Haystack
← Back to Jobs
Technology
ES

Lead AWS IAM Security Engineer

EPAM SystemsNew York, NY🇺🇸United StatesPosted 13 Sept 2026

Why This Role Stands Out

This Lead AWS IAM Security Engineer role offers a fantastic opportunity to architect and automate cutting-edge security controls for a next-generation multi-region architecture, fostering significant career growth in cloud security. You'll thrive here if you possess deep expertise in AWS IAM, PKI, and security automation, and are eager to contribute to a dynamic team at a reputable company. Embrace the hybrid flexibility and apply to shape the future of secure cloud environments!

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
New York, NY, United States
Posted
14 hours ago
AWSEncryptionSonarQubeCDKPKITypeScript

Job Description

We are looking for a specialized Cloud Security Engineer to secure our next-generation multi-region architecture. In this role, you will architect, implement, and automate robust security controls across AWS - spanning enterprise IAM, Public Key Infrastructure (PKI), secrets management, and cloud security posture management (CSPM) - while ensuring strict compliance for PCI-scoped fintech workloads.

Req.# Responsibilities Identity & Access Management: Design and enforce secure AWS IAM policies, roles, permission boundaries, Service Control Policies (SCPs), and EKS Pod Identity / IRSA configurations Cloud Detection & Posture Management: Implement and manage security monitoring and posture tools including Amazon GuardDuty, AWS Security Hub, AWS CloudTrail, Macie, and IAM Access Analyzer PKI & Certificate Management: Build and manage automated certificate lifecycle workflows using AWS Private CA (FIPS 140-2 Level 3 HSM-backed), ACM, and mTLS trust stores, coordinating closely with the client's Security approvals Secrets & Encryption: Secure sensitive data using AWS KMS (including Multi-Region Keys), Secrets Manager, and the External Secrets Operator Requirements Baseline (Mandatory): Strong hands-on experience with AWS CDK and TypeScript for security-as-code automation AWS PKI & TLS: Deep expertise in AWS Private CA (HSM-backed), ACM, mTLS trust stores, automated certificate issuance/rotation/revocation, and PayPal Security compliance workflows Proficiency with Amazon GuardDuty, Security Hub (AWS FSBP, CIS, NIST benchmarks), Macie, and IAM Access Analyzer Experience supporting strict PCI-scoped fintech audits and CSPM frameworks Identity & Secrets Management: Advanced IAM expertise (roles, trust policies, permission boundaries, SCPs, IRSA/EKS Pod Identity), Secrets Manager, External Secrets Operator, and KMS/MRK envelope encryption Supply Chain & Application Security: SAST tools (SonarQube, CodeQL), Dependabot, and software supply chain security (image signing and provenance via Cosign/SLSA) integrated with CDK & TypeScript Nice to have Experience with Wiz (CSPM/CNAPP) Advanced deployments of AWS Private CA (PCA) and complex KMS key hierarchies

Similar jobs