Job Role: Aws Cloud Security Engineer
Location: Boston, MA, Arlington, VA, Atlanta, GA,:Austin, TX, Chicago, IL, Cleveland, OH:
Experience: 10 Years
Skills:
This Senior Consultant role modernizes legacy workloads into cloud-native, resilient and observable AWS platforms. The consultant is expected to operate as an embedded AWS SME, provide hands-on implementation support, and create audit-ready technical documentation aligned to regulated Financial Services delivery expectations.
Role Scope & Key Responsibilities
· Multi-Account Governance (WS-2): Design AWS Organizations landing zone with OU structure, Service Control Policies (SCPs), centralized logging (CloudTrail, VPC Flow Logs, AWS Config), and automated account vending for Security Lab foundation
· Isolated Recovery Environment (WS-3): Architect IRE account with WORM vault locking (S3 Object Lock/Backup Vault Lock), cross-account/cross-region backup (3-2-1 strategy), AWS KMS CMKs, CyberArk break-glass integration, Amazon Macie data classification, AWS Network Firewall, Transit Gateway route isolation, and recovery orchestration
· Clean Room Forensics: Design forensic investigation environment with network isolation, immutable evidence storage, and controlled access patterns
· Security Lab Infrastructure: Establish Amazon EKS baseline and lab environment for testing security capabilities, threat simulation, and vulnerability assessments
· Compliance & Audit: Design AWS Backup Audit Manager compliance framework, Route 53 DNS isolation, and hardened compute baselines (AMI/container hardening)
· Documentation & Implementation: Author IRE & Clean Room Architecture & Design Document, Security Lab Architecture Document, lab operations guide, and account vending admin procedures
· Security Agent Infrastructure (WS-1): Design and support AWS Security Agent cloud infrastructure implementation
Secrets Management: Implement AWS Secrets Manager/Parameter Store integration with CyberArk for break-glass scenarios
Key Deliverables:
· Multi-Account Landing Zone Architecture with OU/SCP design
· IRE & Clean Room Architecture & Design Document
· Security Lab Architecture Document
· Backup Audit Manager compliance framework
· Hardened compute baselines (AMIs, EKS node configurations)
· Account vending automation and admin procedures
Recovery orchestration runbooks
Governance & Multi-Account Architecture:
· AWS Organizations: OU structure design, SCP policies, consolidated billing, cross-account IAM strategies
· AWS Control Tower: Landing zone automation, guardrails, Account Factory customization
· AWS Service Catalog: Automated account vending, standardized resource provisioning
· AWS Resource Access Manager (RAM): Cross-account resource sharing for Transit Gateway, Route 53 Resolver
Security & Compliance:
· AWS IAM: Advanced policies, permission boundaries, IRSA (IAM Roles for Service Accounts), cross-account roles, break-glass access patterns
· AWS KMS: Customer Managed Keys (CMKs), key policies, cross-account/cross-region key grants, envelope encryption
· AWS Secrets Manager: Secret rotation, CyberArk integration, cross-account secret access
· Amazon Macie: Sensitive data discovery, S3 bucket classification, compliance reporting
· AWS Security Hub: Centralized security findings, compliance standards (CIS, PCI-DSS)
· AWS GuardDuty: Threat detection, malware protection, runtime monitoring
· AWS Network Firewall: Stateful/stateless rules, intrusion prevention, domain filtering
· AWS WAF: Web application protection, managed rule groups
Backup & Disaster Recovery:
· AWS Backup: Centralized backup management, WORM vault locking (Vault Lock), cross-account/cross-region backup, 3-2-1 backup strategy
· AWS Backup Audit Manager: Compliance framework design, backup policy enforcement, audit reporting
· Amazon S3: Object Lock (WORM compliance), versioning, cross-region replication, Glacier Vault Lock
· AWS Elastic Disaster Recovery (DRS): Continuous replication, recovery orchestration, failover testing
Logging & Monitoring:
· AWS CloudTrail: Multi-account trail design, log file validation, S3/CloudWatch Logs integration, event history analysis
· Amazon CloudWatch: Centralized logging, log aggregation, metric filters, alarms, dashboards
· VPC Flow Logs: Network traffic analysis, security group validation, threat detection
· AWS Config: Configuration compliance, resource inventory, change tracking, conformance packs
Networking & Isolation:
· Amazon VPC: Advanced networking, security groups, NACLs, VPC peering, PrivateLink
· AWS Transit Gateway: Hub-and-spoke architecture, route table isolation, network segmentation
· Amazon Route 53: DNS isolation, private hosted zones, DNSSEC, resolver rules
· AWS PrivateLink: Service endpoint isolation, cross-account connectivity without internet exposure
Container & Compute Security:
· Amazon EKS: Cluster hardening, pod security policies/standards, IRSA, network policies, secrets encryption, runtime security
· Amazon ECR: Image scanning, vulnerability assessment, immutable tags, lifecycle policies
· AWS Systems Manager: Patch Manager, Session Manager (bastion replacement), Parameter Store, hardened AMI automation
· Amazon EC2: Hardened AMI creation, IMDSv2 enforcement, instance metadata security, EBS encryption
Forensics & Incident Response:
· Amazon Detective: Security investigation, graph-based analysis, threat hunting
· AWS Step Functions: Recovery orchestration workflows, automated incident response
· Amazon EventBridge: Event-driven security automation, cross-account event routing
· AWS Lambda: Automated remediation, forensic data collection, snapshot automation
Infrastructure as Code & Automation:
· AWS CloudFormation: StackSets for multi-account deployments, nested stacks, drift detection
· AWS CDK: Programmatic infrastructure definition, construct libraries for security patterns
· AWS Service Catalog: Self-service account vending, compliance-approved resource templates
Cost Optimization & Governance:
· AWS Cost Explorer: Cost allocation tags, backup storage optimization
· AWS Budgets: Cost alerts, anomaly detection
· AWS Trusted Advisor: Security and cost optimization recommendations
Financial Services & Industry Skills
· Large regulated financial-services delivery with formal change-control, audit and risk governance
· Operational resilience expectations including RTO/RPO, multi-region DR and evidence for audit review
· Awareness of applicable controls and regulations such as DORA, NIST CSF 2.0, PCI DSS, SEC cyber rules, RegSCI and SIFMU/FMI expectations where relevant
· Ability to create Tech Risk-ready documentation including ADRs, runbooks, design docs, threat models and validation evidence
· Clear communication with client engineering, security, SRE, data and platform stakeholders as an embedded SME
Certifications / Qualifications
· AWS Certified Solutions Architect - Associate / Professional
· AWS Certified Developer - Associate
· AWS Certified DevOps Engineer - Professional preferred