Web Application Security Engineer

OpenKyber LLC
United States
3 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$114,400.0 - $135,200.0
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services Amazon Elastic Compute Cloud Amazon S3 Audit Trail Continuous Integration Amazon DynamoDB Github Identity and Access Management OpenID Role-Based Access Control Web Application Security Systems Integration
+8 more
Management of Software Versions Data Logging Autoscaling Amazon Virtual Private Cloud (VPC) Cloudwatch Rundeck Terraform Software Version Control

Job description

responsibilities: Design, build, and maintain Terraform modules and IaC patterns used by multiple delivery teams. Implement and operate Terraform deployments via Spacelift, including stack design, approvals, drift detection, and environment promotion. Develop and maintain Rundeck jobs for AWS operational automation, break?glass actions, and platform support workflows. Build and support GitHub?based CI/CD pipelines using GitOps principles (PR?driven change control). Establish and enforce AWS standards for: Account structure and environments Tagging, cost allocation, and ownership Security, access control, and auditability Implement secure automation using IAM roles, OIDC, and least?privilege access. Collaborate with application and platform teams to onboard workloads to standardized IaC tooling. Produce and maintain documentation, runbooks, and onboarding guides. Troubleshoot IaC, pipeline, and automation failures; participate in root cause analysis as needed.

Requirements

Do you have experience in Version control?, Do you have a Bachelor’s degree?, qualifications: Infrastructure as Code (Terraform) 5+ years of hands?on Terraform experience in production AWS environments. Advanced experience with: Module design, reuse, and versioning Remote state using S3 and DynamoDB Multi?account and multi?environment deployments Standards enforcement via validation and lifecycle rules Experience supporting centralized Terraform modules consumed by many teams. AWS Cloud Expertise Strong, practical experience with: AWS Organizations, SCPs, and multi?account strategies Cross?account IAM role design Account bootstrap / landing zone concepts Hands?on experience provisioning AWS services via Terraform, including: IAM VPC and networking EC2 / Auto Scaling EKS or ECS (working knowledge) S3, RDS CloudWatch and logging KMS and encryption Spacelift (Terraform Orchestration) Production experience using Spacelift for Terraform: Stack and dependency design Environment promotion and approvals Worker configuration (private or AWS?hosted preferred) Drift detection and scheduled runs Experience integrating Spacelift with AWS IAM and GitHub workflows. Rundeck (Operational Automation) Experience designing and operating Rundeck jobs for AWS infrastructure operations. Strong understanding of: Job security, RBAC, and approvals Credential management using IAM roles (no static keys) Error handling, retries, and notifications Familiarity with job?as?code or version?controlled job patterns. GitHub & CI/CD Enterprise GitHub experience, including: Branch protection rules and CODEOWNERS Required reviews and PR?based change control GitHub Actions for CI/CD OIDC?based authentication to AWS Strong understanding of GitOps delivery models. Security & Compliance Experience implementing: Least?privilege IAM and permission boundaries Secure secrets handling (no credentials in code) Approval workflows and separation of duties Ability to embed security and compliance into IaC pipelines rather than manual processes. Experience in regulated or risk?sensitive environments strongly preferred. Operational & Collaboration Skills Strong troubleshooting and operational mindset. Experience supporting shared platforms used by many teams. Ability to document solutions clearly and enable team adoption. Strong communication skills and comfort working with cross?functional stakeholders.

Benefits & conditions

Alaska Remote $55 - $65 an hour - Contract, Pulled from the full job description

  • AD&D insurance
  • 401(k)
  • Health insurance
  • Vision insurance
  • Dental insurance
  • Life insurance
  • Disability insurance

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · WWC 2023

1:06 min

Developer experience and project variety at scale

Alexandra Petri · WWC 2023

2:52 min

Implementing IAM with Keycloak and OpenID Connect

Thomas Südbröcker · LIVE

2:40 min

Using GitHub primitives for internal documentation and corporate operations

Kyle Daigle · Coffee With Developers

1:34 min

Pivoting careers into specialized platform engineering roles

Xavier Portilla Edo · LIVE

Videos

See all

Related articles

See all