Posted 2 days ago
Security Architect
Job description
Project Role : Security Architect Project Role Description : Define the cloud security framework and architecture, ensuring it meets the business requirements and performance goals. Document the implementation of the cloud security controls and transition to cloud security-managed operations. Must have skills : Amazon Web Services (AWS) Security Good to have skills : NA Minimum 5 year(s) of experience is required Educational Qualification : 15 years full time education Summary: We are looking for an AWS IAM Engineer with experience to provide L2/L3 operational support across IAM, SSO, MFA, RBAC, and PAM services. The role requires strong troubleshooting skills, a sound understanding of AWS identity services, and the ability to manage access policies, handle incidents, and deliver clear operational reporting. Roles & Responsibilities: Operations and service delivery -Handle incidents, service requests and change requests across the AWS security service portfolio, meeting agreed response and resolution service levels. -Triage and action findings, alerts and policy violations, escalating to the client or to vendor support where required. -Deliver planned changes within approved maintenance windows, including firewall and WAF rule changes, policy updates and configuration amendments. -Produce daily operational reports and maintain runbooks, standard operating procedures and knowledge articles. -Participate in problem management, contributing root cause analysis for major incidents within agreed timelines. Technical ownership -Administer AWS WAF rule groups and conditions, tune rules to reduce false positives and false negatives, and manage Firewall Manager security policies. -Maintain AWS Config rules, including custom rules, organisation and organisational unit rules, and multi-account deployment. -Operate AWS Security Hub, including central configuration policies, service integrations and findings workflow. -Manage AWS GuardDuty findings and suppression rules, protection plans, runtime monitoring and cross-account aggregation. -Administer AWS IAM roles, policies and permission boundaries perform access reviews, credential reporting and key rotation. -Support AWS KMS and Secrets Manager operations, including key policy, rotation and access control. -Maintain AWS CloudTrail configuration across accounts, including data events, retention and downstream log integrations. -Operate AWS Shield Advanced and AWS Certificate Manager, including certificate lifecycle and renewal monitoring. -Manage Palo Alto VM-Series firewalls deployed on AWS and maintain AWS Security Group rule sets. Essential Skills and Experience -AWS WAF — rule groups, conditions, rule tuning, Firewall Manager security policies. -AWS Config — managed and custom rules, trigger and evaluation modes, organisation, OU and multi-account rules, configuration history and retention. -AWS Security Hub — central configuration policies, integration with GuardDuty, Inspector and Macie, findings management. -AWS GuardDuty — findings analysis, suppression rules, protection plans, cross-region and cross-account aggregation. -AWS IAM — roles, policies, permission boundaries, Access Analyzer, credential reports, access key and secret key rotation. -AWS KMS and AWS Secrets Manager — customer managed keys, symmetric and asymmetric encryption, key and secret rotation, access control. -AWS CloudTrail — multi-account trails, data events, log retention and aggregation. -AWS Shield Advanced and AWS Certificate Manager. -AWS Security Groups and network security concepts in a VPC context. -Working within an ITIL service management framework — incident, change and problem management, ideally on ServiceNow. -Depth across AWS WAF, Config, Security Hub and IAM is the core requirement. Candidates with particular strength in identity and key management — IAM, federated identity, IAM Identity Center and KMS — should highlight this, as a subset of the positions is weighted that way. Professional & Technical Skills: -Federated identity with AWS — OIDC and SAML identity providers, IAM Identity Center including Active Directory integration. -Automated remediation using EventBridge and Lambda. -Infrastructure as code and scripting — Terraform, CloudFormation, Python or Boto3. -Palo Alto VM-Series and Panorama on public cloud. -AWS CloudHSM. -Log and monitoring platforms — CloudWatch, Splunk, Dynatrace. -Regulated industry experience, particularly life sciences or pharmaceutical, and familiarity with GxP or CIS benchmark controls. Additional Information: - The candidate should have minimum 6 years of experience in AWS Administration. - This position is based at our Bengaluru office. - A 15 years full time education is required. 15 years full time education About Accenture Accenture is a leading global professional services company that helps the world’s leading businesses, governments and other organizations build their digital core, optimize their operations, accelerate revenue growth and enhance citizen services—creating tangible value at speed and scale. We are a talent- and innovation-led company with approximately 791,000 people serving clients in more than 120 countries. Technology is at the core of change today, and we are one of the world’s leaders in helping drive that change, with strong ecosystem relationships. We combine our strength in technology and leadership in cloud, data and AI with unmatched industry experience, functional expertise and global delivery capability. Our broad range of services, solutions and assets across Strategy & Consulting, Technology, Operations, Industry X and Song, together with our culture of shared success and commitment to creating 360° value, enable us to help our clients reinvent and build trusted, lasting relationships. We measure our success by the 360° value we create for our clients, each other, our shareholders, partners and communities. Visit us at www.accenture.com Equal Employment Opportunity Statement We believe that no one should be discriminated against because of their differences. All employment decisions shall be made without regard to age, race, creed, color, religion, sex, national origin, ancestry, disability status, military veteran status, sexual orientation, gender identity or expression, genetic information, marital status, citizenship status or any other basis as protected by applicable law. Our rich diversity makes us more innovative, more competitive, and more creative, which helps us better serve our clients and our communities. Bring your incredible skills and join our global team of innovators. We come together from different backgrounds across the world and work with the latest technologies to create value and growth for our clients. With us, you’ll continue to learn and grow so you can advance in your career. Your personal dreams and ambitions are just as important to us; that’s why we offer support any way we can—when you thrive, we all thrive. Explore your next step at Accenture Belong. Grow. Thrive. Join a great place to work for reinventors who drive meaningful change for our clients, communities, and the world. Wo rld. Explore your next step at Accenture
Skills and functions
- Aws
- Python
- Terraform