AWS Security Engineer
AWS Security Engineer responsible for designing and implementing AWS security controls, developing processes for compliance, and playing a central role in incident response and operational security.
Key Highlights
Key Responsibilities
Technical Skills Required
Job Description
Position Overview:
This position combines hands-on AWS security engineering, process design for compliance, and incident management to continuously improve our security posture.
The ideal candidate is a proactive, technically strong engineer who thrives in a collaborative, globally distributed environment. They will design and implement AWS security controls, develop the processes needed to maintain compliance with standards such as ISO 27001 and SOC 2, and play a central role in incident response and operational security.
Responsibilities:
Cloud Security Engineering
- Design, implement, and manage AWS security architecture aligned with company standards and best practices (IAM, VPC, KMS, GuardDuty, Security Hub, Macie, Config, Inspector).
- Directly implement secure configurations and remediation actions within AWS accounts.
- Automate detection, alerting, and response workflows using AWS Lambda, Step Functions, and EventBridge.
- Maintain compliance baselines through infrastructure-as-code (Terraform or CloudFormation).
- Continuously assess and improve the security of AWS services (EC2, S3, RDS, ECS/EKS, CloudFront, API Gateway).
Security Operations & Incident Response
- Monitor and manage security events, alerts, and vulnerabilities across environments.
- Lead or support investigation, containment, and recovery activities during security incidents.
- Develop, document, and refine incident response playbooks and escalation processes.
- Coordinate global response teams across time zones, ensuring clear communication and effective collaboration.
- Conduct forensic analysis and post-incident reviews to strengthen defenses.
- Compliance, Governance & Process Development
- Define and maintain security and compliance processes aligned with ISO 27001 and SOC 2 requirements.
- Support the company’s Information Security Management System (ISMS).
- Perform risk assessments, control validation, and evidence collection for internal and external audits.
- Partner with leadership to ensure documentation and policies reflect real-world operations.
- Deliver security training and awareness programs to reinforce best practices.
Collaboration & Continuous Improvement
- Work closely with IT, DevOps, and Software Development teams to embed security-by-design principles in all systems.
- Collaborate effectively across a remote, globally distributed team, maintaining strong communication, follow-through, and accountability.
- Lead automation and process improvement initiatives to enhance visibility, efficiency, and reliability.
- Stay current with evolving cloud security trends, vulnerabilities, and AWS platform enhancements.
- Contribute to cross-functional improvement efforts during Development Leadership and Security meetings.
Similar Jobs
Explore other opportunities that match your interests