Security Engineer - (VPC, VPN peering, network segmentation, IAM, secrets management)

VTekis Consulting LLP

Security Engineer - (VPC, VPN peering, network segmentation, IAM, secrets management)

New York, NY
Full Time
Paid
  • Responsibilities

    Job Description

    Hard skills

    AWS infrastructure security experience (VPC,​ VPN peering,​ network segmentation,​ IAM,​ secrets management)

    Application security experience (threat modeling,​ dependency/supply-​chain controls,​ secure code review)

    Identity and access management (SSO,​ RBAC,​ least-​privilege design) for both humans and non-​human actors

    IT security (endpoint security,​ device management,​ access controls)

    Compliance and auditability program experience (SOC2,​ pentest coordination,​ vulnerability management)

    What we're looking for

    We need an experienced security engineer with broad expertise across AWS infrastructure security, application security, and identity/access management who has owned security end-to-end as the first or sole security hire at a fast-moving startup. You should be comfortable operating with high autonomy in a small team, building security programs from scratch, and have a track record of making the secure path the easy path rather than gatekeeping. Bonus points if you have experience securing AI/agent systems or working in financial services.

    What you'll do:

    • Own infrastructure security across the entire AWS environment — VPC/VPN peering, network segmentation, IAM, secrets management — designing guardrails that make the secure default also the fastest one
    • Take ownership of application security across web and desktop clients, embedding threat modeling, dependency/supply-chain controls, and secure code review into how the team designs and ships
    • Build and manage identity and access controls (SSO, RBAC, least-privilege) for both humans and AI agents, ensuring every actor reaches exactly what it needs and nothing more
    • Design audit trails and access controls that make autonomous agent activity fully reconstructable — what it did, on whose behalf, with what data, and why
    • Own IT security in partnership with the IT MSP — devices, endpoints, and access for a 12-person in-office team
    • Stand up and run compliance, auditability, bug bounty, VDP, and pentest programs that prove security posture to clients, partners, and auditors as a byproduct of how the system is built.

    Regards,

    Mohammed ilyas,

    PH - 229-264-4024 or Text - 229-469-1455 or you can share the updated resume at Mohammed@vtekis. com

  • Qualifications

    Additional Information

    All your information will be kept confidential according to EEO guidelines.