- Company Name
- eNcloud Services LLC
- Job Title
- Application & Cloud Security Engineer
- Job Description
-
**Job Title:** Application & Cloud Security Engineer
**Role Summary:**
Implement and manage application and cloud security tooling to continuously assess, triage, and remediate vulnerabilities. Partner with development, infrastructure, and operations teams to embed security controls into CI/CD pipelines and cloud environments, while driving automation, metrics, and governance.
**Expectations:**
- Minimum 2 + years of hands‑on experience in Application Security and/or Cloud Security.
- Proficiency with designated AppSec and CloudSec platforms.
- Ability to prioritize high‑risk findings and provide actionable remediation guidance.
- Collaborative mindset for working with cross‑functional engineering teams.
**Key Responsibilities:**
- Configure, maintain, and optimize Checkmarx (SAST), Invicti (DAST), and SonarQube for continuous scanning.
- Enable secrets scanning, API security, and dependency management across code repositories.
- Administer Prisma Cloud and Wiz for CSPM, CNAPP, and CWPP across Azure, GCP, and hybrid clouds.
- Perform misconfiguration and compliance remediation; support IaC security checks (Terraform, GitHub Actions, Jenkins).
- Integrate security testing into CI/CD pipelines and automate ticketing (ServiceNow) and reporting (Tableau/PowerBI).
- Develop and maintain security standards, playbooks, and guardrails; conduct knowledge sharing with engineering, IAM, networking, and infrastructure teams.
**Required Skills:**
- Checkmarx, Invicti, SonarQube (mandatory).
- Prisma Cloud, Wiz (mandatory).
- Strong understanding of secure coding practices, OWASP Top 10, and cloud security frameworks (Azure CAF, GCP Security Foundations).
- Experience with CI/CD tools and DevOps workflows; Infrastructure‑as‑Code (Terraform, GitHub Actions, Jenkins).
- Excellent problem‑solving, risk prioritization, and communication abilities.
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Information Security, or related field, or equivalent practical experience.
- Preferred certifications: CISSP, CISM, AWS Certified Security – Specialty, Azure Security Engineer Associate, or Google Professional Cloud Security Engineer.