Job Description
*Cloud Security Engineer*
At PropertyGuru, we strive to Build Southeast Asias Trust Platform and security is at the centre of building that trust with our customers, agents, and partners across Singapore, Vietnam, Malaysia, Thailand & India.
h2. *Role*
- The Cloud Security Engineer is responsible for strengthening and scaling cloud and infrastructure security across *AWS* and *GCP*.
- This role partners closely with the Sr Cloud Security Engineer (Cloud/Infra owner), AppSec leaders, and platform teams to *reduce cloud attack surface*, *harden identity and infrastructure guardrails*, and ensure that essential security telemetry is usable in *SentinelOne CNAPP* and *SentinelOne AI SIEM.*
The engineer will deliver *required, high-leverage automation* (e.g., IAM review evidence, exposure checks, Terraform guardrails) and will avoid unnecessary integration for integrations sake.
h2. *Responsibilities*
h3. *Cloud & Infrastructure Security (AWS + GCP)*
- Drive secure-by-default posture improvements across AWS and GCP, aligned to PropertyGurus security standards.
- Identify and reduce cloud misconfigurations and risky exposures (public access, overly permissive IAM, risky trust relationships, weak logging baselines).
- Partner with platform/infra teams to implement durable fixes, not just close findings.
h3. *CNAPP Operations & Risk Prioritization*
- Support day-to-day operationalization of SentinelOne CNAPP findings:
- validate, prioritize, and route high-impact issues based on *exposure + criticality + exploitability*
- tune noise and reduce false positives in collaboration with the Cloud/Infra owner
- Ensure visibility for the most important risk categories: *internet exposure*, *identity/IAM risk*, *data access risk*, and *high-impact vulnerabilities* on critical workloads.
h3. *IAM Governance & Privileged Access Review Automation*
- Build repeatable IAM review mechanisms and evidence packs for:
- AWS admin access, wildcard permissions, risky cross-account trust, stale credentials, unused high-privilege roles
- GCP IAM with focus on BigQuery datasets/projects, service accounts, cross-project grants
- Automate periodic reporting and drift detection to highlight privilege creep and unapproved changes.
h3. *IaC Security & Policy-as-Code*
- Support security guardrails for Terraform-managed infrastructure:
- baseline checks for high-risk configurations (public exposure, weak IAM, missing encryption/logging)
- promote approved patterns/modules and reduce repeated misconfig classes
- Collaborate with engineering to implement practical policy-as-code controls where it meaningfully reduces risk and rework.
h3. *Exposure Reduction / Attack Surface Monitoring (Required)*
- Implement and maintain lightweight, high-signal exposure monitoring focused on actionable outcomes:
- newly public cloud resources or services
- direct-to-origin exposure paths where Cloudflare is expected as the controlled ingress
- drift in security-critical configurations that increases external attack surface
- Provide clear evidence and remediation guidance that can be actioned by service owners.
h3. *Logging & Detection Readiness (SentinelOne AI SIEM)*
- Define and validate essential cloud log sources and security event flows required for incident readiness:
- AWS CloudTrail and key control-plane events
- GCP Audit logs relevant to BigQuery access and administrative changes
- Security-relevant Cloudflare events (WAF/API Shield), where applicable
- Validate ingestion, retention, and searchability of these logs in SentinelOne AI SIEM.
- Build a minimal set of high-value dashboards/alerts (e.g., privilege expansion, public exposure changes, abnormal data access indicators) in partnership with the Cloud/Infra owner.
h3. *Incident Support & Root Cause Closure*
- Provide cloud-side investigation support (evidence gathering, timeline reconstruction, blast-radius analysis).
- Perform root cause analysis for cloud security incidents/exposures and ensure preventative controls are implemented to avoid recurrence.
h3. *Compliance Evidence & Reporting*
- Produce concise, engineering-actionable cloud security posture reports:
- top IAM risks and changes
- exposure changes and remediation status
- BigQuery access governance summaries
- progress on guardrails and coverage
- Support audit evidence requests related to IAM, logging, encryption, and access governance.
h2. *Who you are*
h2. *Qualifications*
- Bachelors degree in Cybersecurity, Computer Science, Information Technology, or equivalent practical experience.
- 3-5+ years of experience in *cloud security*, *infrastructure security*, or *DevSecOps/security engineering* roles.
- Strong hands-on experience securing *AWS* (IAM, networking, logging, KMS/encryption) and working knowledge of *GCP*, especially *BigQuery governance*.
- Experience working with *CNAPP/CSPM* tooling (SentinelOne CNAPP preferred; equivalent tools acceptable).
- Strong scripting/automation capability (Python/Go/Node) and comfort working with APIs to build repeatable security checks and reports.
- Experience working with *Terraform* in real-world cloud environments.
h2. *Knowledge*
- Deep understanding of cloud identity and access control models:
- AWS IAM roles/policies/trust relationships
- GCP IAM roles/service accounts; BigQuery dataset/project permissions
- Practical understanding of common cloud attack paths:
- public exposure and misconfig exploitation
- privilege escalation through IAM misconfigurations
- credential leakage and abuse
- data exfiltration paths (especially around data platforms such as BigQuery)
- Familiarity with cloud logging and incident response fundamentals:
- what must be logged, how to validate logging completeness, and how to use logs in investigations
- Familiarity with Cloudflare security controls (WAF/WARP) and origin protection concepts is a plus.
h2. *Essential Personal Skills*
- Self-starter who can execute independently while collaborating closely with cloud/platform and security stakeholders.
- Strong analytical thinking and prioritization skillsable to turn noisy findings into a small number of high-impact actions.
- Clear, concise communicator who can explain risk and remediation in practical engineering terms.
- Methodical, detail-oriented, and maintains strict confidentiality of security issues.
- Comfortable operating across multiple teams/markets/time zones in a high-volume environment.
CLOUD SECURITY TECHNOLOGIES