CDTR-Cybersecurity - Cloud Security-Manager-Bangalore (Bengaluru East)
PwC Acceleration Center India · Bangalore, Karnataka
PwC Acceleration Center India · Bangalore, Karnataka
At PwC, our cybersecurity teams help organizations reduce cyber risk by identifying vulnerabilities, designing secure systems, and deploying proactive controls to protect sensitive data. In this DevSecOps and Application Security role, you will secure cloud workloads across AWS, Azure, and GCP by applying cloud-native controls and using Terraform/IaC to provision compliant infrastructure. You will embed security across the SDLC by partnering with engineering teams on secure design and code reviews, and by automating testing and policy enforcement in CI/CD (SAST/DAST/SCA, secrets and dependency scanning), and API security. You will help define and implement DevSecOps frameworks (security gates, configuration management, and supply-chain protections such as dependency, secrets, and artifact integrity controls). You will also guide teams on remediation and secure coding practices, and continuously improve security maturity as threats and tooling evolve. The role combines hands-on delivery with strong collaboration, you will advise engineering teams, support remediation, and help build a security-first culture. Multi-Cloud Strategy - Design and implement scalable, well-architected frameworks across AWS, Azure, and GCP, ensuring cross-cloud consistency and disaster recovery readiness. - Architect end-to-end GitHub Enterprise CI/CD pipelines that integrate automated security scanning (GitHub scan tools), dependency checks. Container Orchestration - Manage and optimize large-scale Kubernetes environments (EKS, AKS, GKE), focusing on service mesh implementation, ingress controllers, and cost-productive scaling. - Design scalable security processes and governance for private, hybrid, and multi-cloud environments (AppSec/DevSecOps aligned) - Build and implement cloud, container, and application security strategy, including SSDLC practices - Identify security vulnerabilities on web applications, infrastructure systems, network equipment, Wi - Fi systems, mobile application .