Job Description
Cloud Compliance & Operations Engineer
Summary
The Cloud Operations & Compliance Engineer is responsible for day-to-day cloud operational support and continuous compliance across a multi-account cloud environment. This role owns cloud account provisioning, OU (Organizational Unit) management, Cloud Custodian policy operations, and Tenable vulnerability management, partnering with Security, Platform Engineering, and application teams to keep cloud environments secure, compliant, and scalable.
Key Responsibilities
Cloud Account Provisioning & Lifecycle
- Provision, configure, and decommission cloud accounts/subscriptions/projects using approved enterprise standards (naming, tagging, guardrails, baseline monitoring, logging).
- Implement and maintain “day-1” and “day-2” readiness controls: access, encryption defaults, audit logging, centralized security services, and required integrations.
- Maintain account inventory, ownership metadata, and operational runbooks; ensure accounts meet onboarding requirements before go-live.
OU / Organization Management (Governance at Scale)
- Design, maintain, and optimize OU structures aligned to business units, environments (prod/non-prod), and compliance boundaries.
- Manage and validate guardrails and inheritance models (policies, baseline controls, SCP-like restrictions where applicable, service enablement).
- Coordinate OU moves and account restructuring with minimal disruption; assess blast radius and validate policy impacts.
Cloud Custodian Management (Policy-as-Code Operations)
- Develop, deploy, and maintain Cloud Custodian policies to enforce governance (tagging, encryption, public exposure controls, identity hygiene, cost controls).
- Operate Cloud Custodian execution pipelines/schedules; manage policy testing, approvals, exceptions, and rollbacks.
- Investigate policy findings, tune rules to reduce false positives, and document decisioning for auditability.
- Produce compliance evidence and metrics (policy coverage, remediation rates, exception aging).
Tenable Management (Vulnerability & Exposure Management)
- Administer Tenable integrations for cloud vulnerability visibility (asset discovery, credentialing where approved, scan scheduling, agent coverage where applicable).
- Triage vulnerability findings, validate exploitability/asset criticality, and coordinate remediation with service owners.
- Track SLAs, risk acceptance/exception workflows, and recurring reporting for leadership and auditors.
- Improve coverage and data quality (asset tagging alignment, deduplication, ownership mapping).
Required Qualifications
- 3–6 years’ experience in cloud operations, cloud security, or governance/compliance engineering.
- Hands-on experience managing multi-account cloud environments (account lifecycle, policy/guardrails, centralized logging/monitoring).
- Practical experience with policy-as-code and operating enforcement tooling (e.g., Cloud Custodian) in production.
- Experience administering vulnerability management tooling and workflows (e.g., Tenable), including remediation coordination and SLA tracking.
- Scripting/automation proficiency (e.g., Python, Bash, PowerShell) and familiarity with IaC concepts (Terraform/CloudFormation-like).
- Strong operational discipline: documentation, change management, troubleshooting, and stakeholder communication.
͏
͏
͏
͏
Experience: 3-5 Years .
Reinvent your world. We are building a modern Wipro. We are an end-to-end digital transformation partner with the boldest ambitions. To realize them, we need people inspired by reinvention. Of yourself, your career, and your skills. We want to see the constant evolution of our business and our industry. It has always been in our DNA - as the world around us changes, so do we. Join a business powered by purpose and a place that empowers you to design your own reinvention.