Lead AWS IAM Security Engineer

EPAM Systems, Inc.
Chicago, IL, United States
9 days ago
Apply on www.chicagocareersite.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Compensation
$150,000.0 - $160,000.0
Working hours
Regular working hours

Tech stack

Amazon Web Services Cloud Computing Cloud Computing Security Federal Information Processing Standards (FIPS) Identity and Access Management Information Security Management Key Management Public Key Infrastructure SonarQube TypeScript Workflow Management Systems Automatic Programming
+3 more
SSL Certificate Management Software Security Static Application Security Testing

Job description

  • Identity & Access Management: Design and enforce secure AWS IAM policies, roles, permission boundaries, Service Control Policies (SCPs), and EKS Pod Identity / IRSA configurations
  • Cloud Detection & Posture Management: Implement and manage security monitoring and posture tools including Amazon GuardDuty, AWS Security Hub, AWS CloudTrail, Macie, and IAM Access Analyzer
  • PKI & Certificate Management: Build and manage automated certificate lifecycle workflows using AWS Private CA (FIPS 140-2 Level 3 HSM-backed), ACM, and mTLS trust stores, coordinating closely with the client’s Security approvals
  • Secrets & Encryption: Secure sensitive data using AWS KMS (including Multi-Region Keys), Secrets Manager, and the External Secrets Operator

Requirements

  • Baseline (Mandatory): Strong hands-on experience with AWS CDK and TypeScript for security-as-code automation
  • AWS PKI & TLS: Deep expertise in AWS Private CA (HSM-backed), ACM, mTLS trust stores, automated certificate issuance/rotation/revocation, and PayPal Security compliance workflows
  • Proficiency with Amazon GuardDuty, Security Hub (AWS FSBP, CIS, NIST benchmarks), Macie, and IAM Access Analyzer
  • Experience supporting strict PCI-scoped fintech audits and CSPM frameworks
  • Identity & Secrets Management: Advanced IAM expertise (roles, trust policies, permission boundaries, SCPs, IRSA/EKS Pod Identity), Secrets Manager, External Secrets Operator, and KMS/MRK envelope encryption
  • Supply Chain & Application Security: SAST tools (SonarQube, CodeQL), Dependabot, and software supply chain security (image signing and provenance via Cosign/SLSA) integrated with CDK & TypeScript

Nice to have

  • Experience with Wiz (CSPM/CNAPP)
  • Advanced deployments of AWS Private CA (PCA) and complex KMS key hierarchies

Benefits & conditions

  • Medical, Dental and Vision Insurance (Subsidized)
  • Health Savings Account
  • Flexible Spending Accounts (Healthcare, Dependent Care, Commuter)
  • Short-Term and Long-Term Disability (Company Provided)
  • Life and AD&D Insurance (Company Provided)
  • Employee Assistance Program
  • Unlimited access to LinkedIn learning solutions
  • Matched 401(k) Retirement Savings Plan
  • Paid Time Off - the employee will be eligible to accrue 15-25 paid days, depending on specific level and tenure with EPAM (accrual eligibility may change over time)
  • Paid Holidays - nine (9) total per year
  • Legal Plan and Identity Theft Protection
  • Accident Insurance
  • Employee Discounts
  • Pet Insurance
  • Employee Stock Purchase Program
  • If otherwise eligible, participation in the discretionary annual bonus program
  • If otherwise eligible and hired into a qualifying level, participation in the discretionary Long-Term Incentive (LTI) Program

This Remote Position Cannot be Performed in New York City.

This posting includes a good faith range of the salary EPAM would reasonably expect to pay the selected candidate. The range provided reflects base salary only. Individual compensation offers within the range are based on a variety of factors, including, but not limited to: geographic location, experience, credentials, education, training; the demand for the role; and overall business and labor market considerations. Most candidates are hired at a salary within the range disclosed. Salary range: $150,000 - $160,000. In addition, the details highlighted in this job posting above are a general description of all other expected benefits and compensation for the position.

In accordance with the LA County Fair Chance Ordinance, you may find a copy of the Notice containing a summary of the Ordinance’s key provisions here: Concept FCO Posting 8 27 24 (lacounty.gov)

About the company

EPAM Systems, Inc. is an equal opportunity employer. We recognize the value of diversity and inclusion in creating success for our customers, business partners, shareholders, employees and communities. We are committed to recruiting, hiring, developing and promoting employees without discrimination. As a global employer, this commitment includes complying with all laws in the countries in which we operate. Nevertheless, we believe equal employment practices should not be limited to what the law requires. Equal opportunity and inclusion are essential to motivate, empower and recognize the best in everyone.

At EPAM, employment actions are based on individual qualifications, without regard to race, color, religion, creed, gender, pregnancy status, sexual orientation, gender identity, gender expression, marital or familial status, national origin, ancestry, genetics, age, disability status, veteran status, citizenship status when otherwise legally able to work, or any other characteristic protected by law.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.chicagocareersite.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:23 min

Building and installing the compiled custom rule extension

Daniel Strmečki +1 · World Congress 2022

1:00 min

Misconceptions about TypeScript safety capabilities

Simone Sanfratello · JS Congress

1:41 min

Protecting etcd databases using Key Management System plugins

Alex Soto Alex Soto · LIVE

8:12 min

Lambda compatibility, interface security, and career advice

Alexander Günsche Alexander Günsche · LIVE

3:46 min

Adding metadata and documentation to new custom rules

Daniel Strmečki +1 · World Congress 2022

1:24 min

Evaluating formal AWS certifications versus raw practical engineering experience

Jan Giacomelli · LIVE

Videos

See all

Related articles

See all