寻找你的下一个职业机会

按职位、技能和地点搜索招聘信息。准备申请前,先仔细了解职位要求。

找到一个吸引人的职位名称只是求职的起点。请将工作职责、招聘要求和工作条件与你的实际经历进行比较。本指南帮助你筛选机会、准备有针对性的申请材料,并确认每份申请应该在哪里提交。

此界面为简体中文。雇主发布的职位名称和描述保留原文,可能为英文。

清除筛选

搜索结果: 7,367

← 返回搜索结果

Sr. Engineer, Cloud Security

Pocket FM

地点
Bengaluru, Karnataka, India
发布日期
2026年10月7日

申请前,请在雇主网站确认职位仍在招聘,并检查完整要求和条件。

职位描述

此界面为简体中文。雇主发布的职位名称和描述保留原文,可能为英文。

Sr. Engineer, Cloud Security Location: Banglore Experience: 4+ Years About Pocket FM Pocket FM, founded in 2018, is India’s leading audio storytelling platform, transforming the way millions consume stories. Offering high-quality serialized content across genres such as Romance, Drama, Thriller, Fantasy, Sci-Fi, and Mythology in eight languages, Pocket FM has built a strong global presence with over 200 million listeners worldwide. With users spending an average of 120 minutes daily on the platform, it has emerged as one of the fastest-growing audio platforms, rapidly expanding its reach across the US, Europe, LATAM, and Southeast Asia. Role Overview: As a Senior Analyst in Cloud Security, you will be responsible for securing Pocket FM's multi-cloud infrastructure at scale. You will work hands-on across our AWS and GCP environments, collaborate closely with DevOps, SRE, and engineering teams, and play a critical role in hardening our cloud footprint against evolving threats. This role is ideal for someone who thinks in terms of attack surfaces and misconfigurations, loves automating security guardrails, and wants to protect the infrastructure that serves millions of daily listeners. Key Responsibilities: Cloud Security Posture Management: Continuously assess and improve the security posture across Pocket FM's AWS and GCP environments by identifying misconfigurations, enforcing security baselines, and driving remediation across projects, accounts, and services.Infrastructure-as-Code (IaC) Security: Review and secure IaC templates (Terraform, CloudFormation, Deployment Manager) to ensure infrastructure is provisioned securely from the start. Integrate security checks into CI/CD pipelines.Identity & Access Management: Design, review, and enforce IAM policies, roles, and permissions following the principle of least privilege across both cloud providers. Manage and monitor access across AWS accounts, GCP projects, SSO, and federated identity setups.Network Security: Configure and maintain cloud network security controls including VPCs, security groups, firewall rules, WAF policies, and CDN configurations across AWS and GCP. Identify and close network-level exposure risks.Threat Detection & Monitoring: Deploy and tune cloud-native and third-party security monitoring tools (e.g., AWS GuardDuty, Security Hub, GCP Security Command Center, Chronicle) to detect anomalous activity, unauthorized access, and potential breaches.Container & Workload Security: Secure containerized workloads (ECS, EKS, GKE, Cloud Run, Docker) by implementing image scanning, runtime protection, secrets management, and pod-level security policies.Automation & Tooling: Build automated security workflows, custom serverless remediations (Lambda, Cloud Functions), and internal tooling (Python/Bash) to scale cloud security operations and reduce manual effort.Vulnerability Management: Partner with engineering teams to manage cloud infrastructure vulnerabilities end-to-end — from discovery and prioritization to remediation tracking and verification.Incident Response: Participate in cloud security incident investigations, perform root cause analysis using cloud-native logging (CloudTrail, GCP Audit Logs), and contribute to runbooks and playbooks for cloud-specific incident scenarios.Compliance Support: Support cloud-related audit and compliance requirements (SOC 2, ISO 27001) by maintaining evidence, documenting controls, and ensuring alignment with security frameworks (CIS Benchmarks for AWS & GCP, Cloud Well-Architected Frameworks).Security Architecture Reviews: Provide security input on new architecture designs, service adoptions, and cloud migration or multi-cloud expansion initiatives to ensure security is considered from day one. Required Qualifications: 4–5+ years of experience in cloud security, infrastructure security, or a related security engineering role.Strong hands-on expertise with at least one major cloud provider (AWS or GCP) and working familiarity with the other. Key areas include identity & access management, network security, compute and storage security, encryption and key management, and cloud-native security tooling.Solid understanding of cloud security architecture patterns, including network segmentation, encryption at rest and in transit, secrets management, and zero-trust principles — applied in a cloud-agnostic or multi-cloud context.Experience securing CI/CD pipelines and reviewing Infrastructure-as-Code (Terraform strongly preferred; CloudFormation or Deployment Manager a plus).Proficiency in scripting and automation using Python, Bash, or Go for building security tools and automated remediation workflows.Working knowledge of container security (Docker, Kubernetes, and managed container services like EKS/GKE) including image scanning, runtime security, and orchestration-level controls.Familiarity with cloud security benchmarks and frameworks such as CIS Foundations Benchmarks (AWS & GCP), Well-Architected / Architecture Frameworks, and NIST CSF.Experience with CSPM tools (e.g., Wiz, Prisma Cloud, Orca, or cloud-native equivalents like Security Hub / Security Command Center) and SIEM platforms for cloud log analysis and alerting.Solid understanding of networking fundamentals — TCP/IP, DNS, TLS, load balancing, and how they map to cloud constructs across providers.Strong communication and collaboration skills, with the ability to work effectively with DevOps, SRE, and software engineering teams and drive security outcomes without being a bottleneck.A proactive, builder mindset — comfortable working in a fast-paced start-up environment with evolving priorities. Preferred Qualifications: Cloud security certifications such as AWS Security Specialty, Google Professional Cloud Security Engineer, CKS (Certified Kubernetes Security Specialist), or CompTIA Security+.Experience managing security across multi-cloud or hybrid environments.Familiarity with service mesh security (Istio, Envoy) and API gateway security patterns.Exposure to DRM, content protection, or media streaming infrastructure security.Familiarity with chaos engineering or adversarial simulation in cloud environments.Prior experience in a consumer tech, media, or high-scale platform company. You can get more updates, insights and everything behind the scenes at Pocket FM here - Pocket FM

查找职位、比较要求,再准备申请

从你希望从事的职位或运用的技能开始搜索。调整地点和职业筛选,打开职位比较工作职责。如果没有结果,可以使用更短的关键词,或逐一移除筛选条件。

区分必备要求和优先条件,检查已列出的工作安排、薪资和地点。远程职位也可能要求特定居住国家、工作许可或工作时间重合。请向雇主确认职位信息和完整条件。

选择能够回应职位要求的真实经历,说明你的贡献,只使用能够证实的数字。遵循雇主的申请说明,并在提交前检查联系方式、文档内容和 PDF。

提交申请前的检查清单

求职常见问题

为什么有些职位使用英文?

职位名称和描述由招聘企业撰写。为避免改变招聘要求或工作条件,我们保留原文。操作界面和本指南使用简体中文。如果中文搜索没有结果,可以尝试使用职位发布语言中的名称或技能,例如“software engineer”。搜索词不会自动翻译,界面语言也不代表企业要求的申请语言。

远程职位是否允许从任何国家工作?

不一定。企业可能对居住国家、工作许可或工作时段有要求。请查看原始招聘页面中的具体条件。如果未说明,应先向企业确认,再判断能否从你所在的地区工作。“远程”标签本身并不代表没有地点限制。

搜索没有结果时应该怎么办?

尝试更通用的职位名称或单个技能,并逐一移除筛选条件。不同企业可能用不同名称描述相似工作。如果某个职位已经消失,请在企业招聘页面搜索其职位编号。扩大搜索范围不会让已经关闭的职位重新开放。

申请会通过 ResumizeAI 直接提交吗?

申请按钮会打开外部网站。请按照企业或招聘服务的说明,在该网站完成并确认提交。在 ResumizeAI 中准备简历并不等于已经申请职位。如果链接只打开企业网站,请先找到对应职位,再继续申请流程。

如何针对职位调整简历和求职信?

将招聘要求与能够解释清楚的项目、任务和成果联系起来。突出相关经历,不要添加未经实际掌握的技能或虚构成绩。在求职信中用具体例子说明申请动机,并遵守企业要求的语言和文件格式。提交前检查两份文件,确保内容准确、联系方式正确、链接可用。