Role: Senior AWS Cloud Security & Automation Engineer
Job Details
- Job Title: Senior AWS Cloud Security & Automation Engineer
- Job Type: Contract (C2C)
- Location: Philadelphia Suburbs, Pennsylvania or Charlotte, North Carolina
- Work Model: Hybrid – 3 days onsite (Tuesday through Thursday)
- Duration: 6+ Months with possible extension
- Visa Status: USC and Green Card holders only
Job Overview
We are seeking experienced Senior AWS Cloud Security & Automation Engineers to support large-scale enterprise cloud environments. This role focuses on platform-level AWS security engineering and requires hands-on ownership of cloud infrastructure security across multi-account AWS environments.
The ideal candidate will have strong experience implementing security controls, automating cloud operations, and driving remediation efforts in production environments. This is an infrastructure-focused role and is not suitable for application security or advisory-only backgrounds.
Key Responsibilities
- Design, implement, and manage security controls across enterprise AWS environments.
- Administer and secure multi-account AWS environments using best practices.
- Manage AWS IAM, KMS, Secrets Manager, and Service Control Policies (SCPs).
- Develop and maintain infrastructure automation using CloudFormation.
- Build and support automation solutions using Python.
- Utilize CSPM tools to identify and remediate cloud security risks.
- Perform vulnerability management and actively drive remediation activities.
- Implement high-impact security changes within production environments.
- Collaborate with engineering teams to maintain secure and scalable cloud platforms.
Required Skills
- Strong hands-on experience with AWS services including IAM, KMS, Secrets Manager, and SCPs.
- Experience working in large-scale, multi-account AWS environments.
- Deep expertise with CloudFormation as the primary Infrastructure-as-Code tool.
- Senior-level Python development and automation experience.
- Hands-on experience with Wiz or equivalent CSPM platforms such as Orca, Prisma Cloud, or Lacework.
- Experience with Snyk and SAST vulnerability scanning tools.
- Proven experience owning remediation activities and implementing security improvements in production environments.