> Markdown version of [/jobs/ext/2864633-sr-infrastructure-cloud-security-engineer-aws-remote](https://www.wearedevelopers.com/jobs/ext/2864633-sr-infrastructure-cloud-security-engineer-aws-remote). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr Infrastructure Cloud Security Engineer - AWS - Remote - **Company:** American Mortgage Consultants, Inc. - **Location:** Saint Paul, MN, United States - **Experience:** Expert - **Salary:** $135,000.0 - $180,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Amazon Web Services, Proxy Servers, Bash Shell, Cloud Computing, Cloud Computing Security, Cloud Engineering, Cyber Security, Computer Networks, Continuous Integration, Data Auditing, Linux, DevOps, Domain Name System (DNS), Identity and Access Management, Subnetting, Information Systems Security Architecture Professional, Python (Programming Language), Key Management, Network Security, Routing, Network Segmentation, Windows PowerShell, Reliability Engineering, Software Engineering, TCP/IP, Data Logging, Scripting, Transport Layer Security, Load Balancing, Cloud Platform System, Delivery Pipeline, Firewalls (Computer Science), Amazon Virtual Private Cloud (VPC), Git, Cloudformation, Containerization, Kubernetes, Infrastructure Automation Frameworks, Terraform, Devsecops, Serverless Computing, Docker - **Published:** September 12, 2026 - **Apply:** https://dejobs.org/x/x/D55F99A17050439BAE22AEC8D3007119/job/ ## About the Role * Bachelor's degree in a technical field from an accredited college/university, or equivalent job experience. * Minimum of 8+ years of industry and/or relevant experience, typically with 2+ years in an AVP level role or external equivalent. * At least 7+ years of direct relevant work experience in cloud security engineering, application/product security or a similar role * At least 5+ years of experience in cloud engineering, infrastructure engineering, security engineering,DevSecOps, SRE, or related technical disciplines. * Relevant certifications such as CISSP, CEH, GIAC, ISSAP, CISM or other relevant security-focused certifications preferred * Significant hands-on experience securing production AWS environments including: Strong understanding of AWS IAM, including policies, roles, trust policies, permission boundaries, federation, cross-account access, and least-privilege design; Strong knowledge of AWS networking, including VPCs, subnets, routing, security groups, network ACLs, VPC endpoints, load balancers, DNS, and private connectivity. * Experience securing Kubernetes and containerized environments, including EKS or comparable managed Kubernetes platforms. * Hands-on experience with AWS security services such as CloudTrail, Config, GuardDuty, Security Hub, Inspector, IAM Access Analyzer, KMS, and Secrets Manager. * Experience implementing infrastructure using Terraform, CloudFormation, or comparable Infrastructure-as-Code technologies. * Experience with Git-based development and CI/CD workflows. * Strong understanding of networking concepts, including TCP/IP, DNS, TLS, routing, firewalls, proxies, and network segmentation. * Working knowledge of Linux and common infrastructure technologies. * Highly motivated self-starter that can manage multiple deliverables independently in a fast-paced environment * Ability to develop automation using Python, PowerShell, Bash, or similar scripting languages. * Understanding of common cloud attack techniques, identity-based attacks, privilege escalation, credential compromise, and infrastructure security vulnerabilities. * Demonstrated ability to independently troubleshoot complex technical security and infrastructure problems. * Strong written and verbal communication skills with the ability to communicate effectively with security professionals, engineers, architects, and technology leadership. * Highly motivated self-starter that can manage multiple deliverables independently in a fast-paced environment * Broad knowledge across the security, insider threat, risk management and compliance domains. * Proficiency in scripting and automation (e.g., Python, PowerShell, Terraform) * Familiarity with container security technologies (Docker, Kubernetes). * Have familiarity with infrastructure as code (IaC) tooling * Knowledge of encryption and key management practices. * Excellent risk based problem-solving, analytical, and communication skills. * Ability to work independently and as part of a team. ## Description The Senior Cloud & Infrastructure Security Engineer is a senior technical member of the Information Security organization responsible for designing, implementing, and maintaining security controls across cloud and infrastructure environments. This is a hands-on engineering role that works closely with Site Reliability Engineering (SRE), Platform Engineering, Infrastructure, DevOps, and application development teams to ensure security is engineered into cloud platforms and infrastructure from the outset. The objective is to make secure configurations the default, allowing engineering teams to move quickly while maintaining appropriate security controls. The successful candidate will combine deep cloud and infrastructure expertise with strong security engineering skills. This individual will have the technical capability and authority to implement security controls directly, including AWS IAM policies and roles, VPC and network security controls, cloud security guardrails, logging and monitoring, encryption controls, and Infrastructure-as-Code (IaC). Essentials Job Functions: Cloud Security Engineering * Design and maintain AWS security controls across IAM, VPC, encryption, monitoring, and cloud-native services. * Apply least-privilege access, secure networking, encryption, logging, and monitoring standards. * Support secure adoption of AWS services by translating cloud risks into technical safeguards. Infrastructure & Platform Security * Partner with SRE, Platform, Infrastructure, DevOps, and development teams to secure enterprise platforms and cloud infrastructure. * Define secure baselines, hardening standards, reusable guardrails, and preventative controls for infrastructure technologies. * Review infrastructure designs to identify security gaps and recommend scalable remediation. Infrastructure-as-Code & DevSecOps * Build and maintain security controls through Infrastructure-as-Code using Terraform, CloudFormation, reusable modules, and templates. * Integrate automated policy, configuration, vulnerability, and compliance checks into CI/CD pipelines. * Embed security testing and guardrails into deployment workflows to reduce manual review. Cloud Security Monitoring & Respons e * Centralize and protect cloud security telemetry for monitoring, detection, and incident response. * Partner with Security Operations to investigate incidents and build automated detection and remediation capabilities. * Use logs, alerts, and findings to improve detection coverage and response readiness. Security Architecture & Risk Management * Conduct security architecture reviews and translate risk requirements into practical technical controls. * Communicate cloud and infrastructure risks, business impact, and remediation options to stakeholders. * Develop reference architectures, security patterns, technical standards, and engineering guidance. * Other tasks as assigned by manager ## Related Videos - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Turning Container security up to 11 with Capabilities](https://www.wearedevelopers.com/videos/718-turning-container-security-up-to-11-with-capabilities) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)