AWS Security Engineer Contract

With Intelligence
Greater London, UK
1 day ago
Apply on www.collegerecruiter.com
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Java (Programming Language) Amazon Web Services Bash Shell Cloud Computing Security Continuous Integration Data as a Services Identity and Access Management Information Security Management Intrusion Detection and Prevention Python (Programming Language) Node.Js Systems Development Life Cycle
+21 more
Role-Based Access Control Secure Coding Security Information and Event Management Software Engineering Tripwire Software Vulnerability Management Policy as Code Data Logging Scripting Delivery Pipeline Core Api Amazon Virtual Private Cloud (VPC) Cloudformation Tenable Nessus Apache Kafka Data Management Cloudwatch Terraform Devsecops Serverless Computing Qualys

Job description

AWS Security & Vulnerability Remediation Engineer (DevSecOps / Cloud Security)

3 month initial contract outside IR35

Role Summary

We are looking to hire an AWS-focused security engineer to lead the remediation of cloud and application vulnerabilities across our AWS environment. You will work closely with Developers, Data Engineers, and our AWS Security Lead to validate findings, prioritise risk, implement fixes, and strengthen security controls. AWS security is your primary technical skill; a strong understanding of software development, DevSecOps practices, and vulnerability management is essential.

Key Responsibilities

  • Own end-to-end remediation of AWS and workload vulnerabilities: confirm findings, assess impact, prioritise actions, and track through to closure
  • Partner with Developers and Data Engineers to implement secure fixes in code, infrastructure, and delivery pipelines (IaC, containers, serverless, OS/packages)
  • Work with the AWS Security Lead to ensure remediation aligns with AWS security controls, internal risk policies, and compliance requirements
  • Improve and automate vulnerability management processes (e.g., scanning coverage, SLAs, exception handling, evidence capture)
  • Embed security into CI/CD and the SDLC: shift-left reviews, secure coding guidance, dependency management, and pipeline guardrails
  • Configure, tune, and operate AWS security services (e.g., GuardDuty, Security Hub, Inspector, Config, IAM Access Analyzer) to reduce exposure and prevent repeat issues
  • Produce clear remediation guidance, runbooks, and reporting dashboards for both technical and non-technical stakeholders
  • Support incident response and post-remediation validation where high-risk findings are exploited or trending

Requirements

AWS / Cloud Security (Primary)

  • Deep, hands-on AWS security experience across IAM, networking, compute, storage, serverless, and managed data services
  • Strong knowledge of the AWS Well-Architected Security Pillar and common control frameworks (CIS AWS Foundations, NIST/ISO-aligned controls)
  • Demonstrable experience implementing and validating AWS security controls, including:
  • IAM least privilege, roles, permission boundaries, SCPs, and access reviews
  • VPC segmentation, security group/NACL design, private endpoints, WAF/Shield
  • Encryption in transit and at rest using KMS, TLS, and secrets management
  • Logging and monitoring: CloudTrail, CloudWatch, Config, centralised SIEM patterns
  • Threat detection and posture management using AWS native services

Dev / DevSecOps / Vulnerability Management (Primary)

  • Strong understanding of modern SDLC, CI/CD, and DevSecOps approaches
  • Proven experience managing the full vulnerability lifecycle: triage, prioritisation (CVSS/EPSS/KEV), remediation, verification, and reporting
  • Comfortable remediating a wide range of findings: OS/package CVEs, container images, third-party libraries, serverless runtimes, and cloud misconfigurations
  • Able to translate security findings into clear, practical tasks for engineering teams and coach on secure implementation

Engineering & Tooling

  • Infrastructure as Code: Terraform and/or CloudFormation; able to review and fix security weaknesses in IaC
  • Scripting/automation skills in Python, Bash, or similar to streamline remediation and control validation
  • Familiarity with container and serverless security (ECR, ECS/EKS, Lambda, image scanning, runtime hardening)
  • Experience with common vulnerability and scanning tools (e.g., AWS Inspector/Security Hub, Snyk, Trivy, Dependabot, Prisma/Qualys/Tenable, etc.)

Nice to Have

  • Security certifications such as AWS Security Specialty, AWS Solutions Architect, or equivalent
  • Experience supporting data platforms on AWS (Glue, EMR, Redshift, Athena, RDS, OpenSearch, Kafka/MSK)
  • Knowledge of secure coding practices in Python/Node/Java or your core development stack
  • Experience with policy-as-code and automated control enforcement (OPA/Conftest, tfsec, Checkov)

Personal Attributes

  • Highly collaborative and pragmatic; you enjoy working directly with engineers to ship secure fixes quickly
  • Strong risk judgement and the ability to balance urgency with operational impact
  • Clear communicator who can write concise remediation guidance and present progress to stakeholders
  • Ownership mindset: you drive remediation through to completion, not just identification

Benefits

Outside IR35

Requirements

  • Deep, hands-on AWS security experience across IAM, networking, compute, storage, serverless, and managed data services
  • Strong knowledge of the AWS Well-Architected Security Pillar and common control frameworks (CIS AWS Foundations, NIST/ISO-aligned controls)
  • Demonstrable experience implementing and validating AWS security controls, including:
  • IAM least privilege, roles, permission boundaries, SCPs, and access reviews
  • VPC segmentation, security group/NACL design, private endpoints, WAF/Shield
  • Encryption in transit and at rest using KMS, TLS, and secrets management
  • Logging and monitoring: CloudTrail, CloudWatch, Config, centralised SIEM patterns
  • Threat detection and posture management using AWS native services

Dev / DevSecOps / Vulnerability Management (Primary)

  • Strong understanding of modern SDLC, CI/CD, and DevSecOps approaches
  • Proven experience managing the full vulnerability lifecycle: triage, prioritisation (CVSS/EPSS/KEV), remediation, verification, and reporting
  • Comfortable remediating a wide range of findings: OS/package CVEs, container images, third-party libraries, serverless runtimes, and cloud misconfigurations
  • Able to translate security findings into clear, practical tasks for engineering teams and coach on secure implementation

Engineering & Tooling

  • Infrastructure as Code: Terraform and/or CloudFormation; able to review and fix security weaknesses in IaC
  • Scripting/automation skills in Python, Bash, or similar to streamline remediation and control validation
  • Familiarity with container and serverless security (ECR, ECS/EKS, Lambda, image scanning, runtime hardening)
  • Experience with common vulnerability and scanning tools (e.g., AWS Inspector/Security Hub, Snyk, Trivy, Dependabot, Prisma/Qualys/Tenable, etc.), * Security certifications such as AWS Security Specialty, AWS Solutions Architect, or equivalent
  • Experience supporting data platforms on AWS (Glue, EMR, Redshift, Athena, RDS, OpenSearch, Kafka/MSK)
  • Knowledge of secure coding practices in Python/Node/Java or your core development stack
  • Experience with policy-as-code and automated control enforcement (OPA/Conftest, tfsec, Checkov), * Highly collaborative and pragmatic; you enjoy working directly with engineers to ship secure fixes quickly
  • Strong risk judgement and the ability to balance urgency with operational impact
  • Clear communicator who can write concise remediation guidance and present progress to stakeholders
  • Ownership mindset: you drive remediation through to completion, not just identification

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.collegerecruiter.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

7:44 min

Bootstrapping a test-driven asp.net web api

Alex Banul · LIVE

45 sec

Working securely with Node.js path application programming interfaces

Sonya Moisset · World Congress 2023

1:24 min

Evaluating formal AWS certifications versus raw practical engineering experience

Jan Giacomelli · LIVE

2:42 min

Core API types for Angular signals

Daniela Bonvini · LIVE

3:55 min

Identifying underlying Node.js runtime vulnerabilities using fuzzing tools

Sonya Moisset · World Congress 2023

4:23 min

Reviewing AWS infrastructure deployment configuration and planning

Devlin Duldulao · LIVE

Videos

See all

Related articles

See all