Happiest Minds
Job Description ----------------------------------------------------- *Cloud Security Engineer* At PropertyGuru, we strive to “Build Southeast Asia’s Trust Platform” and security is at the centre of building that trust with our customers, agents, and partners across Singapore, Vietnam, Malaysia, Thailand & India. h2. *Role* · The Cloud Security Engineer is responsible for strengthening and scaling cloud and infrastructure security across *AWS* and *GCP*. · This role partners closely with the Sr Cloud Security Engineer (Cloud/Infra owner), AppSec leaders, and platform teams to *reduce cloud attack surface*, *harden identity and infrastructure guardrails*, and ensure that essential security telemetry is usable in *SentinelOne CNAPP* and *SentinelOne AI SIEM.* · The engineer will deliver *required, high-leverage automation* (e.g., IAM review evidence, exposure checks, Terraform guardrails) and will avoid unnecessary “integration for integration’s sake.” h2. *Responsibilities* h3. *Cloud & Infrastructure Security (AWS + GCP)* · Drive secure-by-default posture improvements across AWS and GCP, aligned to PropertyGuru’s security standards. · Identify and reduce cloud misconfigurations and risky exposures (public access, overly permissive IAM, risky trust relationships, weak logging baselines). · Partner with platform/infra teams to implement durable fixes, not just close findings. h3. *CNAPP Operations & Risk Prioritization* · Support day-to-day operationalization of SentinelOne CNAPP findings: o validate, prioritize, and route high-impact issues based on *exposure + criticality + exploitability* o tune noise and reduce false positives in collaboration with the Cloud/Infra owner · Ensure visibility for the most important risk categories: *internet exposure*, *identity/IAM risk*, *data access risk*, and *high-impact vulnerabilities* on critical workloads. h3. *IAM Governance & Privileged Access Review Automation* · Build repeatable IAM review mechanisms and evidence packs for: o AWS admin access, wildcard permissions, risky cross-account trust, stale credentials, unused high-privilege roles o GCP IAM with focus on BigQuery datasets/projects, service accounts, cross-project grants · Automate periodic reporting and drift detection to highlight privilege creep and unapproved changes. h3. *IaC Security & Policy-as-Code* · Support security guardrails for Terraform-managed infrastructure: o baseline checks for high-risk configurations (public exposure, weak IAM, missing encryption/logging) o promote approved patterns/modules and reduce repeated misconfig classes · Collaborate with engineering to implement practical policy-as-code controls where it meaningfully reduces risk and rework. h3. *Exposure Reduction / Attack Surface Monitoring (Required)* · Implement and maintain lightweight, high-signal exposure monitoring focused on actionable outcomes: o newly public cloud resources or services o “direct-to-origin” exposure paths where Cloudflare is expected as the controlled ingress o drift in security-critical configurations that increases external attack surface · Provide clear evidence and remediation guidance that can be actioned by service owners. h3. *Logging & Detection Readiness (SentinelOne AI SIEM)* · Define and validate essential cloud log sources and security event flows required for incident readiness: o AWS CloudTrail and key control-plane events o GCP Audit logs relevant to BigQuery access and administrative changes o Security-relevant Cloudflare events (WAF/API Shield), where applicable · Validate ingestion, retention, and searchability of these logs in SentinelOne AI SIEM. · Build a minimal set of high-value dashboards/alerts (e.g., privilege expansion, public exposure changes, abnormal data access indicators) in partnership with the Cloud/Infra owner. h3. *Incident Support & Root Cause Closure* · Provide cloud-side investigation support (evidence gathering, timeline reconstruction, blast-radius analysis). · Perform root cause analysis for cloud security incidents/exposures and ensure preventative controls are implemented to avoid recurrence. h3. *Compliance Evidence & Reporting* · Produce concise, engineering-actionable cloud security posture reports: o top IAM risks and changes o exposure changes and remediation status o BigQuery access governance summaries o progress on guardrails and coverage · Support audit evidence requests related to IAM, logging, encryption, and access governance. h2. *Who you are* h2. *Qualifications* · Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or equivalent practical experience. · 3-5+ years of experience in *cloud security*, *infrastructure security*, or *DevSecOps/security engineering* roles. · Strong hands-on experience securing *AWS* (IAM, networking, logging, KMS/encryption) and working knowledge of *GCP*, especially *BigQuery governance*. · Experience working with *CNAPP/CSPM* tooling (SentinelOne CNAPP preferred; equivalent tools acceptable). · Strong scripting/automation capability (Python/Go/Node) and comfort working with APIs to build repeatable security checks and reports. · Experience working with *Terraform* in real-world cloud environments. h2. *Knowledge* · Deep understanding of cloud identity and access control models: o AWS IAM roles/policies/trust relationships o GCP IAM roles/service accounts; BigQuery dataset/project permissions · Practical understanding of common cloud attack paths: o public exposure and misconfig exploitation o privilege escalation through IAM misconfigurations o credential leakage and abuse o data exfiltration paths (especially around data platforms such as BigQuery) · Familiarity with cloud logging and incident response fundamentals: o what must be logged, how to validate logging completeness, and how to use logs in investigations · Familiarity with Cloudflare security controls (WAF/WARP) and “origin protection” concepts is a plus. h2. *Essential Personal Skills* · Self-starter who can execute independently while collaborating closely with cloud/platform and security stakeholders. · Strong analytical thinking and prioritization skills—able to turn noisy findings into a small number of high-impact actions. · Clear, concise communicator who can explain risk and remediation in practical engineering terms. · Methodical, detail-oriented, and maintains strict confidentiality of security issues. · Comfortable operating across multiple teams/markets/time zones in a high-volume environment.