Role: Senior AWS Cloud Security & Automation Engineer
Job Details
Location:
- Philadelphia Suburbs, Pennsylvania (Hybrid)
- Charlotte, North Carolina (Hybrid)
Job Type:
Work Model:
- Hybrid – 3 days onsite (Tuesday through Thursday)
Duration:
- 6+ Months with possible extension
Start Timeline:
- Approximately 2 weeks after offer acceptance (subject to background check)
Interview Type:
Visa Status:
Job Overview
We are seeking experienced Senior AWS Cloud Security & Automation Engineers to support enterprise-scale cloud security initiatives. This role focuses on platform-level AWS security engineering and requires hands-on ownership of infrastructure security within large multi-account AWS environments. Candidates should have extensive experience implementing and maintaining security controls, automating cloud operations, and driving remediation efforts in production environments.
Key Responsibilities
- Design, implement, and manage security controls across large-scale AWS environments.
- Administer and maintain AWS IAM, KMS, Secrets Manager, and Service Control Policies (SCPs).
- Develop and maintain infrastructure using CloudFormation.
- Build and enhance automation solutions using Python.
- Manage and remediate vulnerabilities identified through CSPM and SAST tools.
- Execute security improvements and changes in production enterprise environments.
- Collaborate with infrastructure and security teams to maintain cloud security standards.
- Support ongoing cloud governance and operational security initiatives.
Required Skills
- Strong hands-on experience with AWS services including IAM, KMS, Secrets Manager, and SCPs.
- Experience supporting multi-account AWS environments.
- Advanced proficiency with CloudFormation (required Infrastructure as Code platform).
- Senior-level Python development and automation experience.
- Experience with Wiz or equivalent CSPM platforms such as Orca, Prisma Cloud, or Lacework.
- Experience with Snyk or other SAST vulnerability scanning tools with direct remediation ownership.
- Proven experience implementing security changes in enterprise production environments.
Preferred Skills
- Experience with multiple cloud security platforms.
- Strong understanding of cloud governance and security best practices.
Qualifications
- Demonstrated infrastructure ownership experience within enterprise AWS environments.
- Ability to work onsite three days per week (Tuesday through Thursday).
- Strong problem-solving and collaboration skills.
Technical Skills
- AWS IAM
- AWS KMS
- AWS Secrets Manager
- AWS Service Control Policies (SCPs)
- CloudFormation
- Python
- Wiz
- Orca
- Prisma Cloud
- Lacework
- SnykAWS IAM
- AWS KMS
- AWS Secrets Manager
- AWS Service Control Policies (SCPs)
- CloudFormation
- Python
- Wiz
- Orca
- Prisma Cloud
- Lacework
- Snyk
- SAST Tools
- SAST Tools
Additional Requirements
- Candidates must be employed directly by their organization as a W2 or direct C2C employee.
- Sub-contracting and multi-layered arrangements are not permitted.
- Candidates must be available for hybrid onsite work in either the Philadelphia suburbs or Charlotte, NC.
- Background check required prior to onboarding.