AWS Cloud Security Engineer

Insight Global
Gates County, NC, United States
2 days ago
Apply on www.juju.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Kubernetes Security Amazon Web Services Audit Trail Automation of Tests Cloud Computing Cloud Computing Security Continuous Integration DDoS Mitigation Github Identity and Access Management Intrusion Detection and Prevention Python (Programming Language)
+17 more
Network Security OpenID Runbook Security Information and Event Management Data Logging Cloud-native Network Functions (CNF) Google Cloud Software Security Multi-Cloud Cloudformation Containerization Kubernetes Cloudflare Cloud Migration Vertica Terraform Splunk

Job description

We are seeking experienced Cloud Security Engineers to support the implementation of critical cloud security initiatives across AWS and Google Cloud Platform (GCP) environments. This role is highly hands-on and focused on building, deploying, automating, and operationalizing security controls across a large-scale multi-cloud ecosystem.

The ideal candidate has deep expertise in cloud-native security, identity and access management, infrastructure-as-code, Kubernetes security, logging and detection engineering, and cloud network security. This is an engineering-focused role requiring practitioners who can implement solutions, write code, automate controls, and partner closely with platform and application teams.

Responsibilities

Design, implement, and automate cloud security controls across AWS and GCP environments, with a focus on identity security, cloud infrastructure protection, and attack surface reduction.

Implement modern authentication and authorization solutions, including IAM, OIDC, workload identity federation, service accounts, and role-based access controls, while leading efforts to eliminate long-lived credentials and adopt short-lived identities.

Develop and enforce cloud security guardrails, data perimeter protections, default-deny access models, and security policies that reduce unauthorized access, lateral movement, and data exposure risks across multi-cloud environments.

Build infrastructure-as-code and automation solutions to support security deployment, credential management, compliance reporting, monitoring, and policy enforcement at scale.

Enable, integrate, and maintain cloud audit logging, monitoring, SIEM pipelines, security detections, and incident response capabilities across AWS, GCP, Kubernetes, GitHub, and related platforms.

Develop detections and automated response mechanisms for credential abuse, anomalous activity, unauthorized access attempts, and potential data exfiltration events.

Secure Kubernetes and containerized environments by implementing hardened configurations, secure deployment patterns, access controls, and cloud-native security best practices.

Design and implement security protections for internet-facing applications and infrastructure, including Cloudflare WAF, DDoS protection, secure ingress patterns, and private-by-default cloud architectures.

Identify, assess, and remediate security vulnerabilities, exposed cloud resources, insecure network paths, and application security risks through proactive testing, monitoring, and validation activities.

Partner closely with cloud, platform, infrastructure, and application engineering teams to implement security solutions, support cloud migrations, establish operational playbooks, and improve the overall security posture of large-scale cloud environments.

Requirements

5+ years of hands-on experience in AWS cloud security engineering

  • Deep expertise with AWS IAM (roles, policies, SCPs, permission boundaries, OIDC federation)

  • Experience implementing and managing AWS Organizations, SCPs, and resource control policies (RCPs)

  • Proficiency with AWS CloudTrail, GuardDuty, Security Hub, and Config for logging and monitoring

  • Hands-on experience with credential management, rotation, and migration to short-lived credentials

  • Strong infrastructure-as-code skills (Terraform, CloudFormation, or CDK)

  • Experience with network security controls (VPCs, security groups, NACLs, PrivateLink)

  • Familiarity with CI/CD pipeline security and preventive guardrails

  • Ability to write automation scripts (Python, Go, or similar)

  • Experience working in multi-account AWS environments at scale

  • Strong written and verbal communication skills; ability to produce operational playbooks and runbooks

  • Familiarity with EKS and container security - AWS Security Specialty or Solutions Architect Professional certification

  • Experience with AWS resource policies and cross-account access patterns

  • Hands-on experience migrating workloads from static credentials to OIDC/federation-based authentication

  • Familiarity with SIEM integration (Splunk, Sentinel, or similar) and detection engineering

  • Experience with GitHub Actions OIDC integration for AWS

  • Prior work in a staff augmentation or consulting engagement model

  • Experience in regulated or high-security environments (SOC 2, FedRAMP, or similar)

  • Familiarity with ClickHouse

  • Experience building reusable security patterns and frameworks for enterprise adoption

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.juju.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

6:51 min

Audience questions on cloud security and operational capacity

Steffen Heilmann · World Congress 2021

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · World Congress 2023

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

2:40 min

Using GitHub primitives for internal documentation and corporate operations

Kyle Daigle · Coffee With Developers

2:52 min

Implementing IAM with Keycloak and OpenID Connect

Thomas Südbröcker · LIVE

Videos

See all

Related articles

See all