AWS Cloud Security Engineer
New
P
PeratonCloud security
United StatesFull-TimeSenior
Salary$104,000 - $166,000. This represents the typical salary range for this position.
Apply NowOpens the employer's application page
Job Details
- Experience
- Minimum 8 years work experience with BS/BA in computer science, Information Systems, or a related field (or equivalent experience); 5+ years of hands-on AWS engineering experience, with 3+ years specifically in cloud security roles; 3+ years of experience with Infrastructure as Code (Terraform and/or CloudFormation)
- Required Skills
- PythonBashTerraformCloudFormation
Requirements
- Have a minimum of 8 years of work experience with a BS/BA in computer science, Information Systems, or a related field, or equivalent experience.
- Have 5+ years of hands-on AWS engineering experience, including 3+ years in cloud security roles.
- Have experience in a FedRAMP Moderate or High, DoD IL4/IL5, or equivalent federal compliance environment.
- Have experience supporting or maintaining an SSP and RMF processes.
- Have experience with AWS GovCloud (US), AWS Commercial, or equivalent federal AWS environments.
- Demonstrate hands-on expertise with AWS security services, including IAM, GuardDuty, Security Hub, Config, CloudTrail, KMS, WAF, Macie, Inspector, and Systems Manager.
- Understand NIST SP 800-53 Rev 5 control families and how to map implementations to controls.
- Have 3+ years of Infrastructure as Code experience with Terraform and/or CloudFormation, including security scanning and policy-as-code tools.
- Understand VPC design, security groups, NACLs, PrivateLink, Transit Gateway, and network segmentation for compliance boundaries.
- Have experience with vulnerability management and remediation tracking, and implementing Zero Trust Architecture in AWS.
- Be familiar with SIEM or log aggregation tools such as Splunk, AWS CloudWatch, or OpenSearch, and scripting in Python or Bash.
- Understand federal encryption standards, including FIPS 140-2/140-3 and TLS 1.2+, and hold one listed certification: AWS Certified Security – Specialty, AWS Certified Solutions Architect – Professional with a security focus, CISSP, CISM, or Security+ with strong AWS hands-on experience.
Responsibilities
- Design and implement AWS security architecture aligned with FedRAMP Moderate baseline controls.
- Build and maintain security guardrails using AWS-native services.
- Implement and manage Infrastructure as Code security controls with policy as code.
- Support System Security Plans, ATO activities, and POA&M remediation.
- Perform continuous monitoring, vulnerability scanning, and patch management tracking.
- Configure centralized logging, SIEM integration, and audit trail retention.
- Implement least-privilege IAM policies, service control policies, and cross-account access controls.
- Manage encryption at rest and in transit in line with applicable FIPS requirements.
- Respond to security incidents and support cloud-specific incident response playbooks.
- Collaborate with DevOps and Platform teams to embed security into CI/CD pipelines.
View Full Description & ApplyYou'll be redirected to the employer's site