Security Architect - AWS

V-Work Infotech Solutions INC
United States
3 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

Application Programming Interfaces (APIs) Amazon Web Services Amazon Elastic Compute Cloud Software System Penetration Testing Burp Suite Cloud Computing Cloud Computing Security Cloud Engineering Cyber Security Continuous Integration DevOps Github
+41 more
Identity and Access Management Information Systems Security Architecture Professional Python (Programming Language) Key Management OAuth OpenID Open Web Application Security PCI Data Security Standards Role-Based Access Control Openid Connect Security Assertion Markup Language (SAML) Secure Coding Software Engineering SonarQube Software Vulnerability Management Policy as Code Delivery Pipeline Sonatype Software Security Veracode AWS Lambda Cloudformation Containerization Gitlab-ci Kubernetes Infrastructure Automation Frameworks Information Technology Checkmarx Opsworks Functional Programming Api Gateway Terraform Prisma Cloud Platform Devsecops Serverless Computing Docker Jenkins Static Application Security Testing Vulnerability Analysis Microservices Dynamic Application Security Testing

Requirements

  • 15+ years of experience in Application Security, Product Security, or DevSecOps, including 3+ years securing AWS-based applications.
  • Strong expertise in securing applications throughout the Secure Software Development Lifecycle (SSDLC).
  • Perform threat modeling and secure architecture reviews for applications, APIs, microservices, and cloud-native workloads.
  • Hands-on experience securing AWS services including EC2, ECS/EKS, Lambda, API Gateway, IAM, WAF, Shield, GuardDuty, Inspector, Security Hub, KMS, Secrets Manager, and CloudTrail.
  • Implement and manage security controls across CI/CD pipelines using SAST, DAST, SCA, container image scanning, and Infrastructure-as-Code (IaC) scanning.
  • Integrate security into GitHub Actions, GitLab CI, Jenkins, AWS CodePipeline, or similar CI/CD platforms.
  • Configure and enforce least-privilege IAM policies, role-based access control (RBAC), secrets management, and encryption standards.
  • Conduct secure code reviews and vulnerability assessments using OWASP Top 10, CWE, and secure coding best practices.
  • Experience with security tools such as SonarQube, Checkmarx, Veracode, Snyk, Prisma Cloud, Aqua Security, Burp Suite, and OWASP ZAP.
  • Secure containerized workloads using Docker, Kubernetes (EKS), ECS, and serverless applications using AWS Lambda.
  • Perform Infrastructure-as-Code (IaC) security using Terraform or CloudFormation with Checkov, tfsec, cfn-nag, or similar tools.
  • Develop automation scripts using Python, Go, or similar languages for security validation and compliance.
  • Strong understanding of API security, OAuth 2.0, OpenID Connect (OIDC), SAML, JWT, and authentication/authorization mechanisms.
  • Implement cloud security guardrails using AWS Organizations, Service Control Policies (SCPs), AWS Config, and policy-as-code frameworks such as OPA.
  • Coordinate penetration testing activities, validate findings, and drive remediation with development teams.
  • Support security audits and compliance initiatives including SOC 2, ISO 27001, PCI-DSS, HIPAA, and FedRAMP.
  • Respond to application security incidents, investigate threats, and develop detection rules and incident response runbooks.
  • Experience with Cloud Native Application Protection Platforms (CNAPP) such as Wiz, Prisma Cloud, or CrowdStrike Falcon Cloud.
  • Strong knowledge of threat modeling methodologies including STRIDE and PASTA.
  • Collaborate with development, DevOps, infrastructure, and client security teams to promote DevSecOps best practices.
  • Mentor engineering teams on secure coding, cloud security, and vulnerability remediation.
  • Excellent communication, analytical, troubleshooting, and stakeholder management skills.
  • AWS Certified Security - Specialty preferred; CSSLP, CISSP, or OSWE certifications are highly desirable.
  • Bachelor’’s degree in Computer Science, Information Security, Cybersecurity, or a related field.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

2:07 min

Inspecting default bridge architectures and custom Docker networks

Oliver Seitz Oliver Seitz · WWC 2025

1:53 min

Transitioning toward DevSecOps with dynamic scanning and secrets management

Christoph Ruggenthaler · LIVE

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter · WWC 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · WWC Europe 2026

Videos

See all

Related articles

See all