Cloud Security Expert (CSE)/ Cloud Architect
Cloud Security Expert will be responsible to protect department’s data and infrastructure in cloud environment. CSE’s responsibilities involves a wide range of activities, focusing on proactive security measures, threat detection, and incident response.
2.1 Job Responsibilities/ Activities to be performed:
- Setting up Alerts: Ensuring the implementation of the Alert mechanism based on the severity levels to the respective stakeholders for all the security threats identified within the cloud environment.
- Patch Vulnerabilities: Coordinate with the Cloud Network Expert (CNE) to patch the identify vulnerabilities. i.e. port block, IP/IP Pool block, suspicious application removal etc.
- Maintaining Logs: Maintaining all security logs
- Root Cause Analysis (RCA): Prepare RCA for the disruption of services due to security mishaps.
- Designing and Implementing Secure Cloud Architectures: Designing & deploying secure cloud infrastructure that aligns with MeitY’s best cloud practices and Department’s security requirements. This includes selecting appropriate cloud services and configurations to minimize vulnerabilities.
- Developing and Enforcing Security Policies and Procedures: drafting and maintaining security policies, standards, guidelines, and procedures specific to cloud environments to ensure department’s data protection and MeitY’s Cloud Security compliances.
- Implementing Cloud Security Controls: Setting up and managing technical security controls, such as firewalls, intrusion detection/prevention systems (IDS/IPS) & access controls, within cloud platform.
- Identity and Access Management (IAM): Managing user access rights and permissions in the cloud to ensure only authorized individuals can access specific resources. This involves implementing and overseeing IAM policies.
- Data Protection & Encryption: Formulating & applying stringent data protection strategies, including implementing encryption, tokenization etc. measures to safeguard sensitive data at rest & in transit.
- Security Monitoring & Analysis: Continuously monitoring cloud environments for potential security threats, anomalies, and suspicious activities using available security tools and technologies with the department’s Cloud Infra. Analyzing security logs and alerts to identify and respond to incidents.
- Vulnerability Assessment and Penetration Testing (VAPT): Support department for the regular security assessments & vulnerability scans of cloud infrastructure & applications to identify weaknesses & potential entry points for attackers.
- Incident Response and Recovery: Developing and implementing incident response plans to effectively handle security breaches and incidents in the cloud. This includes identifying, containing, eradicating, and recovering from security events.
- Compliance and Governance: Ensuring MeitY’s Cloud security guidelines and policies. Staying updated on regulatory changes and adapting security measures accordingly.
- Threat Intelligence: Keeping well-informed of the latest cloud security threats, attack tactics, and techniques to proactively implement defenses and mitigate potential risks.
- Security Tool Management: Building, deploying & managing various cloud security tools and services. This includes configuring & tuning tools to minimize false positives & maximize threat detection capabilities.
- Evaluating New Security Solutions: Researching and evaluating new cloud security technologies, tools, and services to enhance the department's security posture.
2.2 Qualifications:
- Bachelor's degree in Computer Science, Information Technology, or a related field. Equivalent experience may be considered.
- Minimum of 5+ years of experience in Datacenter and Cloud Security.
- Proven experience designing Security Architecture, implementing, and managing Security & Monitoring Tools on at least one major cloud platform (Oracle preferred, AWS & Azure optional).
- Strong understanding of SoC Monitoring Tools related to VA, Threat intelligence, Splunk, Behavioral analytics, Incident response, Intrusion detection systems, LogRhythm, Crowdstrike
Experience with network security principles and technologies (firewalls, VPNs, intrusion
2.3 Preferred Security Certifications:
- CISSP :Certified Information Systems Security Professional.
- CISM :Certified Information Security Manager
- CEH – Certified Ethical Hacker.
2.4 Essential Skills:
A successful Cloud Security Expert typically possesses a strong combination of technical and soft skills, including:
- Deep Knowledge of Cloud Platforms: Expertise in major cloud platforms such as AWS, Azure and specially Oracle (OCI) including their services and security features.
- Network Security: Solid understanding of networking principles, protocols, and security technologies (e.g., firewalls, VPNs, routing, switching).
- Security Principles and Best Practices: Thorough knowledge of security frameworks, standards, and best practices (e.g., NIST, ISO 27001, OWASP).
- Identity and Access Management (IAM): Proficiency in implementing and managing IAM solutions in cloud environments.
- Cryptography and Encryption: Understanding of encryption algorithms, key management, and their application in cloud security.
- Security Tools and Technologies: Hands-on experience with a wide range of security tools, including SIEM, vulnerability scanners, intrusion detection/prevention systems, and cloud-specific security services (Web Application Firewall (WAF), Anti-DDoS etc.).
- Scripting and Automation: Proficiency in scripting languages (e.g., Python, Bash, PowerShell) and automation tools for security tasks.
- Risk Assessment and Management: Ability to identify, assess, & mitigate security risks in cloud.
- Incident Response and Forensics: Knowledge of incident response methodologies and techniques for investigating security breaches.
- Compliance and Governance: Understanding of MeitY’s Cloud security compliances and industry standards related to cloud security.
- Communication and Collaboration: Excellent written and verbal communication skills to articulate technical concepts to diverse audiences and work effectively within teams.
- Analytical and Problem-Solving Skills: Strong analytical abilities to identify security vulnerabilities, analyze threats, and develop effective solutions.
- Continuous Learning: Staying updated with the rapidly evolving cloud security landscape and emerging threats.