Haystack
← Back to Jobs
Technology
AC

IAM Cloud Engineer

Alltech Consulting Services, Inc.Alpharetta, GA🇺🇸United StatesPosted Oct 8, 2026

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
Alpharetta, GA, United States
Posted
16 hours ago
ShellAWSPython

Job Description

Role: IAM Cloud Engineer
Location: Alpharetta, Georgia


Hands-on cloud threat detection and hunting specialist to assess security telemetry, investigate suspicious activity, and strengthen detection coverage across the existing and target AWS environments. The role will support migration readiness, cutover monitoring, and stabilization in partnership with enterprise security operations and cloud engineering teams.
Key responsibilities
Assess visibility across AWS accounts, workloads, identities, network flows, and application services; identify logging and detection gaps affecting migration readiness.
Work with platform teams to enable and validate approved security telemetry, including CloudTrail, VPC Flow Logs, and relevant EKS, operating-system, and application logs.
Conduct hypothesis-driven threat hunts for credential misuse, privilege escalation, suspicious role assumption, persistence, lateral movement, and potential data exfiltration.
Correlate cloud control-plane events, identity activity, network records, and workload evidence to investigate alerts and establish incident scope and timelines.
Develop and tune detection queries, correlation rules, and alert triage procedures in the client-approved SIEM and cloud security platforms.
Assess exposed services, public storage, excessive privileges, and unusual network traffic; prioritize findings with IAM, network, application, and infrastructure owners.
Validate detections through approved, controlled simulations and test cases; document coverage and false-positive reduction.
Support incident response with evidence preservation, investigation findings, and containment recommendations; execute response actions only through approved processes.
Establish migration-period monitoring baselines and enhanced coverage for parallel operation, cutover, and stabilization.
Prepare hunt reports, detection documentation, response playbooks, and security evidence supporting governance reviews and operational handover.
Required skills and experience
Proposed experience target: 7 10 years in cybersecurity, including 4+ years in threat detection, hunting, or incident response and demonstrable hands-on AWS investigations; subject to client/SME validation.
Strong understanding of AWS IAM, networking, S3, EC2, EKS, and cloud attack paths.
Hands-on analysis of CloudTrail, VPC Flow Logs, identity events, Linux/container logs, and other security telemetry.
Experience writing SIEM queries and detection logic, correlating evidence, and investigating suspicious behavior beyond basic alert triage.
Ability to build threat-hunting hypotheses, map findings to MITRE ATT&CK techniques, and communicate investigation outcomes clearly.
Python or shell scripting skills for repeatable analysis and security automation.
Experience coordinating with incident responders and engineering teams, handling sensitive evidence, and working within production change controls.
Preferred qualifications

Similar jobs