> Markdown version of [/jobs/ext/186759-application-security](https://www.wearedevelopers.com/jobs/ext/186759-application-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security - **Company:** Pyramid Consulting Inc. - **Location:** Hartford, CT, United States (Remote available) - **Experience:** Expert - **Salary:** $145,600.0 - $156,000.0 - **Contract:** Temporary contract - **Skills:** Application Programming Interfaces (APIs), Amazon Web Services, Amazon Elastic Compute Cloud, Cloud Computing, Cloud Computing Security, Cloud Engineering, Continuous Integration, Github, Python (Programming Language), Performance Tuning, Security Software, Systems Integration, Policy as Code, Cloud Platform System, Software Security, Software Troubleshooting, Infrastructure as Code (IaC), Kubernetes, Functional Programming, Api Gateway, Terraform, Devsecops, Serverless Computing, Docker, Security Orchestration, Automation & Response - **Published:** May 16, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=d8435b130bc88dc8 ## About the Role Do you have experience in Terraform?, * 5 years of experience in Cloud Security Engineering, DevSecOps, or related security engineering roles. * Strong hands-on experience with AWS security services and cloud-native security controls. * Deep expertise with AWS WAF, including rule creation, tuning, troubleshooting, and production support. * Experience securing APIs and working with API Gateway and API-focused security tools. * Strong Infrastructure as Code experience using Terraform. * Proficiency in Python scripting and automation. * Experience with GitHub and GitHub Actions for CI/CD and security automation workflows. * Experience securing cloud-native workloads including Docker, Kubernetes, Lambda, and EC2 environments. * Strong troubleshooting, analytical, and communication skills. * Ability to work cross-functionally with engineering, architecture, and security teams. * AWS certifications such as: * AWS Certified Security - Specialty * AWS Certified Solutions Architect * AWS Certified Developer or SysOps Administrator * Security certifications such as CCSP or equivalent. * Experience working in enterprise-scale cloud environments. * Familiarity with policy-as-code and automated security enforcement frameworks. ## Description * Design, implement, tune, and manage AWS WAF rules, policies, and protections for internet-facing applications. * Support and enhance existing cloud security automation workflows using Terraform, Python, and GitHub Actions. * Perform API security engineering, including integrations with API security tools and security monitoring platforms. * Improve visibility, ownership, and accountability of security findings across application environments. * Maintain and enhance Infrastructure as Code (IaC) and policy-as-code security configurations. * Collaborate with cloud architecture, application security, and development teams to implement and optimize security controls. * Support cloud-native environments including containers, Kubernetes, serverless functions (Lambda), and EC2 workloads from a security perspective. * Troubleshoot and resolve WAF and API security-related production issues, including false positive reduction and rule tuning. * Participate in incident-driven security changes and operational support activities. * Recommend and implement improvements to cloud security automation, reporting, and governance processes. ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline)