Job Description
Overview: We are in search of a highly skilled and experienced AWS Cloud Security Engineer to join our team. This role will be responsible for designing, implementing, and maintaining security solutions for our cloud-based infrastructure on Amazon Web Services (AWS). The ideal candidate will have a strong background in cloud security architecture, deep knowledge of AWS services and security best practices, and the ability to collaborate with cross-functional teams to ensure the security and compliance of our cloud environments.
Responsibilities:
- Develop and maintain a comprehensive AWS cloud security architecture, encompassing identity and access management (IAM), network security, data protection, encryption, logging, and monitoring.
- Design and implement security controls, policies, and procedures to protect AWS resources, data, and applications from unauthorized access, exploitation, and cyber threats.
- Conduct security assessments, risk analysis, and vulnerability scans to identify and mitigate security risks and compliance gaps in AWS environments.
- Implement and configure security tools and services on AWS, such as AWS Identity and Access Management (IAM), AWS Security Hub, AWS WAF, AWS GuardDuty, and AWS Config.
- Establish and enforce security best practices, compliance standards (e.g., PCI DSS, HIPAA, GDPR), and industry regulations in alignment with organizational policies and objectives.
- Collaborate with development and operations teams to integrate security into the software development lifecycle (SDLC) and continuous integration/continuous deployment (CI/CD) pipelines.
- Provide security guidance, technical expertise, and training to internal teams on AWS security architecture, controls, and technologies.
- Monitor security events, alerts, and incidents in AWS environments, and respond to security breaches, incidents, and anomalies in a timely and effective manner.
- Stay up-to-date with emerging threats, vulnerabilities, and security trends in cloud computing and AWS services, and recommend proactive measures and solutions to enhance security posture.