Description
Responsibilities
- Own cloud security architecture and technical controls across AWS environments. Designing and operating scalable, auditable safeguards that support FedRAMP, CJIS, HIPAA, and GDPR workloads.
- Execute and sustain FedRAMP Moderate technical requirements in production. Partnering with Product Security and GRC peers to maintain control effectiveness, remediate findings, and support ongoing authorization activities.
- Build and enforce automated cloud security guardrails. Establishing configuration baselines, policy enforcement, and drift detection to prevent non-compliant infrastructure changes.
- Secure AWS network boundaries and regulated data flows. Ensuring segmentation, ingress and egress controls, and inspection patterns meet regulatory and organizational security requirements.
- Support cryptographic and platform security standards. Ensuring encryption, key management, and platform configurations align with regulatory expectations and industry best practices.
- Lead security readiness for significant architectural change. Performing technical security impact analysis for new services, infrastructure changes, and boundary expansions before production deployment.
- Integrate cloud security telemetry into detection and response workflows. Ensuring logging and security signals support continuous monitoring, investigations, and audit evidence needs.
- Embed cloud security into infrastructure and delivery workflows. Collaborating with Infrastructure Engineering to integrate security controls into infrastructure-as-code and CI/CD processes.
- Apply cloud security controls across multi-regulatory environments. Supporting CJIS, HIPAA, and GDPR workloads while reducing one-off solutions and improving consistency.
- Contribute to cloud security strategy and maturity. Helping define the D&I cloud security roadmap, identifying opportunities for automation, and evolving security practices over time.
Qualifications
Soft Skills
- Accountable and Self-Directed. Owns work end-to-end, makes sound decisions with limited direction, and accepts responsibility for outcomes in regulated cloud environments.
- Strong Judgment and Decision-Making. Evaluates risk thoughtfully, anticipates downstream impacts, and balances security, compliance, and delivery realities.
- Clear and Credible Communicator. Explains complex cloud security and compliance topics clearly to engineers, auditors, customers, and non-technical stakeholders; documents decisions and evidence with precision.
- Highly Organized and Reliable. Manages multiple concurrent efforts, meets deadlines consistently, and produces accurate, audit-ready work products.
- Resilient and Adaptable. Able to manage shifting priorities, audit pressure, and evolving regulatory requirements without sacrificing quality or professionalism.
- Detail-Oriented with Systems Thinking. Understands how individual cloud or configuration decisions affect broader platform risk, compliance posture, and customer trust.
- Pragmatic and Solutions-Focused. Seeks practical, sustainable security outcomes rather than theoretical perfection; knows how to move work forward within constraints.
- Collaborative and Team-Oriented. Works effectively across security, infrastructure, engineering, and compliance teams; contributes to shared goals without seeking credit.
- Open to Feedback and Continuous Improvement. Actively seeks input, learns from experience, and continuously develops skills aligned with role expectations and organizational goals.
Tools and Technologies
- AWS cloud security and infrastructure services, including IAM, VPC networking, Security Groups/NACLs, CloudTrail, GuardDuty, AWS Config, Security Hub, KMS, and CloudWatch.
- Infrastructure as Code (IaC) using tools such as Terraform or CloudFormation, with an emphasis on secure, repeatable deployments and configuration baselines.
- Linux-based operating systems (e.g., Amazon Linux, Ubuntu) with strong command-line proficiency and an understanding of OS-level hardening.
- Network security fundamentals, including segmentation, private connectivity patterns, ingress/egress controls, and secure service-to-service communication.
- Cloud-native security monitoring and logging, including centralized log aggregation, alerting, investigation, and correlation across infrastructure and security telemetry.
- Vulnerability and cloud security posture management, including misconfiguration detection, risk prioritization, and remediation tracking in cloud environments.
- Security automation and scripting, using languages such as Python or Bash to validate configurations, collect compliance evidence, and reduce manual effort.
- Secure CI/CD and engineering collaboration practices, including integrating security checks into pipelines and reviewing infrastructure, configuration, and policy changes via pull requests in GitHub.
- Experience securing containerized workloads in AWS, including an understanding of ECS and Fargate security models, task and execution IAM roles, networking and isolation boundaries, logging, and shared responsibility considerations.
- Experience working with modern cloud security tooling, including infrastructure and cloud-focused code scanning, cloud security posture management, endpoint and workload telemetry, and centralized log analysis platforms
- (e.g., GitHub Advanced Security, Tenable Cloud Security, CrowdStrike, Sumo Logic; familiarity with tools such as Nessus, AquaSec, Invicti, and CI/CD platforms like Jenkins or GitHub Actions is a plus)
- Working knowledge of NIST-based security frameworks, particularly NIST SP 800-53, with the ability to map technical implementations to control intent and audit evidence.
- Experience supporting compliance-driven environments, such as FedRAMP Moderate, CJIS, HIPAA, SOC 2, or similar regulated frameworks.
- Identity, access, and cryptography fundamentals, including least privilege, service roles, federated access, MFA enforcement, encryption in transit and at rest, certificate management, and FIPS-aligned cryptographic practices.
- Ability to pass a federal background check and obtain and maintain CJIS clearance required
- Other
- Bachelor's degree in Computer Science, Engineering, Mathematics, Information Systems, or a related field preferred
- Valued Certifications: AWS Security Specialty, AWS Solutions Architect, CompTIA Security+, CISSP
There are more than 50,000 engineering jobs:
Subscribe to membership and unlock all jobs
Engineering Jobs
60,000+ jobs from 4,500+ well-funded companies
Updated Daily
New jobs are added every day as companies post them
Refined Search
Use filters like skill, location, etc to narrow results
Become a member
🥳🥳🥳 452 happy customers and counting...
Overall, over 80% of customers chose to renew their subscriptions after the initial sign-up.
To try it out
For active job seekers
For those who are passive looking
Cancel anytime
Frequently Asked Questions
- We prioritize job seekers as our customers, unlike bigger job sites, by charging a small fee to provide them with curated access to the best companies and up-to-date jobs. This focus allows us to deliver a more personalized and effective job search experience.
- We've got over 200,000 jobs from 15,000+ vetted companies. No fake or sleazy jobs here!
- We aggregate jobs from 15,000+ companies' career pages, so you can be sure that you're getting the most up-to-date and relevant jobs.
- We're the only job board *for* software engineers, *by* software engineers… in case you needed a reminder! We add thousands of new jobs daily and offer powerful search filters just for you. 🛠️
- Every single hour! We add 2,000-3,000 new jobs daily, so you'll always have fresh opportunities. 🚀
- Typically, job searches take 3-6 months. EchoJobs helps you spend more time applying and less time hunting. 🎯
- Check daily! We're always updating with new jobs. Set up job alerts for even quicker access. 📅
What Fellow Engineers Say
