Lead hands-on remediation of AWS cloud security vulnerabilities, misconfigurations, compliance gaps, and platform risks across production and non-production environments.
Review security findings from AWS-native and enterprise security tools, determine remediation approach, implement fixes, and validate successful closure.
Communicate architectural decisions, remediation plans, goals, strategies, and short-term trade-offs versus long-term commitments, risk reduction, and cost impacts.
Engage in and improve the end-to-end lifecycle of cloud services, starting from inception and design through deployment, operations, monitoring, and continuous security improvement.
Establish automation capabilities leveraging AWS-native services, infrastructure as code, policy as code, and CI/CD pipelines to improve developer experience and reduce recurring vulnerabilities.
Support activities including system design consulting, secure platform engineering, software platforms and frameworks, capacity planning, launch reviews, and operational readiness reviews.
Troubleshoot difficult cloud security, infrastructure, and application platform issues and engage customers and stakeholders to drive timely remediation.
Learn and apply new AWS services, security capabilities, and engineering practices as required.
Improve system scalability, sustainability, reliability, and security through automation, repeatable patterns, and engineering standards.
Support enterprise cloud transformation, migration, modernization, and security posture improvement efforts.
Guide customers on cloud-native design, secure architecture patterns, AWS security controls, and platform guardrails.
Provide consultation on technology infrastructure planning, security remediation, and engineering for assigned systems; assess the implications of technology strategies on infrastructure capabilities and risk posture.
Establish strategies to migrate legacy applications to secure, cloud-native patterns, including microservices hosted on AWS Cloud.
Leverage cloud-native architecture components including containers, immutable infrastructure, microservices, service mesh, serverless capabilities, and managed AWS services to build highly available, fault-tolerant, and secure applications.
Conduct research on global technology, cloud security, and platform engineering trends and their applicability to FEPOC products in support of internal development teams and business initiatives.
Promote modern application design, engineering best practices, secure-by-design patterns, vulnerability mitigation, and lifecycle risk management.
Monitor and manage stability, availability, performance, and security of enterprise systems and platforms across IT domains.
Analyze systems, network, storage, cloud, and security telemetry to identify problems, trends, vulnerabilities, and opportunities for improvement.
Automate end-to-end processes to maintain, patch, upgrade, harden, and secure the AWS cloud ecosystem.
Make data-driven recommendations and decisions that improve the overall efficacy, efficiency, security, and reliability of software delivery and cloud platform capabilities.
Mentor peers and engage across teams to socialize solutions, improve security practices, and increase engineering maturity.
Requirements:
Strong skills are desired in each of the following areas:
Cloud Security and Vulnerability Remediation: AWS security services, vulnerability management, configuration compliance, security guardrails, threat detection, IAM hardening, encryption, logging, monitoring, patching, and secure cloud engineering.
Development: Experience programming with one or more languages, including Python, Java, Groovy, or Go.
IaC Tools for Platform Automation: Strong skills and experience in at least one of the following: Ansible, Terraform, AWS CloudFormation, or AWS CDK.
Containers: Docker or other OCI-certified containers is a plus.
Container Orchestration Platform: Experience with Kubernetes, AWS EKS, or AWS ECS is a plus.
CNI Plugins: Calico, Flannel, Weave Net, or similar technologies.
Service Mesh: Istio, AWS App Mesh, OpenShift Service Mesh, or similar technologies.
Container Security Tools: Twist lock, Sysdig, Aqua, Prisma Cloud, or similar tools is a plus.
Platform Monitoring, Observability, & Performance Tools: Nginx, New Relic, AppDynamics, Datadog, Thanos, Jaeger, LogDNA, CloudWatch, CloudTrail, AWS Config, and related observability tools.
DevOps Tools: Git/Repo, Crucible, Bitbucket, Jira, Ansible, Puppet, Jenkins, ArgoCD, Bamboo, Maven, Artifactory, Nexus, and related tools.
Other Required Skills:
Understanding of cloud-native architecture and secure-by-design engineering principles.
Linux, shell scripting, and general administration skills.
Cloud, security, and DevOps certifications, including AWS certification.
Knowledge, Skills, and Abilities (KSAs)
Knowledge of programming languages, scripting, automation, cloud security, vulnerability remediation, and web-based technologies.
Ability to collaborate across teams to solve technical, operational, and security problems.
Expert - Excellent communication skills, both written and verbal.
Expert - The incumbent is required to immediately disclose any debarment, exclusion, or other event that makes them ineligible to perform work directly or indirectly on Client programs.
Must be able to effectively work in a fast-paced environment with frequently changing priorities, deadlines, and workloads that can be variable for long periods of time.
Must be able to meet established deadlines and handle multiple customer service demands from internal and external customers, within set expectations for service excellence.
Must be able to effectively communicate and provide positive customer service to every internal and external customer, including customers who may be demanding or otherwise challenging.
Licenses/Certifications
AWS Cloud certification, minimum of one, is required.
AWS Certified Security – Specialty, AWS Certified Solutions Architect, AWS Certified SysOps Administrator, or AWS Certified DevOps Engineer is preferred