About the job
About Us
At Renmoney, we prioritize the confidentiality, integrity, and availability of our cloud-hosted applications, data, and infrastructure. Our dedicated team employs the latest industry practices, advanced threat-mitigation strategies, and adheres to compliance standards such as ISO 27001 and PCI DSS to safeguard our dynamic cloud environment.
Your Role
As a Cloud Security Engineer, you will take charge of designing, implementing, and managing robust security controls across our cloud environments. You will ensure secure architectures, proactive threat detection, and continuous compliance across AWS, Azure, GCP, and other cloud-native technologies.
Key Responsibilities
- Cloud Security Architecture & Engineering: Design and implement secure cloud architectures for IaaS, PaaS, and SaaS platforms (AWS, Azure, GCP); apply Zero Trust principles, network segmentation, and establish secure landing zones; define and enforce cloud security baselines, hardening standards, and configuration policies.
- Cloud Security Operations: Manage cloud-native security tools (AWS Security Hub, GuardDuty, Azure Defender, GCP Security Command Center); monitor and rectify misconfigurations through CSPM and CIEM solutions; conduct ongoing security assessments and vulnerability remediation; integrate security tools (SAST and DAST) into DevOps pipelines.
- Identity & Access Management: Implement and oversee identity controls like IAM, RBAC, MFA, and conditional access policies; enforce least privilege access for users, applications, and services.
- Threat Detection & Incident Response: Analyze security alerts specific to the cloud, investigate suspicious activities, and manage incident responses; support threat hunting and logging activities using SIEM/SOAR platforms; develop runbooks and playbooks for cloud-related incidents.
- Compliance & Governance: Ensure cloud environments comply with internal security policies, regulatory requirements, and frameworks such as ISO 27001, PCI DSS, CIS Benchmarks, and NIST CSF; conduct periodic cloud compliance audits and offer remediation guidance.
- Documentation & Collaboration: Create and maintain security documentation including architecture diagrams, SOPs, and hardening guides; collaborate closely with DevOps, Networking, Infrastructure, and other teams to ensure the secure deployment of cloud workloads; train and mentor technical teams on cloud security best practices.
