次の仕事の機会を見つけましょう

職種、スキル、勤務地で求人を検索できます。応募書類を準備する前に募集要件を確認しましょう。

魅力的な職種名を見つけることは、仕事探しの出発点です。業務内容、応募条件、働き方を自分の経験と照らし合わせましょう。このガイドでは、候補の絞り込み、応募書類の準備、提出先の確認を順番に進めるためのポイントを紹介します。

操作画面は日本語です。企業が掲載した求人の職種名や説明文は原文のまま表示され、英語の場合があります。

条件をクリア

検索結果: 7,993

← 検索結果に戻る

Sr. Engineer, Cloud Security

Pocket FM

勤務地
Bengaluru, Karnataka, India
掲載日
2026年10月7日

応募する前に、企業のウェブサイトで現在も募集中かどうかと詳しい条件を確認してください。

仕事内容

操作画面は日本語です。企業が掲載した求人の職種名や説明文は原文のまま表示され、英語の場合があります。

Sr. Engineer, Cloud Security Location: Banglore Experience: 4+ Years About Pocket FM Pocket FM, founded in 2018, is India’s leading audio storytelling platform, transforming the way millions consume stories. Offering high-quality serialized content across genres such as Romance, Drama, Thriller, Fantasy, Sci-Fi, and Mythology in eight languages, Pocket FM has built a strong global presence with over 200 million listeners worldwide. With users spending an average of 120 minutes daily on the platform, it has emerged as one of the fastest-growing audio platforms, rapidly expanding its reach across the US, Europe, LATAM, and Southeast Asia. Role Overview: As a Senior Analyst in Cloud Security, you will be responsible for securing Pocket FM's multi-cloud infrastructure at scale. You will work hands-on across our AWS and GCP environments, collaborate closely with DevOps, SRE, and engineering teams, and play a critical role in hardening our cloud footprint against evolving threats. This role is ideal for someone who thinks in terms of attack surfaces and misconfigurations, loves automating security guardrails, and wants to protect the infrastructure that serves millions of daily listeners. Key Responsibilities: Cloud Security Posture Management: Continuously assess and improve the security posture across Pocket FM's AWS and GCP environments by identifying misconfigurations, enforcing security baselines, and driving remediation across projects, accounts, and services.Infrastructure-as-Code (IaC) Security: Review and secure IaC templates (Terraform, CloudFormation, Deployment Manager) to ensure infrastructure is provisioned securely from the start. Integrate security checks into CI/CD pipelines.Identity & Access Management: Design, review, and enforce IAM policies, roles, and permissions following the principle of least privilege across both cloud providers. Manage and monitor access across AWS accounts, GCP projects, SSO, and federated identity setups.Network Security: Configure and maintain cloud network security controls including VPCs, security groups, firewall rules, WAF policies, and CDN configurations across AWS and GCP. Identify and close network-level exposure risks.Threat Detection & Monitoring: Deploy and tune cloud-native and third-party security monitoring tools (e.g., AWS GuardDuty, Security Hub, GCP Security Command Center, Chronicle) to detect anomalous activity, unauthorized access, and potential breaches.Container & Workload Security: Secure containerized workloads (ECS, EKS, GKE, Cloud Run, Docker) by implementing image scanning, runtime protection, secrets management, and pod-level security policies.Automation & Tooling: Build automated security workflows, custom serverless remediations (Lambda, Cloud Functions), and internal tooling (Python/Bash) to scale cloud security operations and reduce manual effort.Vulnerability Management: Partner with engineering teams to manage cloud infrastructure vulnerabilities end-to-end — from discovery and prioritization to remediation tracking and verification.Incident Response: Participate in cloud security incident investigations, perform root cause analysis using cloud-native logging (CloudTrail, GCP Audit Logs), and contribute to runbooks and playbooks for cloud-specific incident scenarios.Compliance Support: Support cloud-related audit and compliance requirements (SOC 2, ISO 27001) by maintaining evidence, documenting controls, and ensuring alignment with security frameworks (CIS Benchmarks for AWS & GCP, Cloud Well-Architected Frameworks).Security Architecture Reviews: Provide security input on new architecture designs, service adoptions, and cloud migration or multi-cloud expansion initiatives to ensure security is considered from day one. Required Qualifications: 4–5+ years of experience in cloud security, infrastructure security, or a related security engineering role.Strong hands-on expertise with at least one major cloud provider (AWS or GCP) and working familiarity with the other. Key areas include identity & access management, network security, compute and storage security, encryption and key management, and cloud-native security tooling.Solid understanding of cloud security architecture patterns, including network segmentation, encryption at rest and in transit, secrets management, and zero-trust principles — applied in a cloud-agnostic or multi-cloud context.Experience securing CI/CD pipelines and reviewing Infrastructure-as-Code (Terraform strongly preferred; CloudFormation or Deployment Manager a plus).Proficiency in scripting and automation using Python, Bash, or Go for building security tools and automated remediation workflows.Working knowledge of container security (Docker, Kubernetes, and managed container services like EKS/GKE) including image scanning, runtime security, and orchestration-level controls.Familiarity with cloud security benchmarks and frameworks such as CIS Foundations Benchmarks (AWS & GCP), Well-Architected / Architecture Frameworks, and NIST CSF.Experience with CSPM tools (e.g., Wiz, Prisma Cloud, Orca, or cloud-native equivalents like Security Hub / Security Command Center) and SIEM platforms for cloud log analysis and alerting.Solid understanding of networking fundamentals — TCP/IP, DNS, TLS, load balancing, and how they map to cloud constructs across providers.Strong communication and collaboration skills, with the ability to work effectively with DevOps, SRE, and software engineering teams and drive security outcomes without being a bottleneck.A proactive, builder mindset — comfortable working in a fast-paced start-up environment with evolving priorities. Preferred Qualifications: Cloud security certifications such as AWS Security Specialty, Google Professional Cloud Security Engineer, CKS (Certified Kubernetes Security Specialist), or CompTIA Security+.Experience managing security across multi-cloud or hybrid environments.Familiarity with service mesh security (Istio, Envoy) and API gateway security patterns.Exposure to DRM, content protection, or media streaming infrastructure security.Familiarity with chaos engineering or adversarial simulation in cloud environments.Prior experience in a consumer tech, media, or high-scale platform company. You can get more updates, insights and everything behind the scenes at Pocket FM here - Pocket FM

検索して比較し、応募を準備しましょう

次の仕事で活かしたい職種やスキルから検索を始めましょう。勤務地と職種の条件を調整し、求人を開いて担当業務を比較してください。結果がない場合は、短い検索語を試すか、条件を一つずつ外してみましょう。

必須条件と歓迎条件を分けて確認し、勤務時間、報酬、勤務地が掲載されている場合は目を通しましょう。リモート勤務でも、居住国、就労資格、勤務時間帯が指定されることがあります。現在の募集状況と詳しい条件は企業に確認してください。

募集要件に関連する実際の経験を選び、自分の役割と貢献を説明しましょう。数値は根拠がある場合にのみ使ってください。企業の応募方法に従い、送信前に連絡先、内容、PDFの表示を確認しましょう。

応募前の確認リスト

仕事探しに関するよくある質問

英語の求人が表示されるのはなぜですか?

職種名や説明文は企業が作成したものです。条件や要件を変えないように原文を掲載しています。操作画面とこのガイドは日本語です。日本語の検索で見つからない場合は、「software engineer」のように、掲載言語の職種名やスキル名でも検索してみてください。検索語が自動翻訳されるわけではありません。

リモート求人なら、どの国からでも働けますか?

必ずしもそうではありません。居住国、就労資格、勤務時間帯が指定されている場合があります。元の求人ページで条件を確認してください。記載がない場合は、自分の居住地から応募できると判断する前に企業へ確認しましょう。リモートという表示だけでは、勤務地の制限がないことは分かりません。

検索結果が出ない場合はどうすればよいですか?

より一般的な職種名や一つのスキルで検索し、条件を一つずつ外してみてください。同じような仕事でも企業によって呼び方が異なります。特定の求人が見つからなくなった場合は、企業の採用ページで求人番号を探しましょう。検索条件を広げても、終了した募集が再開するわけではありません。

ResumizeAIから応募が送信されますか?

応募ボタンは外部サイトを開きます。企業または採用サービスの案内に従い、そのサイトで送信を完了してください。ResumizeAIで応募書類を作成しただけでは応募は送信されません。リンク先が企業のトップページの場合は、該当する募集を探してから手続きを進めましょう。

応募書類とカバーレターはどう調整すればよいですか?

募集要件と、自分が説明できるプロジェクト、業務、成果を結び付けます。経験していない技術や実績を加えず、関連する経験を分かりやすく示してください。カバーレターでは応募理由を具体例とともに伝えます。指定された言語とファイル形式に従い、送信前に両方の書類を確認しましょう。