> Markdown version of [/jobs/ext/2728181-senior-aws-cloud-security-engineer](https://www.wearedevelopers.com/jobs/ext/2728181-senior-aws-cloud-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior AWS Cloud Security Engineer - **Company:** ESS Direct Powered by Vertical - **Location:** New York, NY, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Amazon Web Services, Cloud Computing Security, Cloud Engineering, Continuous Integration, Github, Identity and Access Management, OpenID, Enterprise Data Management, Policy as Code, Amazon Virtual Private Cloud (VPC), Sentry, Cloudflare, Cloudwatch, Terraform - **Published:** September 5, 2026 - **Apply:** https://www.careerjet.com/jobad/us8c089f0237035fedc3fb2ac4113d37da ## About the Role * 8+ years of cloud engineering, cloud security, or infrastructure security experience. * Deep expertise in AWS security architecture and governance. * Demonstrated experience performing API-level threat modeling for AWS services. * Strong hands-on experience with: * Open Policy Agent (OPA) * Rego policy development * Policy testing and validation * Advanced knowledge of: * AWS IAM * AWS Organizations * SCPs and RCPs * Data perimeter architecture * Experience designing least-privilege access models in regulated environments. * Strong understanding of cloud security controls, compliance requirements, and enterprise governance frameworks. Preferred Qualifications * Experience with Kivera.io, Cloudflare One, or similar cloud API policy enforcement platforms. * Experience with Regal policy linting and OPA coverage reporting. * Infrastructure-as-Code expertise using Terraform. * CI/CD experience with: * GitHub Actions * OIDC federation * Policy validation pipelines * Approval-based deployment models * Experience with: * Checkov * Conftest * Policy Sentry * Cloudsplaining * Strong AWS observability experience using: * CloudWatch * CloudTrail * VPC Flow Logs * Amazon EKS security and governance experience. * Experience working directly with AWS Support and Technical Account Managers. * Financial services, banking, capital markets, or other highly regulated industry experience. Technical Environment * AWS Organizations with SCP and RCP governance * Open Policy Agent (OPA) * Rego policy language * Kivera.io policy enforcement platform * Cloudflare One * Terraform * GitHub Actions * CloudWatch * CloudTrail * VPC Flow Logs * Amazon EKS * Enterprise Data Perimeter Architecture ## Description Vertical Relevance is seeking a Senior AWS Cloud Security Consultant to help design remotely and enforce enterprise cloud security controls within a highly regulated environment. This role sits at the intersection of cloud security architecture, policy engineering, and AWS governance, with a primary focus on preventing data exfiltration through policy-as-code, data perimeter controls, and proactive threat modeling. You will evaluate AWS services before they are introduced into production environments, identify potential security risks at the API and configuration level, and implement preventive controls using AWS Organizations policies, IAM guardrails, and Rego-based policy frameworks. This is an opportunity to work on complex cloud security challenges supporting critical business platforms where security, compliance, and operational rigor are non-negotiable., Be an integral part of an agile team that's constantly pushing the envelope to enhance, build, and deliver top-notch technology products. As a Senior Lead Software Engineer at JP… + 13 hours ago + ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [From Doubt to Confidence: How Sentry Uses Verdaccio to Bulletproof SDK Releases](https://www.wearedevelopers.com/videos/739-from-doubt-to-confidence-how-sentry-uses-verdaccio-to-bulletproof-sdk-releases) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [OPA for the cloud natives](https://www.wearedevelopers.com/videos/713-opa-for-the-cloud-natives) - [CI/CD with Github Actions](https://www.wearedevelopers.com/videos/856-ci-cd-with-github-actions) - [30 powerful AWS hacks in just 30 minutes: Boost your developer productivity](https://www.wearedevelopers.com/videos/1624-30-powerful-aws-hacks-in-just-30-minutes-boost-your-developer-productivity) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)