A large financial institution is building out a cloud security engineering capability and is seeking a Principal-level engineer to become a technical authority for its AWS environment.
This is a hands-on engineering and architecture position for someone who has built cloud security standards rather than simply operated within an established program. You will create reusable security patterns, automate controls through infrastructure as code and delivery pipelines, and help other senior engineers adopt consistent engineering practices.
The role combines architecture, hands-on engineering, automation, technical leadership, data security, and emerging AI security.
RESPONSIBILITIES
Design and implement reusable AWS security standards, templates, and baseline controls.
Establish guardrails across IAM, AWS Organizations, SCPs, account governance, networking, storage, and encryption.
Build security requirements directly into Terraform, CloudFormation, and CI/CD pipelines.
Develop Python automation supporting cloud security controls and engineering workflows.
Architect secure cloud patterns that development and platform teams can consume repeatedly.
Review security-sensitive infrastructure and IAM changes and provide technical guidance to other engineers.
Identify cloud risks independently and drive technical remediation.
Support security architecture for data and emerging AI/ML workloads.
Participate in technical investigation and remediation of cloud security issues.
Role Requirements
Deep hands-on AWS security engineering experience.
Strong understanding of AWS IAM policy design and authorization evaluation.
Experience with AWS Organizations, SCPs, and account-level security controls.