5+ years in Security Engineering / DevSecOps roles with proven success delivering secure infrastructure and applications. Strong skills in Python and Bash for building and automating security workflows. Deep knowledge of AWS Cloud Security (IAM least-privilege, encryption, GuardDuty, Security Hub, multi-account environments). Implementation of security controls in pipelines (SAST, DAST, dependency scanning, container image scanning, policy-as-code). Hardening of Linux systems, Docker, Kubernetes/EKS; strong experience with RBAC, PodSecurity/OPA/Gatekeeper/Kyverno policies. Terraform/Terragrunt expertise, including policy-as-code, drift detection, and compliance enforcement. Expertise with HashiCorp Vault, AWS Secrets Manager, or equivalent. Hands-on with centralized logging, SIEM/SOAR tools (Datadog Security, ELK, CloudWatch, etc.) and incident response workflows. In-depth understanding of secure network design, segmentation, and monitoring. Experience with tools enabling temporary, approval-based access (Teleport, AWS IAM Identity Center, Okta, etc.). Ability to design and enforce zero trust principles (continuous verification, microsegmentation, contextual access). Familiarity with SBOM generation (CycloneDX, Syft), artifact signing (Cosign, Sigstore), and applying SLSA/in-toto frameworks. Understanding of ISO 27001, GDPR, PCI-DSS (iGaming relevance), plus experience automating compliance checks with IaC and policy engines.