Lead Analyst
Job Description
Roles and responsibilities:
End-to-End Cloud Security Solution Review & Design Assurance:• Conduct comprehensive design and architecture reviews of end-to-end cloud-focused technology solutions, including cloud platforms (M365, Azure, AWS), SaaS, PaaS, and IaaS implementations, ensuring security by design.• Perform in-depth technical assessments and reviews of implemented technology solutions (on-premises and cloud) for effectiveness, identifying misconfigurations, deviations from best practices, and potential attack vectors.• Evaluate cloud security solutions against threat models, risk assessments, and industry-recognized security frameworks (e.g., NIST CSF, CSA CCM, ISO 27001, CIS Benchmarks).• Provide expert security recommendations and architectural guidance on technology implementations to Risk, InfoSec, and Enterprise IT leadership, and to client processes.Cloud Security Posture Management & Compliance Assurance:• Lead and execute Cloud Security Posture Management (CSPM) reviews utilizing CNAPP (Cloud-Native Application Protection Platform) products to assess cloud security posture, cloud-native identity protection (CIEM), cloud workload protection, and container security.• Run regular compliance scans of cloud resources and workgroups against various compliance standards (e.g., HIPAA, GDPR, PCI DSS, SOC 2) and actively work towards improving compliance postures.• Review and provide feedback on cloud security policies, procedures, and hardening documents, ensuring alignment with CIS benchmarks, organizational InfoSec policies, and relevant regulatory requirements.• Conduct cloud risk assessments to identify potential threats, vulnerabilities, and misconfigurations that could impact IT operations and sensitive data.Secure Cloud Development & Operations Practices:• Collaborate closely with Enterprise IT and DevOps teams to ensure the adoption and adherence to secure cloud development practices, integrating security throughout the SDLC (Secure Development Lifecycle) and CI/CD pipelines.• Review Infrastructure as Code (IaC) templates and automation scripts for security flaws and guide EIT and DevOps teams on implementing IaC-based security best practices.• Participate in cloud attack path analysis to understand potential adversary techniques and help design preventative and detective controls.• Ensure that CIS and other security best practices are rigorously implemented for new and existing applications, products, and IT infrastructure implementations within cloud environments.Security Governance & Remediation Oversight:• Work with various teams to track and ensure the remediation of identified security vulnerabilities and misconfigurations across IT and Dev environments.• Contribute to the continuous improvement of cloud security governance frameworks and processes.• Act as a subject matter expert for incident response and forensic readiness related to cloud security incidents, providing review and guidance on incident handling procedures.• Working with various teams on cloud attack path analysis
Qualifications
Experience (5-10+ years):
• Minimum of 5-10 years of progressive experience in Information Security, with at least 4-7 years focused specifically on Cloud Security architecture, engineering, and review.• Extensive hands-on experience with security services and features across multiple major cloud providers (e.g., Microsoft Azure, Amazon Web Services (AWS), Google Cloud Platform (GCP)).• Demonstrable experience in performing security assessments, penetration testing, or vulnerability management within cloud environments.• Proven experience in designing and reviewing secure cloud architectures for complex enterprise solutions.Technical Expertise: • Deep understanding of Cloud Computing principles (IaaS, PaaS, SaaS) and the Shared Responsibility Model.• Expertise in Cloud Security Frameworks and Standards: NIST CSF, CSA CCM, ISO 27001, CIS Benchmarks, OWASP Cloud Top 10.• Proficiency with CNAPP Solutions: Hands-on experience with market-leading tools for CSPM, CIEM, Cloud Workload Protection (CWP), and container security (One of leading CNAPP platform Prisma Cloud, Wiz, Tenable, Lacework, Microsoft, CrowdStrike Cloud Security).• Strong understanding of Identity and Access Management (IAM) in cloud environments: Azure AD, AWS IAM, GCP IAM, conditional access policies, MFA, SSO, PIM/PAM.• Advanced knowledge of Network Security in the cloud: VPC/VNet design, network segmentation, firewalls (WAF, NGFW), security groups/NSGs, VPNs, private links.• Data Security & Encryption: Expertise in securing data at rest and in transit in cloud storage, databases, and applications using native cloud encryption services (e.g., KMS, Key Vault, Cloud KMS).• Application Security in Cloud: Understanding of secure coding practices, API security, serverless function security, and integrating security into CI/CD pipelines (DevSecOps).• Infrastructure as Code (IaC) Security: Ability to review and provide secure recommendations for IaC templates (Terraform, CloudFormation, ARM templates, Bicep) and policy as code.• Knowledge of containerization (Docker, Kubernetes) and their associated security best practices and tools (e.g., Kubernetes admission controllers, network policies).Compliance & Governance: • In-depth knowledge of regulatory compliance requirements (e.g., GDPR, HIPAA, PCI DSS, SOC 2, ISO 27001) and their application in cloud environments.• Experience with GRC (Governance, Risk, and Compliance) tools and processes for cloud.Analytical & Communication Skills: • Exceptional analytical and problem-solving skills with a meticulous attention to detail.• Strong ability to articulate complex security concepts and risks to both technical and non-technical audiences.• Excellent written and verbal communication skills for documentation, reports, and presentations.• Ability to work independently and as part of a distributed team, managing multiple priorities effectively.Certifications (Highly Preferred): • Industry-leading Cloud Security Certifications: o (ISC)² Certified Cloud Security Professional (CCSP)o AWS Certified Security - Specialtyo Microsoft Certified: Azure Security Engineer Associate (AZ-500)o Google Professional Cloud Security Engineero Certificate of Cloud Security Knowledge (CCSK)• General Security Certifications: o (ISC)² CISSP (Certified Information Systems Security Professional)o CISM (Certified Information Security Manager)
Company Description
WNS, part of Capgemini, is an Agentic AI-powered leader in intelligent operations and transformation, serving more than 700 clients across 10 industries, including Banking and Financial Services, Healthcare, Insurance, Shipping and Logistics, and Travel and Hospitality. We bring together deep domain excellence – WNS’ core differentiator – with AI-powered platforms and analytics to help businesses innovate, scale, adapt and build resilience in a world defined by disruption.Our purpose is clear: to enable lasting business value by designing intelligent, human-led solutions that deliver sustainable outcomes and a differentiated impact. With three global headquarters across four continents, operations in 13 countries, 65 delivery centers and more than 66,000 employees, WNS combines scale, expertise and execution to create meaningful, measurable impact.