5+ years of hands-on cloud security engineering experience, specifically with AWS preferred Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or related discipline, or equivalent professional experience preferred Relevant certifications such as AWS Certified Security Specialty, CISSP, or similar preferred Deep expertise in AWS security services (e.g., Security Hub, GuardDuty, AWS Config, Inspector, Macie) Proficiency with scripting languages (Python, Bash) to automate security controls and integrate with Infrastructure as Code workflows Experience configuring and managing AWS multi account strategies and network architectures (e.g., Control Tower, SCPs, Guardrails) Proven ability to deploy and optimize WAF and API hardening solutions Hands-on experience automating security incident response and compliance workflows Solid understanding of data security, including DLP and encryption standards Practical knowledge of vulnerability management at cloud scale and security scanning tools (DAST/SCA/AWS Inspector, Burp, etc)