Security & Compliance Engineer, AWS Security Assurance Services, LLC
Core
Design, build, and deploy AWS security and compliance solutions for highly regulated customers, translating frameworks like SOC2, HIPAA, and PCI-DSS into secure-by-design implementations.
Role type
Senior IC Security & Compliance Engineer (Cloud Infrastructure)
Builds
Custom preventive/detective controls, IaC controls for Landing Zones/Zero-Trust, automated compliance monitoring pipelines, and security tooling integrations.
Domain
Cloud Security & Compliance (AWS)
Deliverable
production ML models | product features | infrastructure
Required skills
Python, Terraform, AWS CDK, CloudFormation, Rego, threat modeling, risk identification, policy-as-code, AWS security services (IAM, KMS, VPC, Config, Security Hub), networking protocols (HTTP, DNS, TCP/IP)
Preferred skills
TypeScript, Node.js, Go, Java, .NET, AWS Control Tower, Zero-Trust architecture design, CI/CD pipeline design for security, audit evidence production, MCP experience, industry certifications (CISSP, AWS Security Specialty)
Technologies
AWS (Control Tower, Landing Zones, SCPs, RCPs, Config, Security Hub, IAM, KMS, VPC, Lambda, CloudTrail, CloudWatch/EventBridge), cfn-guard, OPA, Cedar, Python, Terraform, AWS CDK, CloudFormation, Rego
Responsibilities
Lead threat modeling and security design reviews; design and implement custom controls (SCPs, RCPs, policy-as-code); build secure-by-design IaC controls; write and review IaC/scripts in Python/Terraform; build continuous compliance monitoring and evidence collection pipelines; integrate custom controls with AWS-native and third-party tooling; identify risks and propose compensating controls; develop technical content; travel to customer sites as needed.
Seniority
Senior, hands-on IC