Senior Application and Cloud Security Engineer

Proactive Logic Consulting Inc
United States
about 1 month ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
1 year minimum
Compensation
$160,555.0 - $228,800.0
Working hours
Regular working hours
Job source

Tech stack

Application Programming Interfaces (APIs) Artificial Intelligence Amazon Web Services Cloud Computing Security Continuous Integration Data Infrastructure Cursor (Graphical User Interface Elements) Multi-Factor Authentication Identity and Access Management OAuth OpenID Role-Based Access Control
+8 more
Zero Trust Network Access Security Assertion Markup Language (SAML) Data Streaming Web Applications Data Logging Amazon Virtual Private Cloud (VPC) Static Application Security Testing Dynamic Application Security Testing

Job description

  • Review application and AWS architectures, identify priority risks, and produce clear remediation guidance.
  • Implement security guardrails, identity controls, cloud configuration improvements, and CI/CD checks.
  • Partner with engineers and stakeholders to balance risk reduction, delivery speed, operability, and cost.
  • Use AI coding agents to accelerate implementation while preserving evidence, testing, and accountability.

Requirements

We’re hiring a Senior Application and Cloud Security Engineer Consultant for a remote healthcare technology modernization program. This is a Corp-to-Corp 1099 engagement for a hands-on security engineer who can assess application and AWS architecture, design practical controls, and help engineering teams implement them.

This is an AI-forward delivery role. Daily use of coding agents such as Claude Code, OpenAI Codex, Cursor, or equivalent tools is required. You must retain human ownership of correctness, security, testing, and production readiness.

Key Requirements

  • 10+ years in application, cloud, platform, or product security.
  • Strong secure-design judgment across APIs, web applications, services, data flows, secrets, authentication, authorization, logging, and failure modes.
  • Hands-on AWS security experience with IAM, workload identities, VPC controls, KMS, Secrets Manager, CloudTrail, Config, GuardDuty, Security Hub, and related services.
  • Zero Trust and identity experience, including least privilege, OIDC/OAuth 2.0, SAML, MFA, RBAC or permission-based authorization, and privileged-access patterns.
  • Application-security testing and remediation experience using threat modeling, SAST, DAST, dependency scanning, container scanning, and CI/CD guardrails.
  • Ability to use AI coding agents to accelerate security work while protecting sensitive data and preserving human review.
  • Excellent client-facing communication, requirements discovery, and the ability to turn findings into prioritized implementation work.
  • Healthcare, pharmacy, HIPAA, PHI, or other regulated-data experience is preferred.
  • Must have an active LLC or S-Corp. This is 1099 Corp-to-Corp only; no W-2., * Application or cloud security: 10+ years (Required)
  • AWS security: 5+ years (Required)
  • Identity and Zero Trust: 3+ years (Required)
  • Consulting/client-facing delivery: 5+ years (Required)
  • Daily use of AI coding agents: 1+ years (Required)
  • Healthcare or regulated-data environments: Any (Preferred)

Benefits & conditions

Agencies: We are not engaging staffing agencies for this role.

Job Type: Contract

Compensation Package:

  • 1099 contract

About the company

Proactive Logic Consulting INC is a boutique technology consulting firm that delivers innovation, assessments and roadmaps, process automation and AI, cloud modernization, and application modernization.

We bring together senior independent consultants who combine deep technical judgment, high EQ, customer focus, and an entrepreneurial approach to delivery.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

1:10 min

Exposing sensitive information through partial search logs

Dennis Schulz Dennis Schulz +1 · World Congress 2026 Europe

1:34 min

Pivoting careers into specialized platform engineering roles

Xavier Portilla Edo · LIVE

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter · World Congress 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

Videos

See all

Related articles

See all