About Us:
LTM is a global technology consulting and digital solutions company that enables enterprises across industries to reimagine business models, accelerate innovation, and maximize growth by harnessing digital technologies. As a digital transformation partner to more than 700+ clients, LTM brings extensive domain and technology expertise to help drive superior competitive differentiation, customer experiences, and business outcomes in a converging world. Powered by nearly 90,000 talented and entrepreneurial professionals across more than 30 countries, LTM a Larsen & Toubro Group company combines the industry-acclaimed strengths of erstwhile Larsen and Toubro Infotech and Mindtree in solving the most complex business challenges and delivering transformation at scale. For more information, please visit
Title: AWS Cloud Security Architect
Location: Remote
Cloud Security Engineer - SRC (Partner)
Description: Hands-on policy authoring and implementation resources responsible for designing and writing Service Control Policies (SCPs), Resource Control Policies (RCPs) and data perimeter policy rule sets. Work under the direction of the AWS Lead Security Consultant. Responsible for Terraform-compatible policy code delivery, testing in non-production environments, and blast radius analysis. Resources are required to cover the volume of work (47 SCPs + 11 RCPs + data perimeter) within the engagement timeline.
Activities:
- Author SCP policy rule sets for all 47 enabled AWS services, prioritized by SCI tier
- Author RCP policy rule sets for the 11 eligible services (S3, KMS, CloudWatch Logs, DynamoDB, EC2 Autoscaling, Inspector, Kinesis, SQS, CodeBuild, CodePipeline, Secrets Manager)
- Implement VPC endpoint policies and resource-based policies for critical assets (logging buckets, KMS keys)
- Deliver all policy artifacts as Terraform-compatible code for deployment via Control Tower AFT pipelines (new landing zone) and hybrid Terraform/manual deployment (legacy landing zone)
- Validate policy syntax and functionality in sandbox/non-production environments
- Conduct blast radius analysis documenting potential impact of each policy on existing workloads
- Develop phased rollout plans (Account/OU level to root) for each policy batch
- Identify and document Control Tower default SCP overlaps with custom policies
- Develop operational runbooks for ongoing policy management and exception handling
- Conduct knowledge transfer sessions with Customers Platform Engineering Team and Cloud Engineering teams
Skills Required:
- AWS Certified Security - Specialty (required)
- Hands-on experience authoring SCPs, RCPs, and data perimeter controls (VPC endpoint policies, resource-based policies)
- Strong Terraform/Infrastructure-as-Code skills, including experience with AWS Control Tower AFT
- Deep knowledge of IAM policy language, condition keys, and service-specific policy capabilities
- Experience with phased deployment of organizational policies in multi-account AWS environments
- Understanding of blast radius analysis and rollback methodologies for policy changes
- Familiarity with NIST and financial services compliance requirements
- Experience working across both Control Tower and legacy (non-CT) AWS landing zones
Benefits/perks listed below may vary depending on the nature of your employment with LTM (LTIM):
Benefits and Perks:
- Medical Plan Covering Medical, Dental, Vision
- Term and Long-Term Disability Coverage
- Plan with Company match.
- Insurance
- Time, Sick Leave, Paid Holidays
- Paternity and Maternity Leave
The range displayed on each job posting reflects the minimum and maximum salary target for the position across all US locations. Within the range, individual pay is determined by work location and job level and additional factors including job-related skills, experience, and relevant education or training. Depending on the position offered, other forms of compensation may be provided as part of overall compensation like an annual performance-based bonus, sales incentive pay and other forms of bonus or variable compensation.
Disclaimer: The compensation and benefits information provided herein is accurate as of the date of this posting.
LTM is an equal opportunity employer that is committed to diversity in the workplace. Our employment decisions are made without regard to race, color, creed, religion, sex (including pregnancy, childbirth or related medical conditions), gender identity or expression, national origin, ancestry, age, family-care status, veteran status, marital status, civil union status, domestic partnership status, military service, handicap or disability or history of handicap or disability, genetic information, atypical hereditary cellular or blood trait, union affiliation, affectional or sexual orientation or preference, or any other characteristic protected by applicable federal, state, or local law, except where such considerations are bona fide occupational qualifications permitted by law.
Safe return to office:
In order to comply with LTM s company COVID-19 vaccine mandate, candidates must be able to provide proof of full vaccination against COVID-19 before or by the date of hire. Alternatively, one may submit a request for reasonable accommodation from LTM s COVID-19 vaccination mandate for approval, in accordance with applicable state and federal law, by the date of hire. Any request is subject to review through LTM s applicable processes.