Experience: 12+ Years
Roles & Responsibilities
• Extensive experience in Cloud Security Posture Management (CSPM), Cloud Workload Protection Platform (CWPP), Data Security Posture Management (DSPM), and AI Security Posture Management (AISPM) using tools like Prisma Cloud / Wiz
• Own and manage cloud security posture across GCP and other CSP environments including misconfiguration detection, remediation tracking, and compliance reporting
• Strong expertise in policy creation, alert triaging, and distribution to remediation teams, ensuring closure with governance oversight
• Ability to design and maintain secure cloud architectures aligned with enterprise and regulatory frameworks
• Drive vulnerability management lifecycle for cloud workloads, including Kubernetes clusters, containers, registries, and images
• Lead risk prioritization and reporting, ensuring visibility to stakeholders through dashboards and executive summaries
• Implement and monitor security governance models, ensuring continuous improvement and audit readiness
• Collaborate with DevOps and engineering teams to embed security into CI/CD pipelines
Key Skills & Experience
- Extensive experience in Containers and Cloud Vulnerability Management
• Strong hands-on experience in CSPM, CWPP, DSPM, and AISPM tools (Wiz / Prisma Cloud preferred)
• Experience in misconfiguration tracking, alert distribution workflows, and remediation coordination
• Good knowledge of compliance frameworks (CIS, NIST, ISO, STIG, etc.)
• Hands-on experience with container security tools (Prisma Cloud, Wiz, Qualys, Lacework, etc.)
• Solid understanding of Kubernetes, Docker, and container lifecycle security
• Expertise in GCP security services and architecture, along with working knowledge of AWS security services
• Experience in DevOps/CI-CD tools such as Jenkins, GitHub, Terraform, Ansible
• Ability to write automation scripts using Python, Terraform, or Ansible
• Understanding of Infrastructure-as-Code (IaC)
- Experience with BI reporting and dashboarding tools (Power BI, Tableau, or similar) for security metrics and governance reporting
• Ability to generate executive-level reports on risk posture, vulnerabilities, and compliance
• Deep understanding of shared responsibility model, cryptography fundamentals, IAM, and zero-trust principles