- Company Name
- Fluent, Inc
- Job Title
- AWS Cloud Security Engineer
- Job Description
-
Job title: AWS Cloud Security Engineer
Role Summary: Design, implement, and manage security controls and monitoring across AWS services to protect infrastructure, enforce least‑privilege IAM, and ensure compliance with SOC 2/ISO 27001.
Expectations: Deliver secure, compliant AWS environments, respond to threats, automate security processes, and collaborate with engineering, DevOps, and third‑party auditors.
Key Responsibilities:
- Architect and maintain security controls for EC2, S3, RDS, EKS, ECS, Lambda, API Gateway, CloudFront, ALB, and VPC networking.
- Configure and optimize GuardDuty, CloudTrail, CloudWatch, Security Hub, AWS Config, and WAF rules.
- Design VPC security architecture, security groups, NACLs, and network segmentation.
- Implement least‑privilege IAM policies, roles, permission boundaries, and integrate AWS Identity Center with Okta.
- Secure containerized and serverless workloads, manage service‑to‑service authentication.
- Monitor alerts, investigate and remediate findings from GuardDuty, CloudTrail, and CSPM tools such as Wiz.
- Develop incident response playbooks and perform threat analysis.
- Implement and secure Databricks workspaces on AWS, supporting SOC 2 and other audits.
- Automate security processes with IaC, scripting, and documentation of runbooks.
- Coordinate with external security vendors, testers, and auditors.
Required Skills:
- 3+ years of AWS security experience; deep knowledge of IAM, GuardDuty, CloudTrail, CloudWatch, Security Hub, Config, VPC, networking, S3, EC2, RDS, EKS, ECS, Lambda, API Gateway, CloudFront, ALB, SQS/SNS.
- Experience with Databricks on AWS and CSPM tools (e.g., Wiz).
- Strong scripting in Python, Bash, or PowerShell for automation.
- Proficiency in federated identity (Okta, SAML, OIDC).
- Understanding of encryption, network security, and security monitoring.
- Experience with SOC 2, ISO 27001, or similar compliance frameworks.
- Problem‑solving and incident response skills.
Required Education & Certifications:
- Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent experience).
- Relevant certifications such as AWS Certified Security – Specialty, AWS Certified Solutions Architect – Associate, or equivalent.