Security Architect - AWS
Ai Asap Llc
United States
3 days ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
3 years minimum
Working hours
Regular working hours
Job source
Tech stack
Java (Programming Language)
.NET Framework
Amazon Web Services
Amazon Elastic Compute Cloud
Software System Penetration Testing
User Authentication
Burp Suite
Cloud Computing
Cyber Security
Continuous Integration
Github
Identity and Access Management
+26 more
Python (Programming Language)
OAuth
OpenID
Open Web Application Security
PCI Data Security Standards
Security Assertion Markup Language (SAML)
Secure Coding
SonarQube
Policy as Code
Delivery Pipeline
Software Security
Veracode
Cloudformation
Gitlab-ci
Information Technology
Checkmarx
Api Gateway
Terraform
Prisma Cloud Platform
Devsecops
Serverless Computing
Docker
Jenkins
Static Application Security Testing
Microservices
Dynamic Application Security Testing
Job description
- Perform threat modeling and secure design reviews for applications and microservices deployed on AWS (EC2, ECS/EKS, Lambda, API Gateway).
- Integrate and operate security tooling in CI/CD pipelines: SAST, DAST, SCA/dependency scanning, container image scanning, and IaC scanning.
- Configure and manage AWS-native security services: WAF, Shield, GuardDuty, Inspector, Security Hub, KMS, Secrets Manager, IAM.
- Define and enforce least-privilege IAM policies, secrets management standards, and encryption (at rest/in transit) across workloads.
- Conduct secure code reviews and vulnerability triage; partner with dev teams on remediation and secure coding practices (OWASP Top 10, CWE).
- Harden infrastructure-as-code (Terraform/CloudFormation) using policy-as-code (OPA, Checkov) and guardrails (SCPs, Config rules).
- Support penetration test coordination, findings remediation, and audit/compliance requirements (SOC 2, ISO 27001, PCI-DSS as applicable).
- Respond to application-layer security incidents; contribute to detection rules and runbooks.
- Mentor engineers and champion DevSecOps culture across delivery teams.
Requirements
- 15+ years in application security / product security, with 3+ years securing workloads on AWS.
- Hands-on expertise with AWS security services: IAM, WAF, GuardDuty, Inspector, Security Hub, KMS, Secrets Manager, CloudTrail.
- Strong knowledge of OWASP Top 10, API security, authentication/authorization patterns (OAuth 2.0, OIDC, SAML).
- Experience with security tooling: SonarQube/Checkmarx/Veracode (SAST), Snyk/Prisma/Aqua (SCA & containers), Burp Suite/OWASP ZAP (DAST).
- Proficiency in at least one language for automation - Python, Go, or similar; ability to read Java/Node.js/.NET application code.
- Experience securing containerized (Docker, EKS/ECS) and serverless (Lambda) architectures.
- IaC security: Terraform or CloudFormation with Checkov/tfsec/cfn-nag.
- CI/CD security integration: GitHub Actions, GitLab CI, Jenkins, or AWS CodePipeline.
- Certifications: AWS Certified Security - Specialty (strongly preferred); CSSLP, OSWE, or CISSP.
Preferred Qualifications
- Experience with CNAPP platforms (Wiz, Prisma Cloud, CrowdStrike Falcon Cloud).
- Threat modeling frameworks (STRIDE, PASTA) and secure SDLC program experience.
- Prior work in a client-facing or consulting/delivery environment with enterprise customers.
- Exposure to compliance frameworks: SOC 2, ISO 27001, PCI-DSS, HIPAA, FedRAMP.
Soft Skills
- Strong communication - able to explain risk and remediation to both engineers and business stakeholders.
- Pragmatic, risk-based mindset; balances security rigor with delivery velocity.
- Self-driven; comfortable operating in ambiguous, fast-moving programs., Bachelor’’s degree in Computer Science, Information Security, or equivalent practical experience.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.dice.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
DC
Daniel Cranney
over 1 year ago
DC
Daniel Cranney
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
6 months ago
CH
Chris Heilmann
Dev Digest 134 - Where pixels sing?
almost 2 years ago
BB
Benedikt Bischof
Walking Into The Era of Supply Chain Risks
about 4 years ago
LM
Luis Minvielle
9 Ways to Make Money Hacking
about 2 years ago
AJ
Austin Joy
What Are The Top Skills Required For Azure Developers?
over 4 years ago