Lead Analyst Information Security
Job Summary
Roles and responsibilities:
End-to-End Cloud Security Solution Review & Design Assurance: Conduct comprehensive design and architecture reviews of end-to-end cloud-focused technology solutions including cloud platforms (M365 Azure AWS) SaaS PaaS and IaaS implementations ensuring security by design. Perform in-depth technical assessments and reviews of implemented technology solutions (on-premises and cloud) for effectiveness identifying misconfigurations deviations from best practices and potential attack vectors. Evaluate cloud security solutions against threat models risk assessments and industry-recognized security frameworks (e.g. NIST CSF CSA CCM ISO 27001 CIS Benchmarks). Provide expert security recommendations and architectural guidance on technology implementations to Risk InfoSec and Enterprise IT leadership and to client Security Posture Management & Compliance Assurance: Lead and execute Cloud Security Posture Management (CSPM) reviews utilizing CNAPP (Cloud-Native Application Protection Platform) products to assess cloud security posture cloud-native identity protection (CIEM) cloud workload protection and container security. Run regular compliance scans of cloud resources and workgroups against various compliance standards (e.g. HIPAA GDPR PCI DSS SOC 2) and actively work towards improving compliance postures. Review and provide feedback on cloud security policies procedures and hardening documents ensuring alignment with CIS benchmarks organizational InfoSec policies and relevant regulatory requirements. Conduct cloud risk assessments to identify potential threats vulnerabilities and misconfigurations that could impact IT operations and sensitive Cloud Development & Operations Practices: Collaborate closely with Enterprise IT and DevOps teams to ensure the adoption and adherence to secure cloud development practices integrating security throughout the SDLC (Secure Development Lifecycle) and CI/CD pipelines. Review Infrastructure as Code (IaC) templates and automation scripts for security flaws and guide EIT and DevOps teams on implementing IaC-based security best practices. Participate in cloud attack path analysis to understand potential adversary techniques and help design preventative and detective controls. Ensure that CIS and other security best practices are rigorously implemented for new and existing applications products and IT infrastructure implementations within cloud Governance & Remediation Oversight: Work with various teams to track and ensure the remediation of identified security vulnerabilities and misconfigurations across IT and Dev environments. Contribute to the continuous improvement of cloud security governance frameworks and processes. Act as a subject matter expert for incident response and forensic readiness related to cloud security incidents providing review and guidance on incident handling procedures. Working with various teams on cloud attack path analysis
Qualifications :
Experience (5-10 years):
Minimum of 5-10 years of progressive experience in Information Security with at least 4-7 years focused specifically on Cloud Security architecture engineering and review. Extensive hands-on experience with security services and features across multiple major cloud providers (e.g. Microsoft Azure Amazon Web Services (AWS) Google Cloud Platform (GCP)). Demonstrable experience in performing security assessments penetration testing or vulnerability management within cloud environments. Proven experience in designing and reviewing secure cloud architectures for complex enterprise Expertise: Deep understanding of Cloud Computing principles (IaaS PaaS SaaS) and the Shared Responsibility Model. Expertise in Cloud Security Frameworks and Standards: NIST CSF CSA CCM ISO 27001 CIS Benchmarks OWASP Cloud Top 10. Proficiency with CNAPP Solutions: Hands-on experience with market-leading tools for CSPM CIEM Cloud Workload Protection (CWP) and container security (One of leading CNAPP platform Prisma Cloud Wiz Tenable Lacework Microsoft CrowdStrike Cloud Security). Strong understanding of Identity and Access Management (IAM) in cloud environments: Azure AD AWS IAM GCP IAM conditional access policies MFA SSO PIM/PAM. Advanced knowledge of Network Security in the cloud: VPC/VNet design network segmentation firewalls (WAF NGFW) security groups/NSGs VPNs private links. Data Security & Encryption: Expertise in securing data at rest and in transit in cloud storage databases and applications using native cloud encryption services (e.g. KMS Key Vault Cloud KMS). Application Security in Cloud: Understanding of secure coding practices API security serverless function security and integrating security into CI/CD pipelines (DevSecOps). Infrastructure as Code (IaC) Security: Ability to review and provide secure recommendations for IaC templates (Terraform CloudFormation ARM templates Bicep) and policy as code. Knowledge of containerization (Docker Kubernetes) and their associated security best practices and tools (e.g. Kubernetes admission controllers network policies).Compliance & Governance: In-depth knowledge of regulatory compliance requirements (e.g. GDPR HIPAA PCI DSS SOC 2 ISO 27001) and their application in cloud environments. Experience with GRC (Governance Risk and Compliance) tools and processes for & Communication Skills: Exceptional analytical and problem-solving skills with a meticulous attention to detail. Strong ability to articulate complex security concepts and risks to both technical and non-technical audiences. Excellent written and verbal communication skills for documentation reports and presentations. Ability to work independently and as part of a distributed team managing multiple priorities (Highly Preferred): Industry-leading Cloud Security Certifications: o (ISC)² Certified Cloud Security Professional (CCSP)o AWS Certified Security - Specialtyo Microsoft Certified: Azure Security Engineer Associate (AZ-500)o Google Professional Cloud Security Engineero Certificate of Cloud Security Knowledge (CCSK) General Security Certifications: o (ISC)² CISSP (Certified Information Systems Security Professional)o CISM (Certified Information Security Manager)
Remote Work :
No
Employment Type :
Full-time
About Company
WNS (Holdings) Limited (NYSE: WNS), is a leading Business Process Management (BPM) company. We combine our deep industry knowledge with technology and analytics expertise to co-create innovative, digital-led transformational solutions with clients across 10 industries. We enable busin ... View more