> Markdown version of [/jobs/ext/145978-senior-cybersecurity-engineer](https://www.wearedevelopers.com/jobs/ext/145978-senior-cybersecurity-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Cybersecurity Engineer - **Company:** Integrated Specialty Coverages, LLC - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $150,000.0 - $180,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Amazon Web Services, User Authentication, Cyber Security, Continuous Integration, Data Security, Github, Identity and Access Management, Information Systems Security Architecture Professional, Python (Programming Language), Key Management, Network Security, Routing, Phishing, Security Information and Event Management, Systems Integration, Software Vulnerability Management, Policy as Code, Data Logging, Delivery Pipeline, Firewalls (Computer Science), Amazon Virtual Private Cloud (VPC), Gitlab, Git, Cloudformation, Cloudwatch, Terraform, Security Orchestration, Automation & Response - **Published:** May 19, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=9615cc9cb83785ce ## About the Role * 7+ years in security engineering with production AWS (multi-account/Organizations) and automation-first delivery. * Domain experience in at least three of the following: + Network security (segmentation, routing, firewall, proxy, WAF) + Endpoint security (EDR/EPP, hardening, health attestation) + Email security (phishing protection, authentication, inbound/outbound controls) + Data security (classification, DLP, encryption, key management) + Vulnerability management (scanning, prioritization, remediation pipelines) + Container security (image scanning, runtime policy, supply chain) + Identity and access management (policy design, federation, least privilege) * IaC proficiency (Terraform preferred) and Python for automation; CI/CD integration experience (e.g., GitHub Actions, GitLab, CodePipeline). * Experience with root-cause analysis and remediation of control failures (not incident RCA). * Demonstrated ability to independently drive complex projects to completion, as well as collaborate effectively with a complex set of stakeholders., * Designed landing zones with SCPs, baseline detective controls, centralized logging, account vending, and guardrail automation. * Built event-driven remediations (e.g., detect to auto-tag/deny/quarantine) safely with approvals and rollbacks. * Advanced experience engineering security controls in AWS (for example, IAM, KMS, VPC, GuardDuty, Security Hub, Detective, CloudTrail, CloudWatch, Organizations, Control Tower), with automation first practices. * Industry certification such as AWS Certified Security - Specialty, Certified Information Systems Security Professional, GIAC Certifications, SANS. * Knowledge of security frameworks and standards such as NIST, ISO, and CIS. ## Description We're looking for a Senior Cybersecurity Engineer to design, build, and operate preventative and detective security controls and automation across our AWS-first and enterprise environments. Reporting to the CISO, this role implements guardrails, platforms, and integrations and partners with infrastructure, platform, and application teams to embed security by default in our AWS cloud and enterprise environments. The role will perform hands-on engineering in multiple security domains including network security, endpoint security, email security, data security, vulnerability management, container security, and identity and access management., * Control Engineering & Operation + Design, implement, and maintain controls in AWS (IAM, KMS, VPC, GuardDuty, Security Hub, Detective, CloudTrail/CloudWatch), network, endpoint, email, data security, vulnerability, and identity domains. + Define SLOs for control availability, latency, coverage, and drift; implement telemetry to continuously measure those SLOs. * Security Automation & "Policy as Code" + Partner with infrastructure, platform, and application teams to build IaC modules (Terraform/CloudFormation) and platform automations (e.g., Python/Lambda, Step Functions) to enforce guardrails (account vending, baseline hardening, logging enablement, key policies, SCPs) using Git. + Implement break-glass patterns and least-privilege workflows that are auditable and reversible. * Detection Enablement + Engineer data pathways (e.g., CloudTrail, VPC Flow, ECS audit, identity logs) into SIEM/MDR tooling; ensure completeness, timeliness, and schema quality. + Translate Detection and Response Lead feedback on false positives/gaps into logging or control adjustments. * Vulnerability & Exposure Engineering + Own scanners/integrations, asset coverage, tagging standards, and develop risk-based remediation pipelines (ticketing, auto-remediation for low-risk classes). + Partner with owners to remove friction (pre-approved windows, canaries, rollbacks). * Identity & Secrets Hardening + Engineer least-privilege patterns, permission boundaries, conditional access, and automated key/secret lifecycle (rotation, discovery, usage attestations). + Provide ready-to-consume roles/policies to teams. * Documentation & Reuse + Maintain runbooks, design docs, and reusable modules; ensure changes are versioned, peer-reviewed, and test- * On-Call (Engineering) + Participate in control-health and platform on-call (e.g., logging ingestion failures, drift, outages). + Escalate security events to the Detection & Response Lead/MDR. ## Related Videos - [Kubernetes Security Best Practices](https://www.wearedevelopers.com/videos/1411-kubernetes-security-best-practices) - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [WeAreDevelopers LIVE - Modern DevOps for IoT Devices and More](https://www.wearedevelopers.com/videos/1805-wearedevelopers-live-modern-devops-for-iot-devices-and-more) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Learning Kubernetes made easy with KubeCampus](https://www.wearedevelopers.com/magazine/348-learning-kubernetes-made-easy-with-kubecampus)