Senior Cloud Infrastructure and Entitlements Management (CIEM) Engr
Job Title: Senior Cloud Infrastructure and Entitlements Management (CIEM) Engineer
Experience
8+ years of experience in cloud infrastructure, cloud security, identity and access management, entitlement governance, and cloud risk remediation.
Role Overview
We are seeking an experienced CIEM Engineer to manage, optimize, and secure cloud identities and entitlements across multi-cloud environments, including AWS, Microsoft Azure, Google Cloud Platform (GCP), and Alibaba Cloud. The ideal candidate will possess strong expertise in Cloud Infrastructure Entitlement Management (CIEM), Identity and Access Management (IAM), cloud security governance, least-privilege access controls, entitlement risk remediation, Just-in-Time access, Azure PIM, Tenable cloud risk findings, and remediation of security and compliance issues across multi-cloud environments
This role combines hands-on operational ownership, engineering, automation, governance, and compliance responsibilities to ensure secure and efficient access management across enterprise cloud platforms.
Work Location: Pune or Chennai.
Shift Timings: 24x5 support/on-call rotation
Key Responsibilities
Cloud Infrastructure and Security
- Secure cloud infrastructure across AWS, Azure, GCP, and Alibaba Cloud.
- Apply cloud security best practices based on the AWS Well-Architected Framework, Microsoft Cloud Security principles, Google Cloud security guidance, and Alibaba Cloud security controls.
- Review cloud accounts, subscriptions, projects, tenants, resource groups, networks, workloads, storage, databases, containers, and serverless services for security risks.
- Partner with infrastructure and application teams to embed security controls into cloud provisioning and deployment processes.
Entitlements and Access Governance
- Manage and govern cloud entitlements, permissions, roles, policies, groups, service accounts, workload identities, and machine identities.
- Conduct periodic access reviews for privileged, non-privileged, inactive, orphaned, and excessive permissions.
- Identify and remediate excessive privileges, toxic combinations, unused permissions, direct assignments, public access, and inappropriate cross-account or cross-tenant access.
- Review and optimize AWS IAM policies, IAM roles, permission sets, SCPs, Azure RBAC, Azure resource permissions, GCP IAM, Alibaba Cloud RAM, and equivalent access controls.
- Govern access lifecycle processes, including joiner, mover, leaver, temporary access, emergency access, and access revocation.
- Support entitlement certification campaigns and provide evidence for audit and compliance requirements.
- Establish ownership and accountability for cloud identities, permissions, roles, groups, and service accounts.
Azure PIM, JIT, and Privileged Access
- Implement and administer Microsoft Entra ID Privileged Identity Management, including, eligible and active role assignments, approval workflows, time-bound access
- Define and maintain Just-in-Time access models for Azure, AWS, GCP, Alibaba Cloud, servers, databases, and other privileged platforms.
- Reduce standing administrative privileges and implement temporary, monitored, and approval-based access.
- Review privileged role assignments and remove stale, excessive, or unauthorized access.
- Support break-glass account governance, emergency access procedures, and privileged access monitoring.
- Integrate privileged access processes with IAM, PAM, ITSM, SIEM, and security monitoring platforms.
- Track and report privileged access usage, approval compliance, access duration, and policy exceptions.
Tenable and Cloud Risk Findings Remediation
- Administer and support Tenable cloud security capabilities.
- Review cloud risk findings related to identity, permissions, vulnerabilities, configuration weaknesses, exposed resources, encryption, network security, and compliance.
- Analyze findings, validate risk severity, identify asset and business ownership, and define remediation plans.
- Coordinate remediation activities with cloud, infrastructure, application, DevOps, and service owners.
- Track findings through closure and verify remediation effectiveness.
- Define risk-based prioritization for critical and high-risk findings.
- Investigate recurring findings and recommend sustainable control improvements.
- Support exception, risk acceptance, compensating control, and remediation extension processes.
- Prepare dashboards, metrics, management reports, and audit evidence for cloud risk remediation.
Multi-Cloud Governance
- Establish consistent identity, entitlement, security, and compliance standards across AWS, Azure, GCP, and Alibaba Cloud.
- Map cloud controls to organizational security policies, CIS benchmarks, NIST, ISO 27001, SOC 2, PCI DSS, or other applicable frameworks.
- Develop cloud security standards, procedures, operating models, and control documentation.
- Support cloud account, subscription, project, and tenant onboarding and offboarding.
- Review third-party integrations, federated identities, service principals, workload identities, API access, and automation accounts.
- Identify cloud security gaps caused by inconsistent configurations or decentralized ownership.
Automation and Continuous Improvement
- Automate entitlement reviews, access discovery, policy validation, risk finding tracking, and remediation activities.
- Develop scripts and workflows using PowerShell, Python, Bash, Azure CLI, AWS CLI, Terraform, REST APIs, or cloud-native automation services.
- Integrate cloud security platforms with ServiceNow, SIEM, SOAR, IAM, PAM, and reporting solutions.
- Create automated notifications, escalations, ticket generation, access expiration, and remediation workflows.
- Improve operational efficiency by reducing manual reviews and repetitive remediation activities.
- Maintain accurate documentation, runbooks, process flows, and control evidence.
Required Technical Skills
- Strong experience with AWS IAM, IAM Identity Center, Organizations, SCPs, Control Tower, Security Hub, CloudTrail, Config, and account governance.
- Strong experience with Microsoft Azure and Entra ID, including Azure RBAC, Management Groups, Azure Policy, Entra roles, service principals, managed identities, and Azure PIM.
- Working experience with GCP IAM, organization policies, folders, projects, service accounts, Cloud Audit Logs, and Security Command Center.
- Working experience with Alibaba Cloud RAM, Resource Directory, Cloud Firewall, ActionTrail, and cloud security controls.
- Hands-on experience with Tenable cloud security, vulnerability management, or comparable cloud security posture management platforms.
- Experience implementing Just-in-Time access and least-privilege access models.
- Knowledge of privileged access management concepts and integration with CyberArk or similar PAM platforms.
- Experience reviewing IAM policies, role permissions, trust relationships, access keys, secrets, certificates, tokens, and workload identities.
- Proficiency in PowerShell, Python, Bash, AWS CLI, Azure CLI, or equivalent automation tools.
- Knowledge of Terraform, CloudFormation, ARM, Bicep, or other infrastructure-as-code technologies.
- Experience with ServiceNow, Jira, SIEM, SOAR, or security workflow platforms.
- Understanding of networking, virtual machines, containers, Kubernetes, storage, databases, encryption, DNS, firewalls, and APIs.
· Relevant certifications—such as AWS Certified Security – Specialty, Microsoft Certified: Identity and Access Administrator Associate, or a Tenable or comparable security platform certification—are an advantage.
Behavioral and Professional Competencies
- Strong analytical and problem-solving skills.
- Ability to assess complex cloud permissions and translate findings into practical remediation actions.
- Strong understanding of risk-based decision-making.
- Ability to work independently across multiple teams and cloud platforms.
- Ability to manage competing priorities and deliver remediation within defined timelines.
- Demonstrated ownership, accountability, and attention to detail.
- Ability to explain technical risks to both technical and non-technical audiences.
Recommended Jobs
Posted 13 hours ago
Posted 13 hours ago
Posted 13 hours ago
Posted 13 hours ago
Posted 13 hours ago

