Haystack
← Back to Jobs
Remote
Technology
TD

Cloud Security Engineer

TESTINGXPERTS, INC. DBA DAMCOSOFTUnited States🇺🇸United StatesPosted 4 Sept 2026

Quick Overview

Seniority
Mid Senior
Work mode
Remote
Location
United States
Posted
Yesterday
AWSEncryptionTerraform

Job Description

Hello,

My name is Sreeja and I represent TestingXperts Inc. TestingXperts is a Specialist QA & Software Testing Company, and an Independent Software Testing division of Damco Group, which is a leading IT Solutions and Services company working with Fortune Enterprises globally. Inheriting the virtues of job quality and optimal user satisfaction from Damco Group, TestingXperts aims at promoting the ethics of connected innovation, thereby seeding the integral values in our employees and achieving unmatched contentment in our clients. To know more about Testingxperts Inc., please visit our website .

If you are interested in the opportunity listed below, please forward your updated resume along with current contact information, or perhaps you can recommend someone who would be interested in this position

Job Title: Cloud Security Engineer

Location: Remote

AWS Organizations guardrails | Terraform and Control Tower AFT | SCP/RCP policy implementation

Experience: 8+ years , Specialization: Security, Risk & Compliance

ROLE SUMMARY

The hands-on cloud security engineer responsible for implementing enterprise AWS security guardrails through

Infrastructure as Code. Authors SCP and RCP policies using Terraform, deploys controls through Control Tower

Account Factory for Terraform (AFT), validates controls in sandbox environments, and supports phased rollout across

organizational units. Designs VPC endpoint and resource-based policies, documents blast-radius impacts, and enables

customer operations teams through runbooks and knowledge transfer.

KEY RESPONSIBILITIES

Author and maintain SCP and RCP policy rule sets using Terraform as the primary delivery mechanism.

Implement security controls through AWS Control Tower Account Factory for Terraform (AFT) pipelines.

Execute validation and testing in sandbox environments and document blast-radius findings before production rollout.

Deploy controls through phased implementation from Sandbox OU to NCZ, DPZ, and Critical Zones.

Design and implement VPC endpoint policies for secure service connectivity.

Build resource-based policies for critical services including logging buckets and AWS KMS keys.

Apply IAM Access Analyzer and AWS Organizations governance capabilities to strengthen least-privilege controls.

Create deployment procedures, operational runbooks, validation evidence, and administration documentation.

Conduct knowledge transfer and operational enablement sessions for the OCC PET team.

Collaborate with cloud security architects and platform teams to translate security policies into deployable AWS controls.

SKILLS REQUIRED

Terraform / IaC

Advanced Terraform development, reusable modules, version-controlled delivery, automated

deployments, and governance controls.

AWS Organizations

Multi-account governance, organizational units, SCP deployment, inheritance models, and

policy rollouts.

Control Tower AFT

Hands-on experience with Account Factory for Terraform, landing zones, and

automation-driven policy deployment.

SCP/RCP Design

Policy authoring, testing, validation, impact analysis, deployment planning, and lifecycle

management.

IAM & Access Analyzer

IAM governance, least privilege design, policy validation, access reviews, and analyzer

capabilities.

VPC Endpoint Policies Implementation of endpoint access controls and private-service connectivity restrictions.

Resource-Based Policies Controls for logging buckets, KMS keys, and critical cloud resources.

Encryption & KMS

Key management, encryption governance, secure access patterns, and protected-data

controls.

Testing & Quality Assurance Sandbox validation, blast-radius assessment, rollout verification, and compliance evidence.

Security Compliance Security, risk, compliance, governance frameworks, and regulated AWS environment controls.

QUALIFICATIONS

Experience - 8+ years in cloud security, AWS governance, Infrastructure as Code, or cloud platform security engineering.

Certification - AWS Certified Security - Specialty preferred.

Core technical requirement - Hands-on Terraform, AWS Organizations, SCPs, IAM Access Analyzer, and VPC endpoint

policy implementation.

Preferred - Control Tower Account Factory for Terraform (AFT) experience.

Delivery capability - Experience testing policies, documenting blast radius, and executing phased enterprise

deployments.

Education - bachelor's degree in computer science, Cybersecurity, Engineering, or equivalent practical experience.

Similar jobs