- Company Name
- Ampstek
- Job Title
- SWA Cybersecurity Consultant with AWS infrastructure
- Job Description
-
Job title: SWA Cybersecurity Consultant with AWS infrastructure
Role Summary:
Provide expert design, deployment, and management of secure AWS environments, integrating cloud-native security tools, CI/CD security workflows, and compliance controls for cloud‑native and containerized applications.
Expectations:
Deliver secure, scalable AWS infrastructures that meet regulatory standards (NIST 800‑53, PCI‑DSS, SOX) while maintaining operational agility. Ensure continuous security monitoring, automation, and documentation.
Key Responsibilities:
- Design, implement, and manage AWS services (EC2, S3, IAM, Lambda, CloudFormation).
- Harden cloud workloads: IAM policies, KMS encryption, GuardDuty, Config, CloudTrail, WAF.
- Integrate security tooling (SAST, SCA, IaC scanning) into CI/CD pipelines (GitLab, GitHub Actions).
- Deploy and operationalize CNAPP/CSPM solutions (Wiz, Orca, Prisma Cloud, AWS equivalents).
- Automate security workflows with scripting (Python, Bash, JavaScript, Go) and AWS services (Lambda, Step Functions).
- Analyze AWS logs (CloudTrail, VPC Flow Logs) for threat detection and incident response.
- Manage change control, documentation, and audit readiness.
- Participate in Agile ceremonies: sprint planning, retrospectives, iterative delivery.
- Collaborate with security operations and service management (ServiceNow, CMDB) for incident ticketing and asset visibility.
Required Skills:
- 2–3 years AWS infrastructure experience (EC2, S3, IAM, Lambda, CloudFormation).
- Strong grasp of cloud security fundamentals (identity, encryption, network, threat detection).
- Knowledge of OWASP Top 10, defense‑in‑depth, least privilege, secure authentication/authorization.
- Familiarity with NIST 800‑53, PCI‑DSS, SOX in cloud contexts.
- Experience with AWS security services (IAM, KMS, GuardDuty, Config, CloudTrail, WAF).
- Integration of SAST/SCA/IaC scanning into CI/CD.
- Working knowledge of CNAPP/CSPM tools (Wiz, Orca, Prisma Cloud, AWS native).
- Proficiency in at least one scripting language (Python, Bash, JavaScript, Go).
- Documentation, auditability, and change‑management skills.
- Independent work, prioritization, and minimal supervision.
Required Education & Certifications:
- Bachelor’s degree in Computer Science, Information Security, or related field.
- AWS Certified Security – Specialty or equivalent preferred.
- Certifications in security frameworks (e.g., CISSP, CISM) are advantageous.