Haystack
← Back to Jobs
Technology
IT

Aws Cloud Security Engineer

ISite Technologies IncManor, TX🇺🇸United StatesPosted 19 Aug 2026

Why This Role Stands Out

This hybrid role offers a significant opportunity to modernize critical AWS cloud infrastructure within the financial services sector, building on your extensive experience. You'll thrive here if you're a hands-on AWS security expert eager to design and implement resilient, observable platforms and create essential documentation. Apply today to join a reputable company and advance your career in cloud security.

Quick Overview

Work Type
Hybrid
Level
Mid Senior

Job Description

Job Role: Aws Cloud Security Engineer

Location: Boston, MA, Arlington, VA, Atlanta, GA,:Austin, TX, Chicago, IL, Cleveland, OH:

Experience: 10 Years

Skills:

This Senior Consultant role modernizes legacy workloads into cloud-native, resilient and observable AWS platforms. The consultant is expected to operate as an embedded AWS SME, provide hands-on implementation support, and create audit-ready technical documentation aligned to regulated Financial Services delivery expectations.

Role Scope & Key Responsibilities

·         Multi-Account Governance (WS-2): Design AWS Organizations landing zone with OU structure, Service Control Policies (SCPs), centralized logging (CloudTrail, VPC Flow Logs, AWS Config), and automated account vending for Security Lab foundation

·         Isolated Recovery Environment (WS-3): Architect IRE account with WORM vault locking (S3 Object Lock/Backup Vault Lock), cross-account/cross-region backup (3-2-1 strategy), AWS KMS CMKs, CyberArk break-glass integration, Amazon Macie data classification, AWS Network Firewall, Transit Gateway route isolation, and recovery orchestration

·         Clean Room Forensics: Design forensic investigation environment with network isolation, immutable evidence storage, and controlled access patterns

·         Security Lab Infrastructure: Establish Amazon EKS baseline and lab environment for testing security capabilities, threat simulation, and vulnerability assessments

·         Compliance & Audit: Design AWS Backup Audit Manager compliance framework, Route 53 DNS isolation, and hardened compute baselines (AMI/container hardening)

·         Documentation & Implementation: Author IRE & Clean Room Architecture & Design Document, Security Lab Architecture Document, lab operations guide, and account vending admin procedures

·         Security Agent Infrastructure (WS-1): Design and support AWS Security Agent cloud infrastructure implementation

Secrets Management: Implement AWS Secrets Manager/Parameter Store integration with CyberArk for break-glass scenarios

Key Deliverables:

·         Multi-Account Landing Zone Architecture with OU/SCP design

·         IRE & Clean Room Architecture & Design Document

·         Security Lab Architecture Document

·         Backup Audit Manager compliance framework

·         Hardened compute baselines (AMIs, EKS node configurations)

·         Account vending automation and admin procedures

Recovery orchestration runbooks

AWS Skills & Services

Governance & Multi-Account Architecture:

·        AWS Organizations: OU structure design, SCP policies, consolidated billing, cross-account IAM strategies

·        AWS Control Tower: Landing zone automation, guardrails, Account Factory customization

·        AWS Service Catalog: Automated account vending, standardized resource provisioning

·        AWS Resource Access Manager (RAM): Cross-account resource sharing for Transit Gateway, Route 53 Resolver

Security & Compliance:

·        AWS IAM: Advanced policies, permission boundaries, IRSA (IAM Roles for Service Accounts), cross-account roles, break-glass access patterns

·        AWS KMS: Customer Managed Keys (CMKs), key policies, cross-account/cross-region key grants, envelope encryption

·        AWS Secrets Manager: Secret rotation, CyberArk integration, cross-account secret access

·        Amazon Macie: Sensitive data discovery, S3 bucket classification, compliance reporting

·        AWS Security Hub: Centralized security findings, compliance standards (CIS, PCI-DSS)

·        AWS GuardDuty: Threat detection, malware protection, runtime monitoring

·        AWS Network Firewall: Stateful/stateless rules, intrusion prevention, domain filtering

·        AWS WAF: Web application protection, managed rule groups

Backup & Disaster Recovery:

·        AWS Backup: Centralized backup management, WORM vault locking (Vault Lock), cross-account/cross-region backup, 3-2-1 backup strategy

·        AWS Backup Audit Manager: Compliance framework design, backup policy enforcement, audit reporting

·        Amazon S3: Object Lock (WORM compliance), versioning, cross-region replication, Glacier Vault Lock

·        AWS Elastic Disaster Recovery (DRS): Continuous replication, recovery orchestration, failover testing

Logging & Monitoring:

·        AWS CloudTrail: Multi-account trail design, log file validation, S3/CloudWatch Logs integration, event history analysis

·        Amazon CloudWatch: Centralized logging, log aggregation, metric filters, alarms, dashboards

·        VPC Flow Logs: Network traffic analysis, security group validation, threat detection

·        AWS Config: Configuration compliance, resource inventory, change tracking, conformance packs

Networking & Isolation:

·        Amazon VPC: Advanced networking, security groups, NACLs, VPC peering, PrivateLink

·        AWS Transit Gateway: Hub-and-spoke architecture, route table isolation, network segmentation

·        Amazon Route 53: DNS isolation, private hosted zones, DNSSEC, resolver rules

·        AWS PrivateLink: Service endpoint isolation, cross-account connectivity without internet exposure

Container & Compute Security:

·        Amazon EKS: Cluster hardening, pod security policies/standards, IRSA, network policies, secrets encryption, runtime security

·        Amazon ECR: Image scanning, vulnerability assessment, immutable tags, lifecycle policies

·        AWS Systems Manager: Patch Manager, Session Manager (bastion replacement), Parameter Store, hardened AMI automation

·        Amazon EC2: Hardened AMI creation, IMDSv2 enforcement, instance metadata security, EBS encryption

Forensics & Incident Response:

·        Amazon Detective: Security investigation, graph-based analysis, threat hunting

·        AWS Step Functions: Recovery orchestration workflows, automated incident response

·        Amazon EventBridge: Event-driven security automation, cross-account event routing

·        AWS Lambda: Automated remediation, forensic data collection, snapshot automation

Infrastructure as Code & Automation:

·        AWS CloudFormation: StackSets for multi-account deployments, nested stacks, drift detection

·        AWS CDK: Programmatic infrastructure definition, construct libraries for security patterns

·        AWS Service Catalog: Self-service account vending, compliance-approved resource templates

Cost Optimization & Governance:

·        AWS Cost Explorer: Cost allocation tags, backup storage optimization

·        AWS Budgets: Cost alerts, anomaly detection

·         AWS Trusted Advisor: Security and cost optimization recommendations

Financial Services & Industry Skills

·        Large regulated financial-services delivery with formal change-control, audit and risk governance

·        Operational resilience expectations including RTO/RPO, multi-region DR and evidence for audit review

·        Awareness of applicable controls and regulations such as DORA, NIST CSF 2.0, PCI DSS, SEC cyber rules, RegSCI and SIFMU/FMI expectations where relevant

·        Ability to create Tech Risk-ready documentation including ADRs, runbooks, design docs, threat models and validation evidence

·        Clear communication with client engineering, security, SRE, data and platform stakeholders as an embedded SME

Certifications / Qualifications

·        AWS Certified Solutions Architect - Associate / Professional

·        AWS Certified Developer - Associate

·        AWS Certified DevOps Engineer - Professional preferred

Skills

AWS
Encryption
PCI DSS
CDK
CloudFormation
DNS
Vault
WAF

Similar jobs