Cloud Security Engineer

Damco Inc
United States
4 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services Cloud Computing Security Cyber Security Data Control Identity and Access Management Key Management Role-Based Access Control Data Logging Cloud Platform System Amazon Virtual Private Cloud (VPC) Information Technology Deployment Automation
+1 more
Terraform

Job description

The hands-on cloud security engineer responsible for implementing enterprise AWS security guardrails through

Infrastructure as Code. Authors SCP and RCP policies using Terraform, deploys controls through Control Tower

Account Factory for Terraform (AFT), validates controls in sandbox environments, and supports phased rollout across

organizational units. Designs VPC endpoint and resource-based policies, documents blast-radius impacts, and enables, Author and maintain SCP and RCP policy rule sets using Terraform as the primary delivery mechanism.

Implement security controls through AWS Control Tower Account Factory for Terraform (AFT) pipelines.

Execute validation and testing in sandbox environments and document blast-radius findings before production rollout.

Deploy controls through phased implementation from Sandbox OU to NCZ, DPZ, and Critical Zones.

Design and implement VPC endpoint policies for secure service connectivity.

Build resource-based policies for critical services including logging buckets and AWS KMS keys.

Apply IAM Access Analyzer and AWS Organizations governance capabilities to strengthen least-privilege controls.

Create deployment procedures, operational runbooks, validation evidence, and administration documentation.

Conduct knowledge transfer and operational enablement sessions for the OCC PET team.

Collaborate with cloud security architects and platform teams to translate security policies into deployable AWS controls., IAM governance, least privilege design, policy validation, access reviews, and analyzer

capabilities.

VPC Endpoint Policies Implementation of endpoint access controls and private-service connectivity restrictions.

Resource-Based Policies Controls for logging buckets, KMS keys, and critical cloud resources.

Encryption & KMS

Key management, encryption governance, secure access patterns, and protected-data

controls.

Testing & Quality Assurance Sandbox validation, blast-radius assessment, rollout verification, and compliance evidence.

Security Compliance Security, risk, compliance, governance frameworks, and regulated AWS environment controls.

Requirements

Experience: 8+ years , Specialization: Security, Risk & Compliance, Terraform / IaC

Advanced Terraform development, reusable modules, version-controlled delivery, automated

deployments, and governance controls.

AWS Organizations

Multi-account governance, organizational units, SCP deployment, inheritance models, and

policy rollouts.

Control Tower AFT

Hands-on experience with Account Factory for Terraform, landing zones, and

automation-driven policy deployment.

SCP/RCP Design

Policy authoring, testing, validation, impact analysis, deployment planning, and lifecycle, Experience - 8+ years in cloud security, AWS governance, Infrastructure as Code, or cloud platform security engineering.

Certification - AWS Certified Security - Specialty preferred.

Core technical requirement - Hands-on Terraform, AWS Organizations, SCPs, IAM Access Analyzer, and VPC endpoint

policy implementation.

Preferred - Control Tower Account Factory for Terraform (AFT) experience.

Delivery capability - Experience testing policies, documenting blast radius, and executing phased enterprise

deployments.

Education - bachelor’s degree in computer science, Cybersecurity, Engineering, or equivalent practical experience.

About the company

My name is Sreeja and I represent TestingXperts Inc. TestingXperts is a Specialist QA & Software Testing Company, and an Independent Software Testing division of Damco Group, which is a leading IT Solutions and Services company working with Fortune Enterprises globally. Inheriting the virtues of job quality and optimal user satisfaction from Damco Group, TestingXperts aims at promoting the ethics of connected innovation, thereby seeding the integral values in our employees and achieving unmatched contentment in our clients. To know more about Testingxperts Inc., please visit our website .

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:46 min

Choosing between AWS CDK and Terraform

Alexander Bubeck · World Congress 2023

1:58 min

Uncovering team dynamics through version control data analysis

Adam Tornhill · Coffee With Developers

1:34 min

Essential commands for running and testing Terraform configurations

Hennie Francis · LIVE

1:10 min

Exposing sensitive information through partial search logs

Dennis Schulz Dennis Schulz +1 · World Congress 2026 Europe

2:32 min

Overview of Terraform and Terraform Cloud features

Devlin Duldulao · LIVE

1:51 min

Evaluating cloud ecosystem dominance and securing Terraform state backends

Thomas Hartenstein · LIVE

Videos

See all

Related articles

See all