Tech Stack
AWSCloudDockerEC2JenkinsKubernetesPythonSDLCTerraformVault
About the role
- Design and implement secure AWS architectures using EC2, S3, IAM, VPC, CloudTrail, GuardDuty, Security Hub, and KMS.
- Design and enforce least privilege access, network segmentation, and secure connectivity models (Transit Gateway, VPC Peering, PrivateLink).
- Integrate security tools and checks into CI/CD pipelines (e.g., GitHub Actions, GitLab CI, Jenkins) to enforce secure code and deployment practices; integrate SAST, DAST, SCA, and IaC scanning into pipelines.
- Enforce secrets detection, artifact signing, and SBOM generation in build workflows.
- Develop and maintain secure IaC templates using Terraform or AWS CloudFormation.
- Secure Docker and Kubernetes workloads running on AWS (EKS), including image scanning, runtime protection, and RBAC policies.
- Set up and manage AWS-native monitoring tools (CloudWatch, CloudTrail) and integrate with third-party solutions like Datadog or ELK for security observability.
- Automate vulnerability scanning and remediation across cloud resources and application layers; build custom tooling/scripts for proactive detection and response.
- Ensure AWS environments meet compliance standards such as SOC 2, ISO 27001, and GDPR; implement automated guardrails and policy enforcement using AWS Config and SCPs; deliver audit-ready evidence dashboards.
- Build custom scripts and tools to automate security tasks, alerts, and reporting; develop incident response automation (Lambda/Step Functions auto-remediation).
- Work closely with development, operations, and security teams to promote a DevSecOps culture; mentor junior engineers and conduct security training sessions.
Requirements
- 6+ years of experience in DevOps, Cloud Security, or Infrastructure Engineering.
- 4+ years of hands-on experience with AWS services and security best practices.
- Strong proficiency in scripting languages (Python, Bash, etc.).
- Experience with containerization (Docker) and orchestration (Kubernetes/EKS).
- Familiarity with security tools like Snyk, Aqua, Prisma Cloud, HashiCorp Vault, etc.
- Deep understanding of IAM, network security, encryption, and secure access patterns.
- Experience with IaC tools (Terraform, CloudFormation) and version control systems (Git).
- Knowledge of compliance frameworks and secure SDLC principles.
- Preferred: AWS Certified Security – Specialty or other relevant AWS certifications.
- Preferred: Experience with zero-trust architecture and cloud-native security models.
- Preferred: Exposure to multi-account AWS environments and landing zone setups.
- Preferred: Familiarity with DevSecOps maturity models and risk assessment methodologies.