Product Security & Cloud Security Consultant (Contract)
Location: Bengaluru (3 Days Onsite required)
Engagement: Initial 6 Months Contract with strong possibility of extension
Company: Arj Global Ltd
At Arj Global Ltd, we are supporting enterprise clients in strengthening their product security, cloud security posture, and regulatory compliance across modern digital platforms.
We are looking for a Product Security & Cloud Security Consultant to work closely with engineering and product teams, ensuring secure design, implementation, and compliance across the software lifecycle.
Scope of Work
You will:
- Assess and advise on security and privacy controls across software design, development, and acquisition processes
- Support implementation of cyber security and data privacy frameworks, ensuring compliance with relevant regulations
- Conduct cloud security posture (CSP) assessments, maturity assessments, and threat modelling exercises
- Strengthen cloud security (primarily Azure) including identity, access, and infrastructure controls
- Translate security findings into business-level risks to support informed decision-making
- Identify and analyse vulnerabilities across applications, networks, and infrastructure
- Collaborate with product and engineering teams to embed security-by-design principles
Key Requirements
Security Architecture
- Strong understanding of product architecture and threat surfaces
- Experience securing APIs, cloud-native systems, and IoT environments
- Knowledge of microservices, containers (Docker/Kubernetes), and distributed systems
Cloud Security Design
- Hands-on experience with Azure (preferred), AWS, or GCP
- Strong understanding of:
- IAM (Identity & Access Management)
- Encryption & key management
- Secrets management
- Experience improving cloud security posture
Secure Development & Engineering
- Experience with Secure Software Development Lifecycle (SSDLC)
- Embedding security into CI/CD pipelines
- Knowledge of threat modelling frameworks (STRIDE, PASTA, LINDDUN)
- Ability to perform secure code reviews (Python, Java, C/C++, Go)
Vulnerability & Risk Management
- Strong experience in vulnerability identification, triage, and remediation
- Familiarity with CVSS scoring and vulnerability disclosure processes
- Ability to translate technical risks into business impact and prioritisation
Regulatory & Compliance
- Knowledge of:
- ISO 27001
- SOC 2
- NIST CSF
- GDPR
- Experience aligning engineering practices with regulatory requirements
Top 3 Must-Have Skills
- ✅ Security Architecture
- ✅ Cloud Security Design (Azure preferred)
- ✅ Security Risk Assessment

