Role: AWS Security Engineer (DevSecOps)
Experience: 7+ years
Location: Remote - anywhere in US and need to support during EST/CST hours
Rate: $70/hr (maximum)
Key Responsibilities
- Design and implement secure AWS architectures following the AWS Well-Architected Framework (Security Pillar).
- Manage and govern IAM, SSO, KMS, CloudTrail, Config, and Security Hub.
- Configure and maintain AWS native security services:
- GuardDuty, Macie, Inspector, Detective, WAF, Shield, and Firewall Manager.
- Build automated security policies and compliance frameworks (CIS, NIST, ISO 27001, PCI DSS).
- Implement encryption at rest and in transit, enforce TLS, and key rotation via KMS.
- Develop and run incident detection, alerting, and response workflows using EventBridge, Lambda, and SNS.
- Integrate AWS Security Hub and GuardDuty findings into SIEM platforms (Splunk, Elastic, etc.).
Systems & Infrastructure Engineering
- Manage and secure Linux/Windows systems running on EC2, EKS, and ECS.
- Build, automate, and maintain infrastructure with Terraform, CloudFormation, or AWS CDK.
- Configure VPCs, subnets, NAT gateways, Transit Gateway, and PrivateLink for secure network segmentation.
- Implement system patching, configuration management, and OS-level hardening (CIS benchmarks).
- Design and manage backups, disaster recovery, and multi-region high availability setups.
- Automate system monitoring, logging, and remediation with CloudWatch, SSM, and Config Rules
DevSecOps
- Integrate security scanning and compliance checks into CI/CD pipelines (GitHub Actions, Jenkins, CodePipeline).
- Automate vulnerability management (ECR image scanning, Inspector, Trivy, or Twistlock).
- Develop infrastructure automation for identity provisioning, logging, and access control.
- Create reusable Terraform modules and templates for AWS accounts and VPCs.
- Implement infrastructure drift detection and self-healing automation.
Monitoring, Audit & Compliance
- Implement centralized log aggregation with CloudWatch Logs, OpenSearch, or SIEM tools.
- Monitor security posture continuously via Security Hub, Config, and GuardDuty dashboards.
- Conduct regular vulnerability scans, penetration testing coordination, and security posture reviews.
- Manage audit readiness and evidence collection for compliance frameworks (SOC2, ISO27001, HIPAA).
- Develop runbooks and playbooks for incident response and operational processes.
Preferred Qualifications
- AWS Certified Security - Specialty (strongly preferred)
- Experience with multi-account AWS Organizations, Control Tower, and Service Control Policies (SCPs)
- Knowledge of container security (EKS, ECS, Bottlerocket, Karpenter)
- Experience with SIEM/SOAR integrations and automated incident response
Exposure to Zero Trust and Network Segmentation design principles
Terms & Conditions for Candidate Portal
Last Updated: May 6th, 2026
Please read these Terms & Conditions ("Agreement", "Terms") carefully before using the Candidate Portal ("Portal", "Service") provided by Yochana IT ("we", "us", "our").
By accessing or registering for the Portal, you ("Candidate", "User", "you", "your") agree to be bound by these Terms.
If you do not agree with any part of these Terms, you may not use the Portal.
- Acceptance of Terms
By accessing or using the Candidate Portal, you affirm that you are at least 18 years old and are legally authorized to enter into this Agreement.
If you are accessing the Portal on behalf of an employer or third party, you represent that you have the authority to bind that entity to these Terms.
- Purpose of Portal
The Portal is provided as a digital platform for Candidates to:
- Create and manage profiles
- Upload resumes, documents, and other professional details
- View and apply for job opportunities
- Track application status
- Communicate with recruiters and client organizations
- Access profile and document-related information
These Terms govern your use of the Portal and all related services.
- User Registration & Account Security
- You agree to provide accurate, complete, and current information during signup.
- You are responsible for maintaining the confidentiality of your account credentials.
- You agree to immediately notify us of any unauthorized use of your account.
- You are responsible for all activities that occur under your account.
- Document Upload & Verification
You understand and agree that:
- All resumes, documents, and information you upload must be true, accurate, and valid
- You are fully responsible for the accuracy and legality of the information you provide
- The Portal may use third-party verification services where applicable
- We reserve the right to reject or remove any document or information that appears invalid or misleading
- Use of Portal Services
You agree to use the Portal in compliance with:
- Applicable laws and regulations
- Professional standards for IT professionals
- Client-specific requirements
- Instructions provided on the Portal
Prohibited actions include, but are not limited to:
- Uploading false or misleading information
- Interfering with Portal operations
- Sharing your credentials or login with others
- Attempting to bypass or manipulate application processes
- Job Application
You acknowledge that:
- Job opportunities displayed on the Portal are not guaranteed of employment.
- Applications are subject to client requirements, screening, and approval.
- Job details (role, location, requirements) are subject to change.
- Profile Accuracy & Updates
- You agree to maintain accurate and up-to-date information in your profile.
- Failure to keep your profile updated may impact your eligibility for job opportunities or result in account restrictions.
- Privacy & Data Use
Your use of the Portal is subject to our Privacy Policy, which describes how we collect, use, and safeguard your personal information.
By using the Portal, you consent to the collection and use of information as described.
- Intellectual Property
All intellectual property contained in or presented through the Portal is owned by us or our licensors.
You may not copy, modify, distribute, or otherwise use any Portal content without express written permission.
- Disclaimer of Warranties
The Portal and all content and services are provided "as is" and "as available."
We make no warranties, express or implied, including:
- Merchantability
- Fitness for a particular purpose
- Accuracy or completeness of information
- Limitation of Liability
To the fullest extent permitted by law, we are not liable for:
- Direct, indirect, incidental, special, or consequential damages
- Loss of data, profits, or business opportunities
- Claims arising from job application outcomes
- Amendments
We may modify these Terms at any time.
Changes will be posted on the Portal with an updated "Last Updated" date.
Your continued use of the Portal after changes indicates your acceptance.
- Termination
We may suspend or terminate your access to the Portal if you violate these Terms or for any reason, with or without notice.