AWS Security Sr. Engineer
6 days ago
Overview:
We are seeking an experienced and highly skilled Senior AWS Security Engineer with a strong focus on Threat Modeling to join our Cloud Security team. In this role, you will be responsible for assessing, identifying, and mitigating potential security risks across our AWS cloud infrastructure and applications. You will collaborate with product engineering teams to identify security vulnerabilities early in the design and development stages, while promoting security best practices across all cloud-based systems.
As part of a rapidly evolving security landscape, you will work with cross-functional teams to build, enhance, and implement threat models that help safeguard our infrastructure, applications, and data in the AWS environment.
Key Responsibilities:
Threat Modeling: Lead and perform threat modeling exercises for AWS cloud-based applications and services, identifying security threats, vulnerabilities, and attack vectors early in the development lifecycle.
Cloud Security Design: Work closely with development teams to integrate security into the design and architecture of AWS-based systems and applications. Provide guidance on secure AWS configurations and secure design principles.
Risk Assessment & Mitigation: Assess the security risks of existing systems, architectures, and processes. Recommend mitigation strategies for identified risks, ensuring they align with AWS security best practices.
Security Requirements & Compliance: Define security requirements for AWS cloud environments, ensuring that security controls and compliance requirements (e.g., SOC 2, GDPR, HIPAA, etc.) are met across all applications and infrastructure.
Automation & Tooling: Develop and implement automated security testing, monitoring, and reporting tools for threat detection and vulnerability management within the AWS ecosystem.
Incident Response & Vulnerability Management: Collaborate with incident response and security operations teams to identify, assess, and resolve security incidents. Lead post-incident analysis and root cause investigations.
Training & Awareness: Provide training, guidance, and mentorship to development and operations teams on threat modeling, secure coding practices, and AWS-specific security best practices.
Documentation & Reporting: Create comprehensive documentation on threat models, risk assessments, mitigation plans, and security controls. Provide regular reports to senior leadership on security posture and progress on remediation efforts.
Required Skills and Qualifications:
Experience: 5+ years of experience in cloud security, with a focus on AWS.
- Proven experience with Wiz, Turbot, Custom Rego Policies, Custom Org Constraints, and AWS GraphQL.
- Solid understanding of threat modeling methodologies and tools, specifically for AWS environments.
- Deep knowledge of AWS security best practices, including but not limited to IAM, VPC security, S3, KMS, CloudTrail, GuardDuty, and Security Hub.
Expertise in Threat Modeling: Strong experience using industry-standard threat modeling methodologies (e.g., STRIDE, PASTA, etc.) to identify and mitigate potential threats in cloud environments, especially AWS.
AWS Knowledge: Deep understanding of AWS security services and best practices, including IAM, VPC, Security Groups, KMS, CloudTrail, GuardDuty, Inspector, Macie, etc. Experience securing infrastructure and applications in AWS environments.
Security Frameworks & Standards: Strong knowledge of security frameworks, regulations, and standards (e.g., NIST, OWASP, CIS, PCI-DSS, SOC 2, etc.) and experience ensuring compliance within AWS environments.
Programming & Scripting: Proficiency in at least one programming or scripting language (e.g., Python, Go, Bash) for automation and security tooling.
Penetration Testing & Vulnerability Management: Familiarity with common penetration testing and vulnerability scanning tools, and ability to assess and mitigate risks in cloud environments.
Communication & Collaboration: Excellent communication skills with the ability to convey complex security concepts to both technical and non-technical stakeholders. Strong collaboration skills to work effectively across engineering and security teams.
Preferred Qualifications:
- AWS Certified Security Specialty or other relevant AWS certifications.
- Experience with container security (e.g., Docker, Kubernetes) in AWS.
- Experience working with Infrastructure as Code (IaC) tools like Terraform, CloudFormation, etc., and understanding of security challenges related to IaC.
- Experience with security tools for continuous integration/continuous delivery (CI/CD) pipelines, code scanning, and container security.
- Knowledge of advanced attack techniques such as lateral movement, privilege escalation, and cloud-native vulnerabilities.
-
AWS Security Sr. Engineer
2 days ago
india Photon Group Full timeDescriptionOverview:We are seeking an experienced and highly skilled Senior AWS Security Engineer with a strong focus on Threat Modeling to join our Cloud Security team. In this role, you will be responsible for assessing, identifying, and mitigating potential security risks across our AWS cloud infrastructure and applications. You will collaborate with...
-
Sr. AWS DevOps Engineer
1 day ago
india Jobgether Full timeThis position is posted by Jobgether on behalf of a partner company. We are currently looking for a Sr. AWS DevOps Engineer in India.We are seeking a highly skilled AWS DevOps Engineer to join a dynamic and innovative team. In this role, you will be responsible for designing, implementing, and maintaining cloud infrastructure and automation processes to...
-
Cloud Security Validation Engineer
1 day ago
india Upwind Security Full timeUpwind is a next-generation Cloud Security Platform that leverages runtime context to identify and prioritize critical risks, providing precise insights and efficient cloud security management. Unlike traditional tools, Upwind uses runtime data proactively for risk prioritization and posture insights, ensuring teams focus on what truly matters. With...
-
Sr. AWS DevOps Engineer
1 week ago
India Jobgether Full time ₹ 15,00,000 - ₹ 25,00,000 per yearThis position is posted by Jobgether on behalf of a partner company. We are currently looking for a Sr. AWS DevOps Engineer in India.We are seeking a highly skilled AWS DevOps Engineer to join a dynamic and innovative team. In this role, you will be responsible for designing, implementing, and maintaining cloud infrastructure and automation processes to...
-
Cloud Security Validation Engineer
1 week ago
India Upwind Security Full time ₹ 12,00,000 - ₹ 36,00,000 per yearUpwind is a next-generation Cloud Security Platform that leverages runtime context to identify and prioritize critical risks, providing precise insights and efficient cloud security management. Unlike traditional tools, Upwind uses runtime data proactively for risk prioritization and posture insights, ensuring teams focus on what truly matters. With...
-
Sr. AWS Data Engineer
1 week ago
India ProArch Full time US$ 60,000 - US$ 1,20,000 per yearProArch is seeking a highly skilled Sr. AWS Data Engineer to join our growing team. In this role, you will leverage your expertise in AWS to design, implement, and manage robust data solutions that enable our organization to capture, store, and analyze vast amounts of data. You will work closely with data scientists, analysts, and other engineering teams to...
-
Junior Cloud Security Validation Engineer
1 week ago
India Upwind Security Full time ₹ 5,00,000 - ₹ 15,00,000 per yearUpwind is a next-generation Cloud Security Platform that leverages runtime context to identify and prioritize critical risks, providing precise insights and efficient cloud security management. Unlike traditional tools, Upwind uses runtime data proactively for risk prioritization and posture insights, ensuring teams focus on what truly matters. With...
-
AWS Network Security
3 days ago
India Zensar Technologies Full time ₹ 12,00,000 - ₹ 24,00,000 per yearDescriptionAWS Network Security Engineer Location: [Your Location – e.g., Pune, Maharashtra]Job Type: Full-TimeExperience Level: Senior (5+ years)Role Overview:We are looking for a seasoned AWS Network Security Engineer to lead the deployment and management of a Cisco Identity Services Engine (ISE) environment within our AWS infrastructure. This role...
-
Senior Security Engineer – AI, Cloud
7 days ago
India Symosis Security Full timeLocation: Remote (India)Type: Full-TimeCompany: Symosis SecurityAbout Symosis SecuritySymosis is a cybersecurity consulting firm purpose-built for the AI-native, cloud-first era. We help public-sector and enterprise clients mature their security operations through managed services, offensive testing, governance, and automation. We’re expanding our MSSP...
-
AWS DevSecOps Sr. Engineer
1 week ago
India Photon Group Full time ₹ 12,00,000 - ₹ 36,00,000 per yearDescriptionAbout the Role:We are seeking an experienced and highly motivated Senior AWS DevSecOps Engineer / Tester with expertise in policy development, security automation, and infrastructure-as-code (IaC). The ideal candidate will have a strong background in AWS cloud environments, DevSecOps principles, and security policy mapping and enforcement. This...