One Identity

Principal Security Engineer Cloud and Infrastructure Security

One Identity
Apply
18 hours ago
Remote, IndiaStaff+

Responsibilities

  • Own security architecture across Azure and AWS, including tenant, subscription, account, network, connectivity, egress, and workload-isolation design.
  • Build hardened infrastructure-as-code modules, secure-by-default landing zones, account baselines, and policy-as-code enforcement across pipelines and platforms.
  • Own virtual-machine and container image pipelines, including patching, provenance, signing, and automated maintenance.
  • Secure container orchestration and define reference architectures and secure defaults for customer-deployed clusters.
  • Set security architecture for AI workloads, including model and inference endpoint exposure, data residency, identity, secrets, and development guardrails.
  • Lead infrastructure vulnerability and exposure management from discovery and prioritization through remediation, verification, and ownership routing.
  • Define cloud posture and workload protection standards across Azure and AWS and automate findings into pull requests where possible.
  • Design controls and queryable evidence for ISO 27001, SOC 2, IRAP, ACN, and PCI requirements.

Requirements

  • 10 or more years of experience in security engineering or infrastructure engineering, with substantial time in cloud architecture; equivalent depth is accepted.
  • Deep cloud security architecture experience across Azure and AWS, with real depth in one and working command of the other.
  • Hands-on experience securing AI workloads or AI-enabled tooling within the last six months.
  • Evidence of building a security capability or system that engineering teams adopted and continued using.
  • Strong infrastructure-as-code, cloud network security, segmentation, private connectivity, egress control, and east-west traffic knowledge.
  • Experience with container and Kubernetes security, image hardening, software supply-chain integrity, secrets management, and policy-as-code frameworks.
  • Experience designing controls that held up under an audit and judgment about risks to carry versus escalate.
  • Helpful experience includes customer-deployed software, FedRAMP or IRAP, carve-outs, and large-scale cloud migrations.

Benefits

  • Leadership backing to build a new infrastructure security program and define the architecture for an independent company.
  • Opportunity to enable engineering directly and support entry into new regulated markets.
  • Global, distributed team environment with career development programs.
  • Health and wellness support and rewards for employee contributions.

Categories

One Identity

About One Identity

501-1,000 employees

One Identity builds enterprise identity security software, unifying identity governance and administration, privileged access management, access management, and Active Directory lifecycle management for large organizations. It offers self-managed and SaaS deployments and sells via enterprise licenses and subscriptions, with services and support. Part of Quest Software and headquartered in Aliso Viejo, California, One Identity serves over 11,000 organizations and helps manage more than 500 million identities worldwide.

Contact me