Full Stack Security Engineer (AWS)

Energy Llc
Houston, TX, United States
18 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

.NET Framework Amazon Web Services ASP.NET MVC Framework Unit Testing Bash Shell C Sharp (Programming Language) Cloud Computing Security Database Security Identity and Access Management Intrusion Detection and Prevention Information Systems Security Architecture Professional Python (Programming Language)
+10 more
Microsoft SQL Server Systems Development Life Cycle Software Engineering SQL Stored Procedures .NET Core Infrastructure as Code (IaC) Information Technology React Native Terraform Devsecops

Job description

As a Full Stack Security Engineer (AWS) at Energy Ogre, you will bridge the gap between software development and cloud security. You will join a high-impact team building secure applications and tools that power our member experiences. You are responsible for the entire development lifecycle-incorporating security-by-design into our C#/.NET stack while architecting robust protection for our AWS cloud-based infrastructure., * Full-Cycle Development: Participate in all phases of the SDLC, from requirements gathering to deployment.

  • Problem Solving: Investigate user pain points, identify root causes, and engineer scalable solutions.
  • System Maintenance: Maintain and refactor existing codebases while proactively integrating new technologies and architectures.
  • Cloud Security Architecture: Design and implement comprehensive security strategies for AWS, including secure architecture blueprints and identity management (IAM).
  • DevSecOps & Automation: Integrate security checks into CI/CD pipelines and implement security automation using Infrastructure as Code (IaC) like Terraform.
  • Threat Detection: Monitor infrastructure for anomalies, conduct vulnerability scans, and develop incident response playbooks for cloud-based threats.
  • Database Security: Optimize SQL Server Stored Procedures and implement end-to-end encryption for data at rest and in transit.
  • Infrastructure Security: Implement and manage security protocols to protect infrastructure, including firewalls, intrusion detection/prevention systems, and encryption
  • Encryption and Data Protection: Implement end-to-end encryption strategies for data at rest and in transit
  • Quality Assurance: Conduct functional and unit testing before delivering code to UAT to ensure high-performance standards.

Requirements

  • Autonomy: Strong ability to work independently with minimal supervision while meeting deadlines.
  • Communication: Ability to bridge the gap between technical requirements and non-technical business needs.
  • Estimation: Proficiency in estimating task complexity and delivering on project milestones.
  • Continuous Learning: A passion for self-advancement and keeping pace with evolving tech stacks.

Required Education & Experience

  • Education: Bachelor’s Degree in Computer Science (or a related field)
  • Professional Experience: 3+ years of software development experience
  • Core Skills: Proficiency in C# and the .NET ecosystem (ASP.NET MVC 5, .NET Core).
  • Software Expertise: 3+ years of experience with C#, .NET Core, SQL Server, and React Native.
  • Cloud Security Expertise: Cloud security engineering expertise (AWS preferred) with certifications like CISSP, CCSP, or AWS Security Specialty.
  • Automation & Compliance: Proficiency in Python/Bash scripting and familiarity with security frameworks (NIST, CIS, ISO 27001).

Benefits & conditions

Pulled from the full job description

  • 401(k)
  • Health insurance
  • Paid time off
  • Vision insurance
  • Dental insurance, * 401(k)
  • Dental insurance
  • Health insurance
  • Paid time off
  • Vision insurance

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

1:34 min

Essential commands for running and testing Terraform configurations

Hennie Francis · LIVE

3:27 min

Preventing command injection during system process execution

Sebastian Leuer Sebastian Leuer · WWC 2024

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

Videos

See all

Related articles

See all