Cloud Security Consultant - Information Compliance Security : CNAPP, CSPM & Multi-Cloud Exp -8 - 12 Yrs | Job Location : Gurgaon, Mumbai
WNS, part of Capgemini, is an Agentic AI-powered leader in intelligent operations and transformation, serving more than 700 clients across 10 industries, including Banking and Financial Services, Healthcare, Insurance, Shipping and Logistics, and Travel and Hospitality. We bring together deep domain excellence – WNS’ core differentiator – with AI-powered platforms and analytics to help businesses innovate, scale, adapt and build resilience in a world defined by disruption.Our purpose is clear: to enable lasting business value by designing intelligent, human-led solutions that deliver sustainable outcomes and a differentiated impact. With three global headquarters across four continents, operations in 13 countries, 65 delivery centers and more than 66,000 employees, WNS combines scale, expertise and execution to create meaningful, measurable impact.
Key Responsibilities
End-to-End Cloud Security Solution Review & Design Assurance
- Conduct comprehensive design and architecture reviews of end-to-end cloud technology solutions, including cloud platforms (M365, Azure, AWS) and SaaS, PaaS, and IaaS implementations, ensuring security by design.
- Perform in-depth technical assessments of implemented technology solutions (on-premises and cloud) to identify misconfigurations, deviations from best practices, and potential attack vectors.
- Evaluate cloud security solutions against threat models, risk assessments, and industry-recognized frameworks (e.g., NIST CSF, CSA CCM, ISO 27001, CIS Benchmarks).
- Provide expert security recommendations and architectural guidance to Risk, InfoSec, and Enterprise IT leadership, as well as to client-facing processes.
Cloud Security Posture Management & Compliance Assurance
- Lead and execute Cloud Security Posture Management (CSPM) reviews using CNAPP (Cloud-Native Application Protection Platform) tools to assess cloud security posture, cloud identity protection (CIEM), workload protection, and container security.
- Run regular compliance scans of cloud resources against standards such as HIPAA, GDPR, PCI DSS, and SOC 2, and drive continuous improvement of compliance posture.
- Review and provide feedback on cloud security policies, procedures, and hardening documents, ensuring alignment with CIS benchmarks and organizational InfoSec policies.
- Conduct cloud risk assessments to identify threats, vulnerabilities, and misconfigurations that could impact IT operations and sensitive data.
Secure Cloud Development & Operations Practices
- Collaborate with Enterprise IT and DevOps teams to embed security throughout the SDLC and CI/CD pipelines.
- Review Infrastructure as Code (IaC) templates and automation scripts for security flaws, guiding teams on secure IaC best practices.
- Participate in cloud attack path analysis to understand adversary techniques and design preventative and detective controls.
- Ensure CIS and other security best practices are rigorously applied across new and existing applications,...