HamburgerMenu
hirist

SipraHub - AWS Cloud Engineer - Network Security & IOM Remediation

Siprahub
10 - 16 Years
Remote

Posted on: 08/07/2026

Job Description

Role : AWS Cloud Engineer(Network Security & IOM Remediation)

Level:- Senior (Individual Contributor)

Experience:- 10 Years to 16 Years

Duration:- Long-term / Ongoing

Location :- Remote

About the Role

We are seeking a contract AWS Cloud Engineer to own the resolution of security findings and Indicators of Misconfiguration (IOMs) across a multi-account AWS environment.


You will architect, harden, and maintain the cloud networking and infrastructure layer - VPCs, Transit Gateways, security groups, IAM policies, and encryption controls - while systematically triaging and remediating findings surfaced by CrowdStrike Falcon Cloud Security, AWS Security Hub, and GuardDuty.

You will partner with a US-based Platform Engineering team (which owns EKS clusters, CI/CD pipelines, and application workloads) to ensure the underlying AWS infrastructure meets security baselines and compliance requirements.


This is a fully remote, long-term contract engagement requiring a minimum of 4 hours daily overlap with US Eastern business hours. Strong written and verbal English communication is essential - you will collaborate daily with US-based engineers and stakeholders via Teams, Jira, and Confluence.

Core Responsibilities :

Security Finding Triage & IOM Remediation :

- Own the full lifecycle of IOMs and security findings: triage, prioritize, remediate, validate, and document across all AWS accounts.

- Remediate misconfigurations across VPCs, security groups, NACLs, S3 bucket policies, IAM roles/policies, encryption settings, and logging configurations.

- Build automated remediation workflows using Lambda, Step Functions, or EventBridge to address recurring finding patterns at scale.

- Perform root cause analysis on IOMs and implement preventive controls (SCPs, Config rules, guardrails) to prevent recurrence.

- Track remediation progress against severity-based SLAs and provide regular reporting to security leadership.

- Coordinate with InfoSec and the CrowdStrike team on finding validation, exception requests, and risk acceptance documentation.

Network Architecture & Security :

- Design and implement secure VPC architectures: subnet segmentation, route tables, NAT gateways, VPC peering, and Transit Gateway topologies across a multi-account AWS Organizations structure.

- Architect and manage network security controls: security groups, NACLs, AWS Network Firewall policies, and prefix list management for hybrid connectivity.

- Implement and maintain hybrid connectivity (Direct Connect, Site-to-Site VPN) with appropriate encryption and access controls.

- Design internal ALB/NLB ingress patterns with proper TLS termination, certificate management (ACM), and origin restriction via security group prefix lists.

- Configure and manage PrivateLink endpoints, VPC endpoint policies, and DNS resolution (Route 53 private/public hosted zones) for secure service access.

- Enforce network segmentation aligned with zero-trust principles - no public-facing resources without explicit approval and compensating controls.

IAM & Access Architecture :

- Design and enforce IAM strategies following least-privilege principles: permission boundaries, SCPs, role trust policies, and condition keys.

- Audit and remediate overly permissive IAM policies, cross-account trust relationships, and unused credentials.

- Implement and maintain OIDC-based authentication patterns for CI/CD runners and workload identities (IRSA for EKS).

- Manage AWS Organizations SCPs and Control Tower guardrails to enforce security baselines across all accounts.

Infrastructure-as-Code & Compliance

- Implement and enforce IaC security standards using Terraform with policy-as-code validation (OPA, Sentinel, cfn-guard, tfsec).

- Author and maintain AWS Config rules and conformance packs for continuous compliance monitoring.

- Build and maintain Terraform modules for secure-by-default infrastructure patterns (VPCs, security groups, IAM roles) that application teams consume.

- Ensure all infrastructure changes flow through code review and automated validation - no manual console changes in production accounts.

Monitoring & Observability :

- Configure and maintain VPC Flow Logs, CloudTrail, DNS query logging, and S3 access logging with centralized analysis (Athena, CloudWatch Logs Insights).

- Build dashboards and alerting for security posture metrics: open finding counts, MTTR trends, compliance drift, and SLA adherence.

- Participate in security incident response related to network intrusion, unauthorized access, or data exfiltration indicators.

- Maintain audit trails and compliance evidence for SOC 2 / PCI workloads as applicable.

Required Technical Skills :

AWS Networking & Architecture :

- Over all 10+ years of IT experience and 5+ years of AWS experience with deep expertise in networking services: VPC, Transit Gateway, Direct Connect, Route 53, ALB/NLB, CloudFront, PrivateLink, and Network Firewall.

- Multi-account AWS Organizations architecture: account vending, centralized networking, shared services patterns, and cross-account resource access.

- Strong understanding of TCP/IP networking, DNS resolution, TLS/mTLS, and network security protocols.

- Practical experience with EKS networking: VPC CNI, security groups for pods, network policies, and ingress controller integration (AWS ALB Controller).

Security & Compliance :

- 3+ years working directly with CSPM tools (CrowdStrike Falcon Cloud Security, AWS Security Hub, or equivalent) and remediating findings at scale (hundreds/thousands of IOMs).

- Hands-on IAM expertise: policy authoring, permission boundaries, SCPs, role trust policies, condition keys, and cross-account access patterns.

- Working knowledge of compliance frameworks (CIS AWS Benchmarks, NIST 800-53, SOC 2) and how they map to specific AWS controls.

- Experience with AWS native security services: GuardDuty, Inspector, Macie, Config, CloudTrail, and Security Hub.

Infrastructure-as-Code :

- Terraform (required): module authoring, state management, workspace patterns, and CI/CD integration for infrastructure pipelines.

- Policy-as-code: OPA/Rego, tfsec, checkov, cfn-guard, or HashiCorp Sentinel for pre-deployment validation.

- Git-based workflows for infrastructure changes with peer review and automated plan/apply patterns.

Automation & Scripting :

- Python or Go for building security automation, remediation lambdas, and custom Config rules.

- Bash scripting for operational automation and runbook implementation.

- Experience with AWS SDK (boto3) and CLI for programmatic infrastructure management.

Communication & Collaboration :

- Professional English proficiency - written and verbal - sufficient for daily technical collaboration with US-based engineers, product managers, and InfoSec stakeholders.

- Availability for a minimum 4-hour daily overlap with US Eastern business hours (8am-6pm EST/EDT); core collaboration windows will be scheduled within this window.

- Comfort working in a distributed, async-first team: proactive written status updates, well-documented pull requests and runbooks, and clear escalation communication.

- Proficiency with standard remote collaboration tooling: Microsoft Teams (chat, video, channels), Jira (ticket tracking and sprint ceremonies), and Confluence (documentation).

- Experience working as an external contractor or vendor resource embedded in a client engineering team; ability to ramp independently with minimal hand-holding.

Preferred / Nice-to-Have :

- AWS Solutions Architect Professional or AWS Security Specialty certification.

- Experience with AWS Network Firewall, Gateway Load Balancer, or third-party NGFW integration (Palo Alto, Fortinet).

- Background in automating security remediation at scale - event-driven architectures that auto-resolve known finding patterns.

- Experience with eBPF-based network observability or runtime security tools.

- Familiarity with Kubernetes security primitives (Pod Security Standards, RBAC, network policies) from an infrastructure perspective.

- Experience working in regulated environments (SOC 2, PCI-DSS, HIPAA) with compliance-as-code tooling.

- Knowledge of DNS security (DNSSEC, DNS firewall, Route 53 Resolver rules) and DDoS mitigation (Shield Advanced, WAF).

Success Metrics (6-12 Months) :

- Critical and high IOMs reduced by 80%+ with documented root cause and preventive controls in place for each resolved finding category.

- Mean time to remediate (MTTR) for critical findings under 72 hours; high findings under 14 days - consistently meeting SLA targets.

- All VPCs, security groups, and IAM roles audited and hardened; zero public-facing resources without explicit approval and compensating controls.

- Secure-by-default Terraform modules published and adopted by platform teams - new infrastructure deploys pre-validated against CIS benchmarks.

- Automated remediation workflows handling 30%+ of recurring finding patterns without manual intervention.

- Continuous compliance dashboards operational with real-time visibility into security posture across all accounts.

- Network architecture documented end-to-end: topology diagrams, connectivity patterns, firewall rules, and data-flow documentation current and maintained.

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...