Enter a job title or keyword

Sr. Consultant, Surface Area Management

Cargill


Job Location:

Bengaluru - India

Monthly Salary: Not provided by the employer
Posted: 13 August 2026 (30+ days ago)
Application Deadline: 6 December 2026
Vacancies: 1 Vacancy

Job Summary

Job Purpose and Impact

Sr Consultant - Surface Area Management safeguards the organizations Digital footprint both On-Prem/Cloud by leading the continuous improvement of security controls guardrails and remediation of the exposures. This role serves as a trusted advisor and technical leader driving enterprise cloud vulnerability/exposure management strategy standards and posture improvement initiatives. With minimal supervision the Senior Consultant partners with cybersecurity cloud platform infrastructure engineering risk and business leaders to reduce cloud risk exposure and improve the exposures and other issues of cloud adoption at scale. professional individual contributor and is recognized as subject matter expert in vulnerability management and exposure reduction strategies.

Key Accountabilities

-Lead enterprise-wide Cloud Vulnerability Management programs across AWS Azure GCP and OCI.
-Design and implement preventive security guardrails using SCPs Azure Policy and organization policies to enforce secure-by-default controls.
-Analyze CSPM/CNAPP findings and prioritize remediation based on exposure business criticality data sensitivity and compensating controls.
-Drive remediation accountability govern security exceptions and manage risk acceptance processes across platform and application teams.
-Develop automation auto-remediation capabilities dashboards and integrations to improve control coverage efficiency and reporting.
-Lead cloud identity and access security initiatives including privileged access federation workload identities secrets management and least privilege enforcement.
-Establish risk-based prioritization models incorporating threat intelligence exploitability business impact and compensating controls.
-Coordinate responses to zero-day threats actively exploited vulnerabilities and critical CVEs.
-Identify systemic security trends and drive strategic improvements in scanning coverage asset visibility attack surface management and remediation effectiveness.
-Conduct cloud security assessments and architecture reviews translating findings into prioritized remediation roadmaps.
-Deliver executive-level risk reporting and partner with Incident Response Threat Intelligence Security Architecture and engineering teams.

ESSENTIAL FUNCTIONS
VULNERABILITY MANAGEMENT STRATEGY & GOVERNANCE
Leads the design implementation operation and continuous improvement of enterprise vulnerability management capabilities. Establishes standards governance processes performance metrics and risk management practices to reduce organizational exposure.
EXTERNAL ATTACK SURFACE MANAGEMENT
Provides strategic oversight of the organizations external attack surface identifying emerging risks prioritizing remediation efforts and guiding improvements to overall exposure management practices.
THREAT-INFORMED VULNERABILITY MANAGEMENT
Integrates vulnerability management with threat intelligence threat hunting offensive security and incident response capabilities to improve detection prioritization and remediation outcomes.
PROGRAM LEADERSHIP & CONTINUOUS IMPROVEMENT
Leads cross-functional initiatives that improve scanning coverage asset visibility remediation performance governance processes and overall program maturity.
EXECUTIVE COMMUNICATION & STAKEHOLDER MANAGEMENT: Communicates complex technical risks to executive leadership and business stakeholders influencing strategic decisions and prioritization of remediation activities.
PREVENTIVE CONTROLS & GUARDRAIL ENGINEERING: Provides strategic and hands-on ownership of preventive cloud controls ensuring insecure configurations are blocked by default and guardrail coverage keeps pace with cloud service adoption.
CLOUD POSTURE & MISCONFIGURATION REMEDIATION: Develops and maintains enterprise risk models for cloud posture findings ensuring remediation efforts focus on the most significant business and cybersecurity risks and advances automated remediation where appropriate.
CLOUD SECURITY ARCHITECTURE & CONTROL VALIDATION: Provides technical leadership for cloud security architecture reviews control validation secure landing zone alignment workload protection encryption network segmentation key management and identity-based access controls to ensure cloud environments remain resilient compliant and secure by design.

Qualifications
  • Bachelors degree in computer science Cybersecurity Information Security Information Systems or a related technical field or equivalent practical experience.
  • 6 years of cybersecurity experience including 4 years focused on cloud security engineeringcybersecurity vulnerability management attack surface management or exposure management experience.
  • Hands-on experience securing enterprise -scale vulnerability management in at least one of AWS Microsoft Azure Google Cloud or Oracle Cloud Infrastructure with working knowledge of a second.
  • Proven experience designing and operatingpreventive cloud guardrails AWS service control policies Azure Policy Google organization policies or equivalent policy-as-code enforcement not detection and reporting alone.
  • Strong expertise incloud security architecture and cloud-native security controls across IaaS PaaS and SaaS including network security data protection and key management such as Azure Key Vault or AWS KMS.
  • Deep expertise incloud identity and access management including least-privilege role design federation and workload identity privileged access management conditional access and Zero Trust principles.
  • Hands-on experience operating aCSPM or CNAPP platform at enterprise scale Wiz Microsoft Defender for Cloud Prisma Cloud AWS Security Hub or equivalent including onboarding policy tuning finding triage and remediation ownership routing.
  • Hands-on experience withinfrastructure as code security and policy enforcement using Terraform Bicep ARM templates or CloudFormation and integrating security controls into CI/CD pipelines and DevSecOps experience conducting cloud security assessments posture reviews threat modeling architecture reviews and security control validation and translating findings into prioritized remediation roadmaps.
  • Strong knowledge ofcloud security frameworks and standards including CSA Cloud Controls Matrix CIS Benchmarks NIST ISO 27001 and cloud provider Well-Architected security principles.
  • Experiencedriving remediation accountability across platform and application teams governing security exceptions and risk acceptances and communicating cloud risk to senior leaders and executive audiences.

Preferred Certifications

  • Cloud-specific certifications strongly preferred:CCSP CCSK AWS Certified Security Specialty Microsoft Certified: Azure Security Engineer Associate (AZ-500) Microsoft Cybersecurity Architect Expert (SC-100) or Google Professional Cloud Security Engineer.
  • CISSP or an equivalent broad security certification is preferred.

Required Experience:

Senior IC


About Company

Cargill, Incorporated is an American privately held global corporation based in Minnetonka, Minnesota, and incorporated in Wilmington, Delaware. Founded in 1865, it is the largest privately held corporation in the United States in terms of revenue.

View Profile View Profile