> Markdown version of [/jobs/ext/1991159-security-architect-aws](https://www.wearedevelopers.com/jobs/ext/1991159-security-architect-aws). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Architect - AWS - **Company:** V-Work Infotech Solutions INC - **Location:** United States (Remote available) - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Amazon Web Services, Amazon Elastic Compute Cloud, Software System Penetration Testing, Burp Suite, Cloud Computing, Cloud Computing Security, Cloud Engineering, Cyber Security, Continuous Integration, DevOps, Github, Identity and Access Management, Information Systems Security Architecture Professional, Python (Programming Language), Key Management, OAuth, OpenID, Open Web Application Security, PCI Data Security Standards, Role-Based Access Control, Openid Connect, Security Assertion Markup Language (SAML), Secure Coding, Software Engineering, SonarQube, Software Vulnerability Management, Policy as Code, Delivery Pipeline, Sonatype, Software Security, Veracode, AWS Lambda, Cloudformation, Containerization, Gitlab-ci, Kubernetes, Infrastructure Automation Frameworks, Information Technology, Checkmarx, Opsworks, Functional Programming, Api Gateway, Terraform, Prisma Cloud Platform, Devsecops, Serverless Computing, Docker, Jenkins, Static Application Security Testing, Vulnerability Analysis, Microservices, Dynamic Application Security Testing - **Published:** August 8, 2026 - **Apply:** https://www.dice.com/job-detail/6ffde439-35e1-4c06-8c83-54771a4d478f ## About the Role * 15+ years of experience in Application Security, Product Security, or DevSecOps, including 3+ years securing AWS-based applications. * Strong expertise in securing applications throughout the Secure Software Development Lifecycle (SSDLC). * Perform threat modeling and secure architecture reviews for applications, APIs, microservices, and cloud-native workloads. * Hands-on experience securing AWS services including EC2, ECS/EKS, Lambda, API Gateway, IAM, WAF, Shield, GuardDuty, Inspector, Security Hub, KMS, Secrets Manager, and CloudTrail. * Implement and manage security controls across CI/CD pipelines using SAST, DAST, SCA, container image scanning, and Infrastructure-as-Code (IaC) scanning. * Integrate security into GitHub Actions, GitLab CI, Jenkins, AWS CodePipeline, or similar CI/CD platforms. * Configure and enforce least-privilege IAM policies, role-based access control (RBAC), secrets management, and encryption standards. * Conduct secure code reviews and vulnerability assessments using OWASP Top 10, CWE, and secure coding best practices. * Experience with security tools such as SonarQube, Checkmarx, Veracode, Snyk, Prisma Cloud, Aqua Security, Burp Suite, and OWASP ZAP. * Secure containerized workloads using Docker, Kubernetes (EKS), ECS, and serverless applications using AWS Lambda. * Perform Infrastructure-as-Code (IaC) security using Terraform or CloudFormation with Checkov, tfsec, cfn-nag, or similar tools. * Develop automation scripts using Python, Go, or similar languages for security validation and compliance. * Strong understanding of API security, OAuth 2.0, OpenID Connect (OIDC), SAML, JWT, and authentication/authorization mechanisms. * Implement cloud security guardrails using AWS Organizations, Service Control Policies (SCPs), AWS Config, and policy-as-code frameworks such as OPA. * Coordinate penetration testing activities, validate findings, and drive remediation with development teams. * Support security audits and compliance initiatives including SOC 2, ISO 27001, PCI-DSS, HIPAA, and FedRAMP. * Respond to application security incidents, investigate threats, and develop detection rules and incident response runbooks. * Experience with Cloud Native Application Protection Platforms (CNAPP) such as Wiz, Prisma Cloud, or CrowdStrike Falcon Cloud. * Strong knowledge of threat modeling methodologies including STRIDE and PASTA. * Collaborate with development, DevOps, infrastructure, and client security teams to promote DevSecOps best practices. * Mentor engineering teams on secure coding, cloud security, and vulnerability remediation. * Excellent communication, analytical, troubleshooting, and stakeholder management skills. * AWS Certified Security - Specialty preferred; CSSLP, CISSP, or OSWE certifications are highly desirable. * Bachelor''s degree in Computer Science, Information Security, Cybersecurity, or a related field. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Docker build without Docker](https://www.wearedevelopers.com/videos/100114-docker-build-without-docker) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Security Basics for Vibe Coders](https://www.wearedevelopers.com/magazine/598-security-basics-for-vibe-coders) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)