Engineer - Cybersecurity
Eli Lilly
- Location
- Bangalore, Karnātaka, India
- Employment
- Full Time
- Work model
- On-Site
- Level
- Entry
- Posted
- Aug 28, 2026
Skills
About this role
At Lilly, the work is demanding because patients are waiting. We unite caring with discovery to help make life better for people around the world, knowing that every decision, every detail, and every day matters. Headquartered in Indianapolis, Indiana, our over 50,000 employees around the globe take on complex challenges to discover and deliver life-changing medicines, strengthen how health is understood and managed, and support the communities we serve. This is hard, urgent, selfless work—but it’s work worth doing. If you’re driven by purpose and ready to bring your best to work that truly matters for patients, we invite you to join us. Cloud Security Analyst Overview: Lilly Cyber is seeking a skilled Cloud Security Analyst with a strong understanding of cloud security technologies, cloud security posture management (CSPM), and vulnerability management best practices. The ideal candidate will join the Threat Mitigations team and play a pivotal role in supporting threat mitigation activities across Lilly's cloud environments, including infrastructure, cloud-native applications, containers, and back-end pipeline management. This is an exciting position that will be dedicated to helping address cloud security risks. As part of a cross-functional team, this analyst will collaborate closely with a broad set of teams to ensure effective threat reduction. This is an excellent opportunity to grow and experience a wide array of different aspects of cloud cybersecurity while performing a meaningful and impactful role.
Key Responsibilities
Cloud Security & Threat Mitigation Assist Cyber Threat Mitigation Leads in identifying, assessing, and developing solutions to reduce security threats. Manage vulnerabilities through their full lifecycle: discovery, triage, ownership assignment, SLA tracking, and remediation verification. Continuously monitor multi-cloud environments (AWS, Azure, GCP) using CSPM platforms such as Wiz to identify misconfigurations, excessive permissions, and compliance drift. Disposition findings from scanning tools, validating issues, and producing clear remediation guidance for developers. Participate in the implementation of mitigation strategies across cloud workloads, containers, APIs, and infrastructure-as-code. Contribute to threat modeling activities for new and existing cloud architectures and applications. Support burndown of risk with the deployment of security tools through hands on involvement for hard to solve issues. Collaborate with diverse teams and stakeholders to promote security best practices. Support tracking and reporting of security mitigation metrics to provide visibility into risk remediation efforts. DevSecOps Management Integrate security tooling into CI/CD pipelines to enable shift-left practices and automated security checks during build process. Support pull request gating, secrets scanning, dependency scanning, and infrastructure-as-code (IaC) scanning across engineering teams. Develop scripts to enable automation of scanning and triaging workflows.
Qualifications
Required Skills: Bachelor's degree in Computer Science, Information Security, or a related field (or equivalent work experience). 1-3 years of experience in cybersecurity, with a focus on cloud security and/or vulnerability management. Working knowledge of cloud security fundamentals across major cloud service providers (AWS, Azure, GCP), including identity and access management, network segmentation, encryption, and logging/monitoring. Hands-on experience with one or more Cloud Security Posture Management (CSPM) platforms (e.g., Wiz, Prisma Cloud, Orca Security, Microsoft Defender for Cloud, or similar). Experience with vulnerability scanners and management platforms (e.g., Wiz, Qualys, Rapid7, or similar). Solid understanding of vulnerability management processes, including CVSS scoring, and risk-based prioritization. Familiarity with cloud-native architectures (containers, Kubernetes, serverless) and the