Apexon is a digital-first technology services firm specializing in accelerating business transformation and delivering human-centric digital experiences. We have been meeting customers wherever they are in the digital lifecycle and helping them outperform their competition through speed and innovation.Apexon brings together distinct core competencies in AI, analytics, app development, cloud, commerce, CX, data, DevOps, IoT, mobile, quality engineering and UX, and our deep expertise in BFSI, healthcare, and life sciences to help businesses capitalize on the unlimited opportunities digital offers. Our reputation is built on a comprehensive suite of engineering services, a dedication to solving clients toughest technology problems, and a commitment to continuous improvement. Backed by Goldman Sachs Asset Management and Everstone Capital, Apexon now has a global presence of 15 offices (and 10 delivery centers) across four continents.
We enable #HumanFirstDIGITAL
Cloud Security Architect
JOB SUMMARY
We are seeking an experienced Cloud Security Architect to lead the design and implementation of secure cloud infrastructure across our AWS-based environments. This role will focus on securing network boundaries, containerized workloads (such as Kubernetes and Amazon EKS), cloud-native data storage (e.g., S3), and overall cloud infrastructure components. You will serve as the security expert in cloud architecture projects, ensuring all designs align with best practices and compliance requirements.
CANDIDATE PROFILE
Education and Experience
Required
- Bachelor's or Master's degree in Computer Science, Information Security, or related field, or equivalent professional experience.
- 7+ years of experience in cybersecurity with at least 3+ years focused on cloud security in AWS.
- Hands-on expertise in AWS services (VPC, EC2, EKS, S3, IAM, CloudTrail, KMS, GuardDuty), Kubernetes security, and Infrastructure-as-Code security (Terraform).
Preferred
- Cloud Security Certifications: AWS Certified Security Specialty, AWS Certified Solutions Architect, Certified Kubernetes Security Specialist (CKS), CISSP, SA.
- Multi-Cloud Security Experience: Experience securing workloads across AWS, Azure, and Google Cloud Platform with understanding of platform-specific security implications.
- Zero Trust Architecture: Familiarity with Zero Trust principles, identity-aware access policies, microsegmentation strategies, and secure service-to-service communication.
CORE WORK ACTIVITIES
- Designs and maintains secure architectures for cloud infrastructure in AWS, AliCloud, and any cloud operates in, defining security reference architectures and guardrails for services like VPC, subnets, security groups, and IAM roles.
- Implements and validates network segmentation, ingress/egress controls, and virtual firewall configurations for cloud infrastructure components (EC2, ALB/NLB, Route 53, VPCs, Transit Gateways).
- Secures containerized workloads in Amazon EKS or self-managed Kubernetes clusters, defining security controls including RBAC, network policies, pod security standards, and image scanning.
- Collaborates with DevOps and platform teams to integrate security into CI/CD pipelines and container registries.
- Ensures secure configuration of cloud-native storage solutions (S3, EBS, EFS), implementing encryption, logging, access control, and data classification.
- Evaluates and enforces policies around public access, bucket-level permissions, and data loss prevention for cloud-stored data.
- Ensures cloud solutions comply with internal policies and external regulatory requirements (ISO 27001, SOC 2, HIPAA, GDPR).
- Contributes to threat modeling, risk assessments, and architecture review processes for new and existing workloads.
- Defines and implements logging and monitoring strategies using CloudTrail, GuardDuty, Security Hub, and container-level telemetry.
- Collaborates with Security Operations and Incident Response teams on alerts and forensic readiness.
- Conducts security and privacy technology research, assessments, and integration processes; provides and supports prototype capabilities.
- Consults with customers to gather and evaluate functional requirements and provides security and privacy requirements, guidelines, and standards.
- Provides sound advice and recommendations to leadership and staff on cloud security topics, translating technical security risks into business impact.
- Manages and measures information security implications within the organization, including strategic planning, risk management, and security awareness.
Our Commitment to Diversity & Inclusion:
Did you know that Apexon has been Certified by Great Place To Work , the global authority on workplace culture, in each of the three regions in which it operates: USA (for the fourth time in 2023), India (seven consecutive certifications as of 2023), and the UK.Apexon is committed to being an equal opportunity employer and promoting diversity in the workplace. We take affirmative action to ensure equal employment opportunity for all qualified individuals. Apexon strictly prohibits discrimination and harassment of any kind and provides equal employment opportunities to employees and applicants without regard to gender, race, color, ethnicity or national origin, age, disability, religion, sexual orientation, gender identity or expression, veteran status, or any other applicable characteristics protected by law. You can read about our Job Applicant Privacy policy here Job Applicant Privacy Policy (apexon.com)
Our Commitment to Environment:
Actively contribute to Apexon's commitment to environmental responsibility by following sustainable practices and supporting ESG initiatives.
Our Perks and Benefits:
Our benefits and rewards program has been thoughtfully designed to recognize your skills and contributions, elevate your learning/upskilling experience and provide care and support for you and your loved ones. As an Apexon Associate, you get continuous skill-based development, opportunities for career advancement, and access to comprehensive health and well-being benefits and assistance.
We also offer:
o Health Insurance with Dental & Vision
o 401K Plan
o Life Insurance, STD & LTD
o Paid Vacations & Holidays
o Paid Parental Leave
o FSA Dependent & Limited Purpose care