Job Description
Responsibilities
- Implement AWS multi-account security baselines, including CloudTrail, GuardDuty, Security Hub, AWS Config, SCP, account onboarding, and baseline drift detection.
- Support IAM/PAM, JumpServer, Archery, break-glass access, SSH key, production access, and database access governance.
- Implement KMS, Secrets Manager, access key, token, certificate, and key rotation controls.
- Govern Security Groups, NACLs, VPC segmentation, public exposure, egress control, and network drift.
- Implement Jenkins, ArgoCD, Bitbucket, SAST, SCA, IaC scanning, secrets scanning, SBOM, and pipeline security gates.
- Use Terraform, Python, CI/CD, scripting, or security tools to automate detection, remediation guidance, and dashboards.
- Use AI to generate scripts, analyze configuration risks, review IAM policies, review Terraform / CI/CD configurations, produce remediation recommendations, summarize baseline gaps, and prepare risk summaries.
- Integrate AI into daily DevSecOps workflows, such as AI-assisted IaC Review, AI-assisted IAM Review, and AI-assisted CI/CD Security Review.
- Partner with DevOps, Infrastructure, R&D, and DBA teams to drive remediation and process improvement.
- Support incident recovery through credential cleanup, account hardening, network exposure reduction, CI/CD hardening, and control restoration.
- Work with SOC, Red Team, and GRC to ensure controls can be monitored, validated, and reviewed.
Requirements
- 6+ years of experience in DevSecOps, cloud security, security engineering, platform security, or application security.
- Familiarity with AWS security capabilities including IAM, VPC, KMS, CloudTrail, GuardDuty, Security Hub, and Security Groups.
- Strong experience in at least two of the following areas: IAM/PAM, KMS/Secrets, cloud network security, CI/CD security, container security, or database access governance.
- Hands-on experience with Terraform / IaC, Python / Shell, CI/CD pipelines, or security automation.
- Good understanding of least privilege, credential lifecycle, production access auditing, security baselines, and security gates.
- Strong AI capability, with the ability to improve security engineering efficiency using AI and validate AI-generated scripts, policies, configuration analysis, and remediation recommendations.
- Understanding of sensitive information protection when using AI, avoiding the use of non-compliant AI tools for secrets, production data, customer information, or unmasked logs.
- Ability to work with DevOps, R&D, Infrastructure, and DBA teams to drive remediation.
- Strong analytical, documentation, and execution skills.
Are you interested in this position?
Apply by clicking on the “Apply Now” button below!
#GraphicDesignJobsOnline
#WebDesignRemoteJobs
#FreelanceGraphicDesigner
#WorkFromHomeDesignJobs
#OnlineWebDesignWork
#RemoteDesignOpportunities
#HireGraphicDesigners
#DigitalDesignCareers
# Dynamicbrand guru