AWS Security Architecture engineer

Manor, TX, US • Posted 1 day ago • Updated 1 day ago
Contract Corp To Corp
Contract W2
Contract Independent
12 Months
No Travel Required
On-site
Depends on Experience
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • Amazon Web Services
  • Amazon EKS
  • Amazon RDS
  • Amazon Route 53
  • Amazon S3
  • DNSSEC
  • IBM WebSphere MQ
  • Kubernetes
  • Mergers and Acquisitions
  • Disaster Recovery
  • Computer Networking
  • Encryption
  • Embedded Systems
  • Incident Management
  • Inventory
  • Change Control
  • Amazon ECR
  • Migration
  • Integration Architecture
  • OIDC
  • Information Security Governance
  • DRS
  • Cloud Computing
  • Amazon VPC

Summary

Job Role: AWS Security Architecture engineer

Location:  Boston, MA, Arlington, VA, Atlanta, GA,:Austin, TX, Chicago, IL, Cleveland, OH:

Experience: 10 years

Skills:

Lead security architecture design and threat modeling for FICC (Fixed Income, Currency, and Commodities) target-state migration to AWS. Conduct STRIDE-based threat assessments, design security controls mapping, and establish security testing frameworks for multi-region disaster recovery environments. Architect HashiCorp Vault integration patterns, validate IBM MQ RDQM security configurations, and define security requirements for OpenShift Container Platform (OCP) deployments on AWS with financial services compliance focus.

Role Scope & Key Responsibilities

·         Threat Modeling & Risk Assessment: Conduct STRIDE-based threat modeling for FICC target-state architecture on AWS; map security controls to identified threats using DREAD methodology; assess attack surfaces across multi-region deployments

·         Security Testing Framework: Define comprehensive security testing framework covering pre-deployment validation, integration testing, resilience testing, and continuous security monitoring for AWS workloads

·         Multi-Region DR Security: Validate disaster recovery design from security perspective including split-brain prevention mechanisms, cross-region audit trail integrity, and failover security controls

·         Secrets Management Architecture: Design HashiCorp Vault integration patterns for OCP workloads on AWS including authentication methods (Kubernetes auth, AWS IAM auth), per-SYS ID ACL policies, and secret rotation strategies

·         Messaging Security: Assess IBM MQ RDQM security configurations including mTLS certificate management, channel authentication (CONNAUTH), and encryption at rest/in transit

·         Platform Security Governance: Review AWS Control Tower/Organizations security controls (Service Control Policies, account boundaries, guardrails) for A3P platform; define security baselines and compliance frameworks

·         Identity Federation: Define Ping Federate cloud connectivity security requirements for AWS integration including SAML/OIDC federation, MFA enforcement, and session management

·         Security Documentation: Produce security implementation guidance, developer security checklists, and HiPAM-to-Vault migration scope assessments per SYS I

Key Deliverables:

·         Security Threat Model & Controls Mapping (STRIDE/DREAD analysis)

·         Security Testing Framework (pre-deployment, integration, resilience, continuous)

·         Security Implementation Guidance & Developer Checklist

·         HiPAM-to-Vault Migration Scope Assessment per SYS ID

·         Multi-Region DR Security Validation Report

·         Vault Integration Architecture Design

IBM MQ RDQM Security Assessment

AWS Skills & Services

 

Security & Compliance:

·         AWS IAM: Advanced policies, permission boundaries, cross-account roles, IRSA (IAM Roles for Service Accounts) for EKS/OCP, service control policies (SCPs), IAM Access Analyzer

·         AWS Secrets Manager: Secret rotation, cross-account access, integration with HashiCorp Vault, RDS/Aurora credential management

·         AWS KMS: Customer Managed Keys (CMKs), key policies, cross-region key replication, envelope encryption, CloudHSM integration

·         AWS Security Hub: Centralized security findings, compliance standards (CIS, PCI-DSS, NIST), automated remediation, custom insights

·         AWS GuardDuty: Threat detection, malware protection, runtime monitoring, S3 protection, EKS protection

·         Amazon Macie: Sensitive data discovery, PII detection, S3 bucket classification

·         AWS Config: Configuration compliance, conformance packs, remediation actions, resource inventory

·         AWS CloudTrail: Multi-region trails, log file validation, CloudTrail Insights, event history analysis, cross-account logging

·         AWS Audit Manager: Compliance framework automation, evidence collection, audit-ready reports

Networking & Isolation:

·         Amazon VPC: Security groups, NACLs, VPC Flow Logs, VPC peering, PrivateLink, Transit Gateway route isolation

·         AWS Network Firewall: Stateful/stateless rules, intrusion prevention, domain filtering, TLS inspection

·         AWS WAF: Web application protection, managed rule groups, rate limiting, bot control

·         AWS Shield: DDoS protection (Standard/Advanced), attack mitigation, cost protection

·         AWS PrivateLink: Service endpoint isolation, cross-account connectivity without internet exposure

 

Container & Compute Security:

·         Amazon EKS: Pod security policies/standards, IRSA, network policies, secrets encryption, runtime security (Falco/Sysdig integration)

·         Amazon ECR: Image scanning (basic/enhanced), vulnerability assessment, immutable tags, lifecycle policies, encryption

·         AWS Systems Manager: Patch Manager, Session Manager (bastion replacement), Parameter Store encryption, Run Command

Disaster Recovery & Resilience:

·         AWS Backup: Vault Lock (WORM compliance), cross-region backup, backup policies, audit reporting

·         Amazon Route 53: Health checks, failover routing, DNSSEC, private hosted zones

·         AWS Elastic Disaster Recovery (DRS): Continuous replication, failover orchestration, split-brain prevention

 

Monitoring & Incident Response:

·         Amazon CloudWatch: Security metrics, log aggregation, anomaly detection, alarms, dashboards

·         Amazon Detective: Security investigation, graph-based analysis, threat hunting

·         AWS Step Functions: Automated incident response workflows, security orchestration

·         Amazon EventBridge: Event-driven security automation, cross-account event routing

 

Identity & Federation:

·         AWS IAM Identity Center (SSO): SAML/OIDC federation, Ping Federate integration, MFA enforcement, session policies

·         Amazon Cognito: User authentication, identity pools, user pools (if applicable for application-level auth)

 

Governance & Compliance:

·         AWS Organizations: Multi-account strategy, OU structure, SCP policies, consolidated billing

·         AWS Control Tower: Landing zone automation, guardrails, Account Factory, compliance dashboards

AWS Service Catalog: Compliance-approved resource templates, self-service provisioning

Financial Services & Industry Skills

·        Large regulated financial-services delivery with formal change-control, audit and risk governance

·        Operational resilience expectations including RTO/RPO, multi-region DR and evidence for audit review

·        Awareness of applicable controls and regulations such as DORA, NIST CSF 2.0, PCI DSS, SEC cyber rules, RegSCI and SIFMU/FMI expectations where relevant

·        Ability to create Tech Risk-ready documentation including ADRs, runbooks, design docs, threat models and validation evidence

·        Clear communication with client engineering, security, SRE, data and platform stakeholders as an embedded SME

Certifications / Qualifications

·        AWS Certified Security - Specialty

·        AWS Certified Solutions Architect - Professional

·        AWS Certified Advanced Networking - Specialty nice to have

 

Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 90718572
  • Position Id: 9062460
  • Posted 1 day ago
Contact the job poster
kiran myneni

kiran myneni

Talent Acquisition Manager @ ISite Technologies Inc
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Manor, Texas

2d ago

Easy Apply

Contract, Third Party

Depends on Experience

Remote or Austin, Texas

Today

Full-time

USD 175,000.00 - 200,000.00 per year

Remote

11d ago

Easy Apply

Contract, Third Party

$65 - $70

Remote

4d ago

Easy Apply

Contract, Third Party

Depends on Experience

Search all similar jobs