Application Security

Pyramid Consulting Inc.
Hartford, CT, United States
3 months ago

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$145,600.0 - $156,000.0
Working hours
Regular working hours
Job source

Tech stack

Application Programming Interfaces (APIs) Amazon Web Services Amazon Elastic Compute Cloud Cloud Computing Cloud Computing Security Cloud Engineering Continuous Integration Github Python (Programming Language) Performance Tuning Security Software Systems Integration
+13 more
Policy as Code Cloud Platform System Software Security Software Troubleshooting Infrastructure as Code (IaC) Kubernetes Functional Programming Api Gateway Terraform Devsecops Serverless Computing Docker Security Orchestration, Automation & Response

Job description

  • Design, implement, tune, and manage AWS WAF rules, policies, and protections for internet-facing applications.
  • Support and enhance existing cloud security automation workflows using Terraform, Python, and GitHub Actions.
  • Perform API security engineering, including integrations with API security tools and security monitoring platforms.
  • Improve visibility, ownership, and accountability of security findings across application environments.
  • Maintain and enhance Infrastructure as Code (IaC) and policy-as-code security configurations.
  • Collaborate with cloud architecture, application security, and development teams to implement and optimize security controls.
  • Support cloud-native environments including containers, Kubernetes, serverless functions (Lambda), and EC2 workloads from a security perspective.
  • Troubleshoot and resolve WAF and API security-related production issues, including false positive reduction and rule tuning.
  • Participate in incident-driven security changes and operational support activities.
  • Recommend and implement improvements to cloud security automation, reporting, and governance processes.

Requirements

Do you have experience in Terraform?, * 5 years of experience in Cloud Security Engineering, DevSecOps, or related security engineering roles.

  • Strong hands-on experience with AWS security services and cloud-native security controls.
  • Deep expertise with AWS WAF, including rule creation, tuning, troubleshooting, and production support.
  • Experience securing APIs and working with API Gateway and API-focused security tools.
  • Strong Infrastructure as Code experience using Terraform.
  • Proficiency in Python scripting and automation.
  • Experience with GitHub and GitHub Actions for CI/CD and security automation workflows.
  • Experience securing cloud-native workloads including Docker, Kubernetes, Lambda, and EC2 environments.
  • Strong troubleshooting, analytical, and communication skills.
  • Ability to work cross-functionally with engineering, architecture, and security teams.
  • AWS certifications such as:
  • AWS Certified Security - Specialty
  • AWS Certified Solutions Architect
  • AWS Certified Developer or SysOps Administrator
  • Security certifications such as CCSP or equivalent.
  • Experience working in enterprise-scale cloud environments.
  • Familiarity with policy-as-code and automated security enforcement frameworks.

Benefits & conditions

Pulled from the full job description

  • 401(k)
  • Health insurance
  • Vision insurance
  • Dental insurance
  • Paid sick time, Pay Range: $70 - $75/hour. Employee benefits include, but are not limited to, health insurance (medical, dental, vision), 401(k) plan, and paid sick leave (depending on work location).

About the company

Our client is a leading Insurance Industry, and we are currently interviewing to fill this and other similar contract positions. If you are interested in this position, please apply online for immediate consideration.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:07 min

Inspecting default bridge architectures and custom Docker networks

Oliver Seitz Oliver Seitz · WWC 2025

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · WWC 2023

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

1:34 min

Pivoting careers into specialized platform engineering roles

Xavier Portilla Edo · LIVE

2:34 min

Docker sandbox architecture and microVM environment integration

Manuel de la Peña Manuel de la Peña · WWC Europe 2026

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

Videos

See all

Related articles

See all