About the Role: We are seeking an experienced AWS Cloud Security Engineer to join our team and take ownership of securing multiple diverse AWS environments. This role will focus on designing, implementing, and enforcing security policies, guardrails, and best practices to ensure the security and compliance of our cloud infrastructure. The ideal candidate will have strong expertise in AWS security services, automation, and compliance frameworks. Key Responsibilities: Design, implement, and maintain security policies and guardrails across diverse AWS environments.Develop and enforce cloud security best practices to protect critical workloads, data, and infrastructure.Implement and manage AWS-native security tools such as AWS IAM, AWS Organizations, GuardDuty, Security Hub, Macie, WAF, SCPs, and Control Tower.Work closely with DevOps, Cloud, and Security teams to integrate security controls into CI/CD pipelines and cloud workloads.Automate security processes using Infrastructure as Code (IaC) tools such as Terraform or AWS CloudFormation.Monitor and assess AWS environments for compliance with security frameworks (e.g., NIST, CIS, ISO 27001, SOC 2, HIPAA).Conduct security assessments, audits, and threat modelling to proactively identify and mitigate security risks.Provide guidance and training to internal teams on AWS security best practices and policies.Stay updated with the latest cloud security trends, vulnerabilities, and AWS security services. Required Skills & Experience: 2+ years of hands-on experience in AWS cloud security engineering or a similar role.Deep knowledge of AWS security services, IAM policies, networking security, and encryption mechanisms.Experience with security automation using Python, Lambda, or other scripting languages.Proficiency in Infrastructure as Code (IaC) tools like Terraform, AWS CloudFormation, or CDK.Strong understanding of cloud compliance frameworks (CIS AWS Benchmark, NIST, SOC 2, etc.).Experience with
SIEM, SOAR, and
incident response in AWS environments.Familiarity with AWS Organizations, SCPs, and multi-account governance models.Ability to work independently and collaborate effectively with cross-functional teams. Preferred Qualifications:Experience securing multi-cloud environments.Hands-on experience with Kubernetes security (EKS) and container security best practices.Familiarity with cloud-native Zero Trust Security principles.Knowledge of penetration testing and vulnerability management in AWS. Preferred Certifications: AWS Certified Security SpecialistAWS Certified Advanced Networking - Specialty