Sutherland is an experience-led digital transformation company. Our mission is to deliver exceptionally engineered experiences for customers and employees today, that continue to delight tomorrow. For over 37 years, we have cared for our clients' customers, delivering measurable results and accelerating growth.
Job DescriptionPosition Summary
We are seeking an experienced Lead Cloud Security Engineer with 10+ years of experience in Information Security and at least 5+ years in Cloud Security implementation, and governance of security controls across multi-cloud environments (Azure, OCI, AWS, GCP). The role focuses on cloud security architecture, compliance, security operations, threat management, and continuous improvement of the organization's cloud security posture.
Key Responsibilities
- Design and govern secure, scalable cloud architectures, security standards, policies, guardrails, and landing zones across multi-cloud environments.
- Own and enhance the Cloud Security Posture Management (CSPM) program, ensuring alignment with NIST, ISO 27001, CIS Benchmarks, SOC 2, PCI-DSS, GDPR, and Cloud Security Alliance frameworks.
- Perform threat modeling, security architecture reviews, risk assessments, and defining remediation strategies.
- Implement and manage cloud security controls including IAM, MFA, PAM, SSO, Zero Trust, CSPM, and Cloud Workload Protection (CWPP).
- Monitor cloud environments for threats, vulnerabilities, and misconfigurations, drive remediation with platform and application teams.
- Investigate and respond to cloud security incidents, support forensic investigations, and integrate cloud logs into SIEM platforms.
- Detect, investigate, and respond to cloud-based security incidents.
- Analyze logs from cloud-native services such as Defender for Cloud, OCI Cloud Guard, AWS CloudTrail, Azure Monitor, and GCP Logging.
- Support vulnerability management (Tannable), EDR (Sentinel One), Stellar XDR and Cyber AI Behavior Analytics , Defender for Office 365 email security monitoring solutions.
- Ensure audit readiness, compliance reporting, and maintenance of cloud security documentation, standards, and procedures.
- Provide technical leadership, mentor security engineers, and collaborate with business and technology stakeholders to strengthen cloud security capabilities.
Required Skills & Experience
- Strong hands-on experience securing Azure, OCI, and AWS and GCP environments.
- Expertise in IAM, cloud-native security services, CSPM, CWPP, SIEM, Zero Trust, and cloud security operations.
- Experience with threat modeling, security architecture reviews, incident response, vulnerability management, and compliance assessments.
- Knowledge of ISO 27001, NIST, CIS Benchmarks, SOC 2, PCI-DSS, and GDPR.
- Experience with Tenable, SentinelOne, cloud logging, and security monitoring platforms.
- Strong communication, stakeholder management, and leadership skills.
Position Summary
We are seeking an experienced Lead Cloud Security Engineer with 10+ years of experience in Information Security and at least 5+ years in Cloud Security implementation, and governance of security controls across multi-cloud environments (Azure, OCI, AWS, GCP). The role focuses on cloud security architecture, compliance, security operations, threat management, and continuous improvement of the organization's cloud security posture.
Key Responsibilities
- Design and govern secure, scalable cloud architectures, security standards, policies, guardrails, and landing zones across multi-cloud environments.
- Own and enhance the Cloud Security Posture Management (CSPM) program, ensuring alignment with NIST, ISO 27001, CIS Benchmarks, SOC 2, PCI-DSS, GDPR, and Cloud Security Alliance frameworks.
- Perform threat modeling, security architecture reviews, risk assessments, and defining remediation strategies.
- Implement and manage cloud security controls including IAM, MFA, PAM, SSO, Zero Trust, CSPM, and Cloud Workload Protection (CWPP).
- Monitor cloud environments for threats, vulnerabilities, and misconfigurations, drive remediation with platform and application teams.
- Investigate and respond to cloud security incidents, support forensic investigations, and integrate cloud logs into SIEM platforms.
- Detect, investigate, and respond to cloud-based security incidents.
- Analyze logs from cloud-native services such as Defender for Cloud, OCI Cloud Guard, AWS CloudTrail, Azure Monitor, and GCP Logging.
- Support vulnerability management (Tannable), EDR (Sentinel One), Stellar XDR and Cyber AI Behavior Analytics , Defender for Office 365 email security monitoring solutions.
- Ensure audit readiness, compliance reporting, and maintenance of cloud security documentation, standards, and procedures.
- Provide technical leadership, mentor security engineers, and collaborate with business and technology stakeholders to strengthen cloud security capabilities.
Required Skills & Experience
- Strong hands-on experience securing Azure, OCI, and AWS and GCP environments.
- Expertise in IAM, cloud-native security services, CSPM, CWPP, SIEM, Zero Trust, and cloud security operations.
- Experience with threat modeling, security architecture reviews, incident response, vulnerability management, and compliance assessments.
- Knowledge of ISO 27001, NIST, CIS Benchmarks, SOC 2, PCI-DSS, and GDPR.
- Experience with Tenable, SentinelOne, cloud logging, and security monitoring platforms.
- Strong communication, stakeholder management, and leadership skills.
All your information will be kept confidential according to EEO guidelines.
Skills Required
- 10+ years of experience in Information Security
- At least 5+ years in Cloud Security implementation and governance
- Hands-on experience securing Azure, OCI, AWS, and GCP environments
- Expertise in IAM, MFA, PAM, SSO, Zero Trust
- Experience with CSPM, CWPP, SIEM, cloud-native security services
- Threat modeling, security architecture reviews, incident response, vulnerability management
- Knowledge of ISO 27001, NIST, CIS Benchmarks, SOC 2, PCI-DSS, GDPR
- Experience with Tenable (vulnerability management) and SentinelOne (EDR)
- Experience analyzing cloud logs (Defender for Cloud, OCI Cloud Guard, AWS CloudTrail, Azure Monitor, GCP Logging)
- Familiarity with Stellar XDR, Cyber AI Behavior Analytics, Defender for Office 365, XDR/EDR
- Strong communication, stakeholder management, and leadership skills
Sutherland Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Sutherland and has not been reviewed or approved by Sutherland.
-
Flexible Benefits — Flexible scheduling and work-from-home arrangements are offered on certain programs, supported by remote-work infrastructure and virtual IT support. Program-specific flexibility is emphasized for “Sutherland Anywhere” roles.
-
Leave & Time Off Breadth — Paid time off and paid training are positioned as standard elements, with some materials also highlighting flexible vacation days. Core leave features are presented as part of the baseline package.
-
Strong & Reliable Incentives — Performance incentives, bonuses, and commissions are available on selected programs to supplement base pay. Goal-linked earnings opportunities are described for certain functions.
Sutherland Insights
What We Do
We make digital ?????™ by combining human-centered design with real-time Analytics, AI, Cognitive Technology & Automation to create exceptionally engineered Brand Experiences! Sutherland is an experience-led digital transformation company. Our mission is to deliver exceptionally engineered experiences for customers and employees today, that continue to delight tomorrow. For over 35 years, we have cared for our customers’ customers, delivering measurable results and accelerating growth. Our proprietary, AI-based products and platforms are built using robust IP and automation. We are a team of global professionals, operationally effective, culturally meshed, and committed to our clients and to one another. We call it One Sutherland. #MakeDigitalHuman







