AVP, AWS Security Engineer
Core
Senior cloud security engineer responsible for codifying security controls, managing CSPM tools, and operating as a governance partner across the Cloud Center of Excellence to raise cloud security posture.
Role type
Senior IC cloud security engineer (AWS)
Builds
Secure-by-default AWS landing zones, Terraform modules, and automated control libraries for enterprise application teams.
Domain
Financial services, Cloud Security, Infrastructure as Code
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
AWS multi-account landing zone architecture, Terraform (IaC), Security Hub CSPM, AWS Config conformance packs, incident response, network security controls, policy-as-code, agentic AI tooling integration
Preferred skills
Wiz/Prisma Cloud experience, Service Control Policies (SCPs), NIST/CIS framework translation, AWS networking primitives, Master's degree, GenAI tooling integration
Technologies
AWS, Terraform, Security Hub, AWS Config, Wiz, GitHub Actions, Terraform Cloud, Cursor, Claude Code, Bedrock
Responsibilities
Codify and improve cloud control library using Security Hub and AWS Config; partner with Security Engineering to monitor and resolve Wiz findings; contribute to Account Factory for Terraform (AFT) base layer; support enterprise vulnerability management triage; embed agentic AI capabilities into engineering and governance practices; operate as hands-on senior engineer in code, triage, and incident response; participate in 24x7 on-call rotations; partner with Network Engineering on shared security controls; translate regulatory requirements into automated controls.
Seniority
Senior, hands-on IC