Overview
Protect Marvell’s digital assets by securing its multi-cloud environment across AWS, Azure, GCP, and OCI. Design and implement security controls, drive cloud security posture management through CNAPP platforms, and embed security across the cloud lifecycle from code to runtime.
What you'll do
- Design, implement, and maintain security controls across AWS, Azure, GCP, and OCI, including IAM, network segmentation, encryption, key management, and logging.
- Own the deployment, tuning, and day-to-day operation of CNAPP platforms such as Palo Alto Cortex Cloud, Wiz, and/or Orca.
- Assess, develop, implement, operationalize, and document security, data protection, cryptography, key management, IAM, and network security capabilities within IaaS, PaaS, and other cloud environments.
- Manage CSPM, CWPP, CIEM, DSPM, vulnerability management, and container/Kubernetes security capabilities.
- Triage and prioritize findings by risk and attack path, drive remediation with application and platform teams, and track SLAs and risk reduction metrics.
- Build custom policies, detection rules, and automated remediation workflows.
- Integrate security into CI/CD pipelines through IaC scanning, SAST/SCA, secrets detection, and container image scanning.
- Integrate cloud-native telemetry with the SIEM/SOAR platform.
- Map cloud controls to CIS Benchmarks, NIST, ISO 27001/27017, and other applicable regulations.
- Support audits and produce evidence, and maintain security documentation, standards, and runbooks.
- Report on security posture, risk trends, and KPIs.
- Partner with cloud platform, DevOps, SRE, and application teams as a trusted security advisor.
What you'll need
- 5+ years of experience in cloud security.
- Hands-on experience in at least one cloud—AWS, Azure, GCP, and OCI—with knowledge of the others.
- Experience with at least one leading CNAPP tool: Cortex Cloud, Wiz, Prisma Cloud, or Orca.
- Strong understanding of cloud IAM, network security, encryption/KMS, secrets management, and logging/monitoring.
- Experience with Infrastructure as Code, with Terraform preferred, and security scanning of IaC.
- Scripting/automation skills in Python, Bash, or PowerShell.
- Familiarity with APIs and event-driven automation.
- Familiarity with security frameworks and benchmarks: CIS, NIST CSF, ISO 27001, and MITRE ATT&CK for Cloud.
- Strong communication skills, with the ability to explain risks to both technical and non-technical stakeholders.
- Strong interpersonal and communication skills and the ability to work in a team environment.
- Ability to work independently with minimal direction; self-starter/self-motivated.
Nice to have
- Certifications such as AWS Certified Security – Specialty, AZ-500, Google Professional Cloud Security Engineer, OCI Security Professional, CCSP, and/or CISSP.
- Strong expertise in GCP services, including Cloud Services Platform, Google Kubernetes Engine, Compute Engine, and Cloud Interconnect.
- Experience with SIEM/SOAR tools such as XSOAR, Splunk, Sentinel, and Chronicle.
- Exposure to containers and Kubernetes security.
- Exposure to Zero Trust, data security/DSPM, and API security.
Details
- Location: Bangalore.
- Applicants may be subject to an export license review process prior to employment, except for U.S. citizens, lawful permanent residents, or protected individuals as defined by 8 U.S.C. 1324b(a)(3).
Read the full description and apply on the company’s own careers page.