Quick Overview
Job Description
Hello,
My name is Sreeja and I represent TestingXperts Inc. TestingXperts is a Specialist QA & Software Testing Company, and an Independent Software Testing division of Damco Group, which is a leading IT Solutions and Services company working with Fortune Enterprises globally. Inheriting the virtues of job quality and optimal user satisfaction from Damco Group, TestingXperts aims at promoting the ethics of connected innovation, thereby seeding the integral values in our employees and achieving unmatched contentment in our clients. To know more about Testingxperts Inc., please visit our website .
If you are interested in the opportunity listed below, please forward your updated resume along with current contact information, or perhaps you can recommend someone who would be interested in this position
Job Title: Cloud Security Engineer
Location: Remote
AWS Organizations guardrails | Terraform and Control Tower AFT | SCP/RCP policy implementation
Experience: 8+ years , Specialization: Security, Risk & Compliance
ROLE SUMMARY
The hands-on cloud security engineer responsible for implementing enterprise AWS security guardrails through
Infrastructure as Code. Authors SCP and RCP policies using Terraform, deploys controls through Control Tower
Account Factory for Terraform (AFT), validates controls in sandbox environments, and supports phased rollout across
organizational units. Designs VPC endpoint and resource-based policies, documents blast-radius impacts, and enables
customer operations teams through runbooks and knowledge transfer.
KEY RESPONSIBILITIES
Author and maintain SCP and RCP policy rule sets using Terraform as the primary delivery mechanism.
Implement security controls through AWS Control Tower Account Factory for Terraform (AFT) pipelines.
Execute validation and testing in sandbox environments and document blast-radius findings before production rollout.
Deploy controls through phased implementation from Sandbox OU to NCZ, DPZ, and Critical Zones.
Design and implement VPC endpoint policies for secure service connectivity.
Build resource-based policies for critical services including logging buckets and AWS KMS keys.
Apply IAM Access Analyzer and AWS Organizations governance capabilities to strengthen least-privilege controls.
Create deployment procedures, operational runbooks, validation evidence, and administration documentation.
Conduct knowledge transfer and operational enablement sessions for the OCC PET team.
Collaborate with cloud security architects and platform teams to translate security policies into deployable AWS controls.
SKILLS REQUIRED
Terraform / IaC
Advanced Terraform development, reusable modules, version-controlled delivery, automated
deployments, and governance controls.
AWS Organizations
Multi-account governance, organizational units, SCP deployment, inheritance models, and
policy rollouts.
Control Tower AFT
Hands-on experience with Account Factory for Terraform, landing zones, and
automation-driven policy deployment.
SCP/RCP Design
Policy authoring, testing, validation, impact analysis, deployment planning, and lifecycle
management.
IAM & Access Analyzer
IAM governance, least privilege design, policy validation, access reviews, and analyzer
capabilities.
VPC Endpoint Policies Implementation of endpoint access controls and private-service connectivity restrictions.
Resource-Based Policies Controls for logging buckets, KMS keys, and critical cloud resources.
Encryption & KMS
Key management, encryption governance, secure access patterns, and protected-data
controls.
Testing & Quality Assurance Sandbox validation, blast-radius assessment, rollout verification, and compliance evidence.
Security Compliance Security, risk, compliance, governance frameworks, and regulated AWS environment controls.
QUALIFICATIONS
Experience - 8+ years in cloud security, AWS governance, Infrastructure as Code, or cloud platform security engineering.
Certification - AWS Certified Security - Specialty preferred.
Core technical requirement - Hands-on Terraform, AWS Organizations, SCPs, IAM Access Analyzer, and VPC endpoint
policy implementation.
Preferred - Control Tower Account Factory for Terraform (AFT) experience.
Delivery capability - Experience testing policies, documenting blast radius, and executing phased enterprise
deployments.
Education - bachelor's degree in computer science, Cybersecurity, Engineering, or equivalent practical experience.
Similar jobs
- OR
Senior Core Infrastructure Engineer
Oracle Corporation
Austin, TX🇺🇸$79.2k - $209.5k/yrHybrid3 weeks agoOracleEncryptionTechnology - KO
Cloud Network Engineer - W2s Only
NewKollasoft Inc.
Charleston, WV🇺🇸HybridYesterdayAWSLoad BalancingTCP/IP+5Technology - SS
Cloud Engineer
NewStrategic Staffing Solutions
MO🇺🇸On-siteYesterdayDockerAWSLoad Balancing+15Technology - PT
Cloud Network Engineer II
Peterson Technology Partners
Farmington Hills, MI🇺🇸€75/hrHybrid7 weeks agoDockerAWSEncryption+16Technology - KP
IT Infrastructure Engineer
NewKaiser Permanente
Greensboro, North Carolina🇺🇸Hybrid56 minutes agoTechnology - WH
Senior Network Engineer / Architect with Security Clearance
NewWaypoint Human Capital
Honolulu, HI🇺🇸$190k - $225k/yrOn-siteYesterdayiOSTechnology