> Markdown version of [/jobs/ext/2719364-cloud-security-engineer](https://www.wearedevelopers.com/jobs/ext/2719364-cloud-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cloud Security Engineer - **Company:** Damco Inc - **Location:** United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Cloud Computing Security, Cyber Security, Data Control, Identity and Access Management, Key Management, Role-Based Access Control, Data Logging, Cloud Platform System, Amazon Virtual Private Cloud (VPC), Information Technology, Deployment Automation, Terraform - **Published:** September 4, 2026 - **Apply:** https://www.dice.com/job-detail/556d5696-418b-4bf9-a811-63f734442152 ## About the Role Experience: 8+ years , Specialization: Security, Risk & Compliance, Terraform / IaC Advanced Terraform development, reusable modules, version-controlled delivery, automated deployments, and governance controls. AWS Organizations Multi-account governance, organizational units, SCP deployment, inheritance models, and policy rollouts. Control Tower AFT Hands-on experience with Account Factory for Terraform, landing zones, and automation-driven policy deployment. SCP/RCP Design Policy authoring, testing, validation, impact analysis, deployment planning, and lifecycle, Experience - 8+ years in cloud security, AWS governance, Infrastructure as Code, or cloud platform security engineering. Certification - AWS Certified Security - Specialty preferred. Core technical requirement - Hands-on Terraform, AWS Organizations, SCPs, IAM Access Analyzer, and VPC endpoint policy implementation. Preferred - Control Tower Account Factory for Terraform (AFT) experience. Delivery capability - Experience testing policies, documenting blast radius, and executing phased enterprise deployments. Education - bachelor's degree in computer science, Cybersecurity, Engineering, or equivalent practical experience. ## Description The hands-on cloud security engineer responsible for implementing enterprise AWS security guardrails through Infrastructure as Code. Authors SCP and RCP policies using Terraform, deploys controls through Control Tower Account Factory for Terraform (AFT), validates controls in sandbox environments, and supports phased rollout across organizational units. Designs VPC endpoint and resource-based policies, documents blast-radius impacts, and enables, Author and maintain SCP and RCP policy rule sets using Terraform as the primary delivery mechanism. Implement security controls through AWS Control Tower Account Factory for Terraform (AFT) pipelines. Execute validation and testing in sandbox environments and document blast-radius findings before production rollout. Deploy controls through phased implementation from Sandbox OU to NCZ, DPZ, and Critical Zones. Design and implement VPC endpoint policies for secure service connectivity. Build resource-based policies for critical services including logging buckets and AWS KMS keys. Apply IAM Access Analyzer and AWS Organizations governance capabilities to strengthen least-privilege controls. Create deployment procedures, operational runbooks, validation evidence, and administration documentation. Conduct knowledge transfer and operational enablement sessions for the OCC PET team. Collaborate with cloud security architects and platform teams to translate security policies into deployable AWS controls., IAM governance, least privilege design, policy validation, access reviews, and analyzer capabilities. VPC Endpoint Policies Implementation of endpoint access controls and private-service connectivity restrictions. Resource-Based Policies Controls for logging buckets, KMS keys, and critical cloud resources. Encryption & KMS Key management, encryption governance, secure access patterns, and protected-data controls. Testing & Quality Assurance Sandbox validation, blast-radius assessment, rollout verification, and compliance evidence. Security Compliance Security, risk, compliance, governance frameworks, and regulated AWS environment controls. ## Related Videos - [Terraform for Developers](https://www.wearedevelopers.com/videos/3-terraform-for-developers) - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Your Code as a Crime Scene](https://www.wearedevelopers.com/videos/1342-your-code-as-a-crime-scene) - [Implementing Feature Environments with AWS and Terraform](https://www.wearedevelopers.com/videos/531-implementing-feature-environments-with-aws-and-terraform) - [Building Applications with Infrastructure as Code](https://www.wearedevelopers.com/videos/887-building-applications-with-infrastructure-as-code) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Best Coding Boot Camps in Germany](https://www.wearedevelopers.com/magazine/237-best-coding-boot-camps-in-germany)