Rubiscape is deployed across a uniquely
complex topology — public SaaS, customer BYOC (Bring Your Own Cloud), hybrid,
on-premises, and fully air-gapped environments. As Cloud Security Engineer, you
will be responsible for securing this entire deployment surface: cloud
infrastructure hardening, identity and access governance in AWS/Azure/GCP,
Kubernetes security, and CSPM. You will work alongside platform infrastructure
and DevSecOps teams to ensure that Rubiscape’s cloud posture meets the bar set
by Fortune 500 and public sector customers who run mission-critical decisions
on the platform.
· Design and implement cloud
security architecture for Rubiscape’s AWS, Azure, and GCP deployments, covering
VPC design, IAM least-privilege, service control policies, and network security
groups.
· Operate Cloud Security Posture
Management (CSPM) tooling (Wiz, Prisma Cloud, or AWS Security Hub); triage
findings, prioritise by risk, and drive remediation with infrastructure owners.
· Harden Kubernetes clusters
(EKS, AKS, GKE) running Rubiscape’s studio workloads: enforce pod security
standards, network policies, image signing, and runtime protection.
· Build and maintain automated
IaC security scanning (Checkov, tfsec) as a mandatory gate in Terraform and
Helm chart pipelines.
· Design the BYOC customer
onboarding security model — ensuring tenant isolation, key management
separation, and audit log forwarding without exposing Rubiscape control-plane
credentials.
· Define and validate cloud
security controls for ISO 27001, SOC 2, and CERT-IN cloud security guidelines;
produce cloud-specific evidence packs for compliance audits.
· Respond to cloud security
incidents — containment, forensic investigation, root cause analysis, and
post-incident hardening recommendations.
· Certifications: AWS Security
Specialty, CCSP, Google Professional Cloud Security Engineer, or CKS (Certified
Kubernetes Security Specialist).
· Experience designing security
for BYOC or hybrid SaaS deployments where customer cloud accounts host vendor
workloads.
· Familiarity with eBPF-based
runtime security tooling (Falco, Cilium, Tetragon).
· Prior work in regulated cloud
environments subject to CERT-IN, RBI Cloud Guidelines, or SEBI Cybersecurity
framework.
Rubiscape is India’s leading Decision
Intelligence Platform, unifying data engineering, BI, machine learning, and
agentic AI in a single governed platform. Built in Pune and trusted by Fortune
500 enterprises across BFSI, manufacturing, healthcare, and government. 8
international innovation patents. 10 Industry-Academia Labs & COEs. From BI
to AI — One Platform. Every Decision.
RequirementsRequirements
· 4+ years of cloud security
experience with at least two of AWS, Azure, or GCP, including hands-on IAM,
networking, and security services.
· Demonstrated expertise in
Kubernetes security: pod security, RBAC, network policies, secrets management
(Vault/Sealed Secrets), and container image scanning.
· Proficiency with CSPM platforms
and infrastructure-as-code security scanning tools.
· Experience designing
multi-tenant isolation architectures in cloud environments, including
cross-account strategies and customer-managed encryption keys (BYOK/HYOK).
· Scripting ability in Python or
Go for security automation, custom policy enforcement, and cloud API
interactions.

