Lead Cloud Security Engineer

Reposted 19 Days Ago
Be an Early Applicant
Pune, Mahārāshtra
In-Office
Senior level
Information Technology • Security • Cybersecurity
The Role
As a Lead Cloud Security Engineer, you'll design and implement security controls, automate security workflows, conduct assessments, and promote security best practices across cloud platforms.
Summary Generated by Built In

Come work at a place where innovation and teamwork come together to support the most exciting missions in the world!

About the Role

We're seeking a Lead Cloud Security Engineer to join our Product Security team’s Cloud Infrastructure Security wing, where you'll play a critical role in building and maintaining security infrastructure that prevents issues before they become incidents. Working closely with our leads across Qualys, you'll design and implement security controls, automation, and policies that protect our cloud-native products at scale.

What You'll Do

Cloud Security Engineering

  • Design, implement, and maintain security controls for Kubernetes environments across multiple clusters
  • Develop and optimize Infrastructure as Code (IaC) security patterns using tools like Terraform and CloudFormation
  • Build and enforce Policy as Code frameworks to ensure consistent security posture across cloud platforms
  • Create and maintain security policies for Platform-as-a-Service (PaaS) offerings
  • Conduct security reviews of cloud architecture as well as services, recommend hardening measures, and drive adoption through IaC and PaC.

Cloud Security Posture Management (CSPM)

  • Write/ create appropriate security policies
  • Review the CSPM findings and work with appropriate stakeholders to get the findings remediated.
  • Quarterly posture assessment presentation with the stakeholders

Process Automation

  • Develop automation solutions to streamline security workflows and eliminate manual security tasks
  • Build security tooling and integrations that enable product teams to shift security left
  • Create automated compliance checks and remediation workflows
  • Implement security testing automation within CI/CD pipelines
  • Design self-service security capabilities that empower engineering teams

Security Analysis

  • Perform in-depth security assessments of applications, infrastructure, and cloud environments
  • Analyze security telemetry and metrics to identify trends and potential vulnerabilities
  • Investigate security findings and provide detailed remediation guidance
  • Conduct threat modeling for new features and architecture changes
  • Evaluate emerging security technologies and recommend adoption strategies

What You Bring

Required:

  • 7+ years of experience in security engineering, with significant focus on cloud security
  • Experience in managing/ writing policies in any of the industry leading CSPM platform
  • Proficiency in Policy as Code frameworks (OPA/Rego, Sentinel, or similar)
  • Deep understanding of the cloud services and workloads security.
  • Hands-on experience with major cloud platforms (AWS, Azure, or GCP)
  • Strong experience with Infrastructure as Code tools like HELM and security best practices
  • Deep expertise in Kubernetes security (RBAC, network policies, pod security, admission controllers)
  • Programming/scripting skills in Python, Go, or similar languages for automation
  • Strong understanding of container security and orchestration
  • Experience with security automation and DevSecOps practices
  • Excellent problem-solving skills and ability to work independently

Preferred:

  • Experience with Qualys’s Total Cloud platform
  • Experience with REGO, Python
  • Experience with Terraform
  • Experience with security scanning tools (SAST, DAST, SCA, container scanning)
  • Knowledge of compliance frameworks (SOC 2, ISO 27001, PCI DSS)
  • Contributions to open-source security projects
  • Relevant security certifications (CCSP, CCSK, CKS, or equivalent)
  • Experience in product security or application security role

Why Join Us

You'll be part of a team that operates at the intersection of security, engineering, and product development. We believe in preventing problems before they occur through smart automation, robust architecture, and proactive security practices. You'll have the opportunity to work with cutting-edge cloud technologies while making a tangible impact on product security at Qualys.

Top Skills

AWS
Azure
CloudFormation
Container Scanning
Dast
GCP
Go
Helm
Infrastructure As Code
Kubernetes
Policy As Code
Python
Sast
Sca
Security Automation
Terraform
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
2,736 Employees
Year Founded: 1999

What We Do

Qualys, Inc. (NASDAQ: QLYS) is a pioneer and leading provider of disruptive cloud-based security, compliance and IT solutions with more than 10,000 subscription customers worldwide, including a majority of the Forbes Global 100 and Fortune 100. Qualys helps organizations streamline and automate their security and compliance solutions onto a single platform for greater agility, better business outcomes, and substantial cost savings.
The Qualys Cloud Platform leverages a single agent to continuously deliver critical security intelligence while enabling enterprises to automate the full spectrum of vulnerability detection, compliance, and protection for IT systems, workloads and web applications across on premises, endpoints, servers, public and private clouds, containers, and mobile devices. Founded in 1999 as one of the first SaaS security companies, Qualys has strategic partnerships and seamlessly integrates its vulnerability management capabilities into security offerings from cloud service providers, including Amazon Web Services, the Google Cloud Platform and Microsoft Azure, along with a number of leading managed service providers and global consulting organizations. For more information, please visit http://www.qualys.com

Similar Jobs

MetLife Logo MetLife

Associate - Technology Services

Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
Remote or Hybrid
India
43000 Employees

MetLife Logo MetLife

Assistant Manager - Technology Services

Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
Remote or Hybrid
India
43000 Employees

MetLife Logo MetLife

Assistant Manager - Vendor Management

Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
Remote or Hybrid
India
43000 Employees

CrowdStrike Logo CrowdStrike

Sr. MDM Engineer (Remote, IND)

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
India
10000 Employees

Similar Companies Hiring

Credal.ai Thumbnail
Software • Security • Productivity • Machine Learning • Artificial Intelligence
Brooklyn, NY
Standard Template Labs Thumbnail
Software • Information Technology • Artificial Intelligence
New York, NY
15 Employees
Milestone Systems Thumbnail
Software • Security • Other • Big Data Analytics • Artificial Intelligence • Analytics
Lake Oswego, OR
1500 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account