AWS Security Engineer (DevSecOps)

YOCHANA IT SOLUTIONS, INC.
  • NY
  • Remote
  • $70 Per Hour
1 day ago

Job Description

Role: AWS Security Engineer (DevSecOps)

Experience: 7+ years

Location: Remote - anywhere in US and need to support during EST/CST hours

Rate: $70/hr (maximum)

Key Responsibilities

  • Design and implement secure AWS architectures following the AWS Well-Architected Framework (Security Pillar).
  • Manage and govern IAM, SSO, KMS, CloudTrail, Config, and Security Hub.
  • Configure and maintain AWS native security services:
  • GuardDuty, Macie, Inspector, Detective, WAF, Shield, and Firewall Manager.
  • Build automated security policies and compliance frameworks (CIS, NIST, ISO 27001, PCI DSS).
  • Implement encryption at rest and in transit, enforce TLS, and key rotation via KMS.
  • Develop and run incident detection, alerting, and response workflows using EventBridge, Lambda, and SNS.
  • Integrate AWS Security Hub and GuardDuty findings into SIEM platforms (Splunk, Elastic, etc.).

Systems & Infrastructure Engineering

  • Manage and secure Linux/Windows systems running on EC2, EKS, and ECS.
  • Build, automate, and maintain infrastructure with Terraform, CloudFormation, or AWS CDK.
  • Configure VPCs, subnets, NAT gateways, Transit Gateway, and PrivateLink for secure network segmentation.
  • Implement system patching, configuration management, and OS-level hardening (CIS benchmarks).
  • Design and manage backups, disaster recovery, and multi-region high availability setups.
  • Automate system monitoring, logging, and remediation with CloudWatch, SSM, and Config Rules

DevSecOps

  • Integrate security scanning and compliance checks into CI/CD pipelines (GitHub Actions, Jenkins, CodePipeline).
  • Automate vulnerability management (ECR image scanning, Inspector, Trivy, or Twistlock).
  • Develop infrastructure automation for identity provisioning, logging, and access control.
  • Create reusable Terraform modules and templates for AWS accounts and VPCs.
  • Implement infrastructure drift detection and self-healing automation.

Monitoring, Audit & Compliance

  • Implement centralized log aggregation with CloudWatch Logs, OpenSearch, or SIEM tools.
  • Monitor security posture continuously via Security Hub, Config, and GuardDuty dashboards.
  • Conduct regular vulnerability scans, penetration testing coordination, and security posture reviews.
  • Manage audit readiness and evidence collection for compliance frameworks (SOC2, ISO27001, HIPAA).
  • Develop runbooks and playbooks for incident response and operational processes.

Preferred Qualifications

  • AWS Certified Security - Specialty (strongly preferred)
  • Experience with multi-account AWS Organizations, Control Tower, and Service Control Policies (SCPs)
  • Knowledge of container security (EKS, ECS, Bottlerocket, Karpenter)
  • Experience with SIEM/SOAR integrations and automated incident response

Exposure to Zero Trust and Network Segmentation design principles

Numbers & Facts

LocationNY (
Remote
)

Skills

  • AWS Lambdaunmatched
  • Access Controlunmatched
  • Amazon Elastic Compute Cloud (EC2)unmatched
  • Amazon Web Services (AWS)unmatched
  • Auditingunmatched
  • Automationunmatched
  • Benchmarkingunmatched
  • Change Order Managementunmatched
  • Computer Securityunmatched
  • Configuration Managementunmatched
  • Continuous Deployment/Deliveryunmatched
  • Continuous Integrationunmatched
  • Cryptographyunmatched
  • Data Recoveryunmatched
  • Disaster Recoveryunmatched
  • GitHubunmatched
  • HIPAA (Health Insurance Portability and Accountability Act)unmatched
  • High Availabilityunmatched
  • Hyperion Pillarunmatched
  • ISO (International Organization for Standardization)unmatched
  • Incident Responseunmatched
  • Jenkinsunmatched
  • Linux Operating Systemunmatched
  • Maintain Complianceunmatched
  • Microsoft Windows Operating Systemunmatched
  • NAT (Network Address Translation)unmatched
  • Network Designunmatched
  • Operations Processesunmatched
  • PCI-DSSunmatched
  • Penetration Testingunmatched
  • Policy Developmentunmatched
  • Protective Servicesunmatched
  • Reporting Dashboardsunmatched
  • SSL-TLS (Secure Socket Layer - Transport Layer Security)unmatched
  • Security Architectureunmatched
  • Security Information and Event Management (SIEM)unmatched
  • Security Monitoringunmatched
  • Single Sign-On (SSO)unmatched
  • Software Patchesunmatched
  • Splunkunmatched
  • Subnetunmatched
  • Systems Administration/Managementunmatched
  • U.S. National Institute of Standards and Technology (NIST)unmatched
  • Vulnerability Scannersunmatched

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

Level up your application

Professional resume templates

Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

Free resume templates

Free resume builder

Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

Free resume builder