azure DevOps Pipelines and GitHub Actions
• Support Kubernetes deployments and GitOps workflows using Argo CD to enable secure and reliable application deployments
• Collaborate with cloud, security, and development teams to design secure and scalable cloud architectures
• Create technical documentation, operational runbooks, and knowledge transfer materials for internal teams
• Participate in Agile ceremonies and support planned project delivery within cloud security initiatives
• Provide rapid incident response and troubleshooting support during P0-P3 security and networking incidents
• Ensure compliance with enterprise cloud security standards and best practices
Required Skills & Experience:
• 5+ years of hands-on experience as a Cloud Engineer, Cloud Security Engineer, or DevOps Engineer
• Strong expertise in Terraform including reusable module design, state management, and enterprise workflows
• Strong experience with Azure and GCP network security services including NSGs, VPC-SC, Cloud Armor, and NGFW with IPS/IDS
• Experience building CI/CD pipelines using Azure DevOps and GitHub Actions
• Familiarity with GitOps tools such as Argo CD or Flux for Kubernetes deployments
• Scripting experience using PowerShell, Bash, or Python for automation and troubleshooting
• Strong troubleshooting skills and experience handling cloud security incidents
• Experience documenting architecture designs, runbooks, and knowledge transfer documentation
Competencies:
• Strong analytical and problem-solving skills in cloud environments
• Ability to design secure and scalable multi-cloud architectures
• Strong collaboration with cloud engineering, security, and DevOps teams
• Ability to work in fast-paced environments balancing project delivery and incident response
• Strong communication and documentation skills
Preferred Skills:
• Experience securing Kubernetes workloads in AKS (Azure Kubernetes Service) and GKE (Google Kubernetes Engine)
• Exposure to CI/CD platforms such as GitLab CI, Jenkins, or CircleCI
• Experience with configuration management tools such as Ansible
• Knowledge of enterprise DevSecOps and GitOps practices
Preferred Certifications:
• Microsoft Azure Security Engineer Associate
• Azure Solutions Architect Expert
• Google Professional Cloud Security Engineer
• Google Professional Cloud Architect
• HashiCorp Certified: Terraform Associate
• Certified Kubernetes Administrator (CKA) or Certified Kubernetes Application Developer (CKAD)
• Azure DevOps Engineer Expert