Experience: 3 to 6 years
Roles and Responsibilities
Overview:
We are seeking a motivated and technically skilled Cloud Security Engineering Analyst with at least 3 years of experience in AWS Cloud Security. The role involves leading the design, testing, deployment, and compliance validation of AWS security policies and controls. You will be responsible for integrating cloud-native and custom guardrails, performing risk assessments, managing policy exceptions, and collaborating with cross-functional teams to enforce security-by-default principles. This position requires a strong understanding of AWS-native security services and the ability to develop scalable policy enforcement strategies across multiple accounts.
Key Responsibilities:
· Design, develop, and deploy custom and AWS-native security policies (e.g., SCPs, IAM policies, AWS Config Rules) across AWS accounts.· Perform pre-deployment compliance assessments and identify non-compliant configurations in AWS environments.· Collaborate with application and infrastructure teams to remediate misconfigurations and implement secure-by-design practices.· Validate and monitor policy effectiveness post-deployment using tools like AWS Config, Security Hub, CloudTrail, and GuardDuty.· Own and manage the AWS policy exemption workflow — review exception requests, conduct risk assessments, and track approvals.· Maintain detailed documentation on policy changes, enforcement status, and exception decisions.· Participate in tool evaluations and implementations that support cloud security posture management and automation.· Support continuous improvement of cloud security posture through quarterly reviews, metrics, and tuning recommendations.
Required Qualifications:
· Minimum 3 years of hands-on experience in AWS cloud security or policy enforcement.· Strong working knowledge of AWS security services: IAM, SCPs, AWS Config, Security Hub, CloudTrail, GuardDuty, KMS, etc.· Experience with cloud compliance standards (e.g., CIS AWS Foundations Benchmark, NIST, ISO 27001, HIPAA).· Proficient in writing and troubleshooting IAM policies, JSON/YAML templates, Lambda functions, and scripting (Python/Bash).· Familiarity with DevSecOps practices and Infrastructure as Code (IaC) tools such as Terraform or CloudFormation.
Preferred Certifications:
· AWS Certified Security – Specialty· AWS Certified Solutions Architect – Associate or Professional
Soft Skills:
· Excellent communication and stakeholder collaboration skills.· Strong analytical thinking and problem-solving abilities.· Ability to manage multiple tasks and priorities in a fast-paced environment.Apply for this job