AWS Application Security engineer

Remote • Posted 1 hour ago • Updated 1 hour ago
Contract Corp To Corp
Contract Independent
Contract W2
12 Months
No Travel Required
Remote
$65 - $70/hr
Company Branding Image
Fitment

Dice Job Match Score™

👤 Reviewing your profile...

Job Details

Skills

  • AWS
  • Security engineer

Summary

AWS Application Security Engineer
Role: Certified - Application Security Engineer (AWS) 
Level: Senior (8–12 years) 
Location: Remote 
 
Role Summary
We are seeking an experienced Application Security Engineer to secure applications built and operated on AWS. You will embed security across the SDLC — from secure design and code review through CI/CD integration, runtime protection, and incident response — working closely with development, DevOps, and client security teams.
 
Key Responsibilities
  • Perform threat modeling and secure design reviews for applications and microservices deployed on AWS (EC2, ECS/EKS, Lambda, API Gateway).
  • Integrate and operate security tooling in CI/CD pipelines: SAST, DAST, SCA/dependency scanning, container image scanning, and IaC scanning.
  • Configure and manage AWS-native security services: WAF, Shield, GuardDuty, Inspector, Security Hub, KMS, Secrets Manager, IAM.
  • Define and enforce least-privilege IAM policies, secrets management standards, and encryption (at rest/in transit) across workloads.
  • Conduct secure code reviews and vulnerability triage; partner with dev teams on remediation and secure coding practices (OWASP Top 10, CWE).
  • Harden infrastructure-as-code (Terraform/CloudFormation) using policy-as-code (OPA, Checkov) and guardrails (SCPs, Config rules).
  • Support penetration test coordination, findings remediation, and audit/compliance requirements (SOC 2, ISO 27001, PCI-DSS as applicable).
  • Respond to application-layer security incidents; contribute to detection rules and runbooks.
  • Mentor engineers and champion DevSecOps culture across delivery teams.
Required Skills & Experience
  • 8+ years in application security / product security, with 3+ years securing workloads on AWS.
  • Hands-on expertise with AWS security services: IAM, WAF, GuardDuty, Inspector, Security Hub, KMS, Secrets Manager, CloudTrail.
  • Strong knowledge of OWASP Top 10, API security, authentication/authorization patterns (OAuth 2.0, OIDC, SAML).
  • Experience with security tooling: SonarQube/Checkmarx/Veracode (SAST), Snyk/Prisma/Aqua (SCA & containers), Burp Suite/OWASP ZAP (DAST).
  • Proficiency in at least one language for automation — Python, Go, or similar; ability to read Java/Node.js/.NET application code.
  • Experience securing containerized (Docker, EKS/ECS) and serverless (Lambda) architectures.
  • IaC security: Terraform or CloudFormation with Checkov/tfsec/cfn-nag.
  • CI/CD security integration: GitHub Actions, GitLab CI, Jenkins, or AWS CodePipeline.
  • Certifications: AWS Certified Security – Specialty (strongly preferred); CSSLP, OSWE, or CISSP.
Preferred Qualifications
  • Experience with CNAPP platforms (Wiz, Prisma Cloud, CrowdStrike Falcon Cloud).
  • Threat modeling frameworks (STRIDE, PASTA) and secure SDLC program experience.
  • Prior work in a client-facing or consulting/delivery environment with enterprise customers.
  • Exposure to compliance frameworks: SOC 2, ISO 27001, PCI-DSS, HIPAA, FedRAMP.
Soft Skills
  • Strong communication — able to explain risk and remediation to both engineers and business stakeholders.
  • Pragmatic, risk-based mindset; balances security rigor with delivery velocity.
  • Self-driven; comfortable operating in ambiguous, fast-moving programs.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 91133294
  • Position Id: 19628-10625-1786387313
  • Posted 1 hour ago

Company Info

About IMR Soft LLC

We're building a great company, and we're very excited about the future of the company.

IMR Soft. is one of the fastest-growing, USA based Information Technology company specializing in software development and IT Services. Founded in 2017, by a team of experienced professionals with a solid base in IT and Management. Headquartered in Princeton, New Jersey.

We help clients Create the Future. We deliver innovative information technology solutions and unlimited services that benefit our clients by maximizing their performance. We combine tech expertise and business intelligence to catalyze change and deliver results. In a world that is constantly changing, companies are faced with the challenge of continually adapting to a dynamic environment.

Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

It looks like there aren't any Similar Jobs for this job yet.

Search all similar jobs