Lead AWS IAM Security Engineer

Remote in New York, NY, US • Posted 2 hours ago • Updated 2 hours ago
Full Time
On-site
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • Security Controls
  • Cloud Security
  • Identity Management
  • Cloud Computing
  • FIPS
  • PKI
  • TLS
  • Hierarchical Storage Management
  • Regulatory Compliance
  • Workflow
  • Payment Card Industry
  • Auditing
  • Management
  • Encryption
  • Software Security
  • Supply Chain Management
  • TypeScript
  • Amazon Web Services
  • PCA

Summary

We are looking for a specialized Cloud Security Engineer to secure our next-generation multi-region architecture. In this role, you will architect, implement, and automate robust security controls across AWS - spanning enterprise IAM, Public Key Infrastructure (PKI), secrets management, and cloud security posture management (CSPM) - while ensuring strict compliance for PCI-scoped fintech workloads. Req.# Responsibilities Identity & Access Management: Design and enforce secure AWS IAM policies, roles, permission boundaries, Service Control Policies (SCPs), and EKS Pod Identity / IRSA configurations Cloud Detection & Posture Management: Implement and manage security monitoring and posture tools including Amazon GuardDuty, AWS Security Hub, AWS CloudTrail, Macie, and IAM Access Analyzer PKI & Certificate Management: Build and manage automated certificate lifecycle workflows using AWS Private CA (FIPS 140-2 Level 3 HSM-backed), ACM, and mTLS trust stores, coordinating closely with the client's Security approvals Secrets & Encryption: Secure sensitive data using AWS KMS (including Multi-Region Keys), Secrets Manager, and the External Secrets Operator Requirements Baseline (Mandatory): Strong hands-on experience with AWS CDK and TypeScript for security-as-code automation AWS PKI & TLS: Deep expertise in AWS Private CA (HSM-backed), ACM, mTLS trust stores, automated certificate issuance/rotation/revocation, and PayPal Security compliance workflows Proficiency with Amazon GuardDuty, Security Hub (AWS FSBP, CIS, NIST benchmarks), Macie, and IAM Access Analyzer Experience supporting strict PCI-scoped fintech audits and CSPM frameworks Identity & Secrets Management: Advanced IAM expertise (roles, trust policies, permission boundaries, SCPs, IRSA/EKS Pod Identity), Secrets Manager, External Secrets Operator, and KMS/MRK envelope encryption Supply Chain & Application Security: SAST tools (SonarQube, CodeQL), Dependabot, and software supply chain security (image signing and provenance via Cosign/SLSA) integrated with CDK & TypeScript Nice to have Experience with Wiz (CSPM/CNAPP) Advanced deployments of AWS Private CA (PCA) and complex KMS key hierarchies
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 10330481
  • Position Id: e0c55f3e93959b78a5b9452e9b9e0c6c
  • Posted 2 hours ago
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

New York, New York

Today

Full-time

New York, New York

Today

Full-time

USD 220,000.00 - 300,000.00 per year

New York, New York

Today

Full-time

USD 210,000.00 - 234,100.00 per year

New York, New York

Today

Full-time

USD 226,000.00 - 300,000.00 per year

Search all similar jobs