Posted on: 08/07/2026
Role : AWS Cloud Engineer(Network Security & IOM Remediation)
Level:- Senior (Individual Contributor)
Experience:- 10 Years to 16 Years
Duration:- Long-term / Ongoing
Location :- Remote
About the Role
We are seeking a contract AWS Cloud Engineer to own the resolution of security findings and Indicators of Misconfiguration (IOMs) across a multi-account AWS environment.
You will architect, harden, and maintain the cloud networking and infrastructure layer - VPCs, Transit Gateways, security groups, IAM policies, and encryption controls - while systematically triaging and remediating findings surfaced by CrowdStrike Falcon Cloud Security, AWS Security Hub, and GuardDuty.
You will partner with a US-based Platform Engineering team (which owns EKS clusters, CI/CD pipelines, and application workloads) to ensure the underlying AWS infrastructure meets security baselines and compliance requirements.
This is a fully remote, long-term contract engagement requiring a minimum of 4 hours daily overlap with US Eastern business hours. Strong written and verbal English communication is essential - you will collaborate daily with US-based engineers and stakeholders via Teams, Jira, and Confluence.
Core Responsibilities :
Security Finding Triage & IOM Remediation :
- Own the full lifecycle of IOMs and security findings: triage, prioritize, remediate, validate, and document across all AWS accounts.
- Remediate misconfigurations across VPCs, security groups, NACLs, S3 bucket policies, IAM roles/policies, encryption settings, and logging configurations.
- Build automated remediation workflows using Lambda, Step Functions, or EventBridge to address recurring finding patterns at scale.
- Perform root cause analysis on IOMs and implement preventive controls (SCPs, Config rules, guardrails) to prevent recurrence.
- Track remediation progress against severity-based SLAs and provide regular reporting to security leadership.
- Coordinate with InfoSec and the CrowdStrike team on finding validation, exception requests, and risk acceptance documentation.
Network Architecture & Security :
- Design and implement secure VPC architectures: subnet segmentation, route tables, NAT gateways, VPC peering, and Transit Gateway topologies across a multi-account AWS Organizations structure.
- Architect and manage network security controls: security groups, NACLs, AWS Network Firewall policies, and prefix list management for hybrid connectivity.
- Implement and maintain hybrid connectivity (Direct Connect, Site-to-Site VPN) with appropriate encryption and access controls.
- Design internal ALB/NLB ingress patterns with proper TLS termination, certificate management (ACM), and origin restriction via security group prefix lists.
- Configure and manage PrivateLink endpoints, VPC endpoint policies, and DNS resolution (Route 53 private/public hosted zones) for secure service access.
- Enforce network segmentation aligned with zero-trust principles - no public-facing resources without explicit approval and compensating controls.
IAM & Access Architecture :
- Design and enforce IAM strategies following least-privilege principles: permission boundaries, SCPs, role trust policies, and condition keys.
- Audit and remediate overly permissive IAM policies, cross-account trust relationships, and unused credentials.
- Implement and maintain OIDC-based authentication patterns for CI/CD runners and workload identities (IRSA for EKS).
- Manage AWS Organizations SCPs and Control Tower guardrails to enforce security baselines across all accounts.
Infrastructure-as-Code & Compliance
- Implement and enforce IaC security standards using Terraform with policy-as-code validation (OPA, Sentinel, cfn-guard, tfsec).
- Author and maintain AWS Config rules and conformance packs for continuous compliance monitoring.
- Build and maintain Terraform modules for secure-by-default infrastructure patterns (VPCs, security groups, IAM roles) that application teams consume.
- Ensure all infrastructure changes flow through code review and automated validation - no manual console changes in production accounts.
Monitoring & Observability :
- Configure and maintain VPC Flow Logs, CloudTrail, DNS query logging, and S3 access logging with centralized analysis (Athena, CloudWatch Logs Insights).
- Build dashboards and alerting for security posture metrics: open finding counts, MTTR trends, compliance drift, and SLA adherence.
- Participate in security incident response related to network intrusion, unauthorized access, or data exfiltration indicators.
- Maintain audit trails and compliance evidence for SOC 2 / PCI workloads as applicable.
Required Technical Skills :
AWS Networking & Architecture :
- Over all 10+ years of IT experience and 5+ years of AWS experience with deep expertise in networking services: VPC, Transit Gateway, Direct Connect, Route 53, ALB/NLB, CloudFront, PrivateLink, and Network Firewall.
- Multi-account AWS Organizations architecture: account vending, centralized networking, shared services patterns, and cross-account resource access.
- Strong understanding of TCP/IP networking, DNS resolution, TLS/mTLS, and network security protocols.
- Practical experience with EKS networking: VPC CNI, security groups for pods, network policies, and ingress controller integration (AWS ALB Controller).
Security & Compliance :
- 3+ years working directly with CSPM tools (CrowdStrike Falcon Cloud Security, AWS Security Hub, or equivalent) and remediating findings at scale (hundreds/thousands of IOMs).
- Hands-on IAM expertise: policy authoring, permission boundaries, SCPs, role trust policies, condition keys, and cross-account access patterns.
- Working knowledge of compliance frameworks (CIS AWS Benchmarks, NIST 800-53, SOC 2) and how they map to specific AWS controls.
- Experience with AWS native security services: GuardDuty, Inspector, Macie, Config, CloudTrail, and Security Hub.
Infrastructure-as-Code :
- Terraform (required): module authoring, state management, workspace patterns, and CI/CD integration for infrastructure pipelines.
- Policy-as-code: OPA/Rego, tfsec, checkov, cfn-guard, or HashiCorp Sentinel for pre-deployment validation.
- Git-based workflows for infrastructure changes with peer review and automated plan/apply patterns.
Automation & Scripting :
- Python or Go for building security automation, remediation lambdas, and custom Config rules.
- Bash scripting for operational automation and runbook implementation.
- Experience with AWS SDK (boto3) and CLI for programmatic infrastructure management.
Communication & Collaboration :
- Professional English proficiency - written and verbal - sufficient for daily technical collaboration with US-based engineers, product managers, and InfoSec stakeholders.
- Availability for a minimum 4-hour daily overlap with US Eastern business hours (8am-6pm EST/EDT); core collaboration windows will be scheduled within this window.
- Comfort working in a distributed, async-first team: proactive written status updates, well-documented pull requests and runbooks, and clear escalation communication.
- Proficiency with standard remote collaboration tooling: Microsoft Teams (chat, video, channels), Jira (ticket tracking and sprint ceremonies), and Confluence (documentation).
- Experience working as an external contractor or vendor resource embedded in a client engineering team; ability to ramp independently with minimal hand-holding.
Preferred / Nice-to-Have :
- AWS Solutions Architect Professional or AWS Security Specialty certification.
- Experience with AWS Network Firewall, Gateway Load Balancer, or third-party NGFW integration (Palo Alto, Fortinet).
- Background in automating security remediation at scale - event-driven architectures that auto-resolve known finding patterns.
- Experience with eBPF-based network observability or runtime security tools.
- Familiarity with Kubernetes security primitives (Pod Security Standards, RBAC, network policies) from an infrastructure perspective.
- Experience working in regulated environments (SOC 2, PCI-DSS, HIPAA) with compliance-as-code tooling.
- Knowledge of DNS security (DNSSEC, DNS firewall, Route 53 Resolver rules) and DDoS mitigation (Shield Advanced, WAF).
Success Metrics (6-12 Months) :
- Critical and high IOMs reduced by 80%+ with documented root cause and preventive controls in place for each resolved finding category.
- Mean time to remediate (MTTR) for critical findings under 72 hours; high findings under 14 days - consistently meeting SLA targets.
- All VPCs, security groups, and IAM roles audited and hardened; zero public-facing resources without explicit approval and compensating controls.
- Secure-by-default Terraform modules published and adopted by platform teams - new infrastructure deploys pre-validated against CIS benchmarks.
- Automated remediation workflows handling 30%+ of recurring finding patterns without manual intervention.
- Continuous compliance dashboards operational with real-time visibility into security posture across all accounts.
- Network architecture documented end-to-end: topology diagrams, connectivity patterns, firewall rules, and data-flow documentation current and maintained.
Did you find something suspicious?
Posted by
Posted in
DevOps / SRE
Functional Area
IT Security
Job Code
1652304