Cloud Security Engineer
Job description
About the role
You own the security posture for identity and key management across Azure, AWS, and GCP. Daily work means turning controls into working configurations that teams can trust. You respond when access or keys behave unexpectedly and keep policy aligned with standards.
Key facts
What you will do
Design and implement security baselines for cloud platforms using code-based controls. Operate cloud key management and vault services with focus on cryptographic lifecycle operations. Build access reviews and recertification workflows for identity governance across cloud directories. Shape network security rules and firewall behavior on Fortigate platforms. Partner with observability tools to track security posture and traffic anomalies. Ship security configurations through infrastructure as code pipelines with repeatable patterns. Review change impacts before firewall or policy updates go live to production. Collaborate with vendors and security partners to align on controls and emerging risks.
Responsibilities in identity and access management
Execute IAM operations including provisioning, troubleshooting access issues, and managing RBAC and ABAC configurations. Implement Service Control Policies on AWS to enforce organizational boundaries and guardrails. Build and manage Azure Policy definitions, initiatives, and assignments in line with compliance requirements. Support IAM architecture across Azure AD or Entra ID, AWS IAM, GCP IAM, and the enterprise Identity Center. Assist with IAM incident response and Level 2 escalations when access anomalies are detected.
Key management and secrets vault operations
Operate cloud KMS platforms such as Azure Key Vault and AWS KMS with emphasis on key rotation and key policies. Manage certificates and PKI operations while enforcing cryptographic standards that include RSA, AES, and ECC. Ensure secure key access patterns and proper lifecycle management for cloud keys and secrets.
Cloud security controls and compliance
Implement cloud security baselines, guardrails, and compliance controls aligned with CIS, NIST, and ISO 27001 frameworks. Support network and security posture configuration using tools such as Wiz and Prisma where applicable. Configure and troubleshoot cloud-native firewalls, Network Security Groups, routing, and segmentation rules.
Network security operations on Fortigate
Manage, monitor, and troubleshoot Fortigate firewalls including security policies, NAT, VPN IPsec and SSL, and routing configurations. Oversee IPS and IDS configurations and associated threat profiles. Ensure high availability operations in Active/Passive designs. Support network segmentation, micro-segmentation, and Zero Trust enforcement initiatives. Participate in firewall rule reviews, change management, and impact assessments. Analyze traffic flows, logs, and events using FortiAnalyzer tools for security insights.
Automation and infrastructure as code
Define infrastructure as code patterns that automate security configurations across multi-cloud environments. Embed security checks within pipelines to validate policies before deployment. Maintain documentation for security playbooks and standard operating procedures.
Requirements
You can manage identity systems on Azure AD, AWS IAM, and GCP IAM with hands-on experience. You understand Service Control Policies and how they enforce boundaries between accounts and workloads. You have practical experience with Azure Key Vault and AWS KMS operations including key import and rotation. You know RSA, AES, and ECC approaches for encryption, signing, and key exchange. You can handle TLS certificate lifecycles across cloud services and on-prem PKI where relevant. You have configured Network Security Groups, routing, and network segmentation in cloud environments. You have managed Fortigate firewalls including NAT, VPN, and routing configurations. You have worked with IPS, IDS, and threat profile settings to maintain detection capabilities.
Nice to have
Experience with Wiz or Prisma security platforms for continuous posture management.
Skills and tools
Azure, AWS, GCP, Fortigate, Key Vault, KMS, Wiz, Prisma, Identity Center.
Practical notes
before submitting your application. Ensure your experience matches the responsibilities outlined in this role.