- Company Name
- InvitISE Ltd
- Job Title
- AWS Security Engineer
- Job Description
-
**Job title:** AWS Security Engineer
**Role Summary:**
Execute end‑to‑end remediation of cloud and application vulnerabilities in AWS environments. Collaborate with Developers, Data Engineers and the AWS Security Lead to validate findings, prioritize risk, implement secure fixes, and reinforce AWS security controls.
**Expectations:**
- Deliver high‑quality remediation within a 3–6 month contract.
- Operate in a hybrid setting, attending the office 3 days per week (outside IR35).
- Own issues from discovery to resolution, ensuring consistent application of security best practices.
**Key Responsibilities:**
- Configure and manage IAM, VPC segmentation, private endpoints, WAF/Shield, KMS, secrets management, and logging.
- Operate AWS Security Hub, GuardDuty, Inspector, Config, and Access Analyzer.
- Remediate vulnerabilities in OS packages, containers, libraries, serverless runtimes, and misconfigured cloud resources.
- Implement CI/CD and DevSecOps practices: shift‑left reviews, dependency management, pipeline guardrails.
- Secure Infrastructure as Code with Terraform and/or CloudFormation.
- Automate remediation and control validation using Python or Bash scripts.
- Use scanning tools such as Inspector, Snyk, Trivy, Dependabot, Prisma, or Tenable.
**Required Skills:**
- Deep hands‑on AWS security (IAM, networking, compute, storage, serverless).
- Security controls: least privilege, VPC segmentation, private endpoints, WAF/Shield, KMS, secrets management, logging.
- Experience with AWS Security Hub, GuardDuty, Inspector, Config, Access Analyzer.
- Vulnerability remediation across OS/packages, containers, libraries, serverless runtimes, cloud misconfigurations.
- CI/CD and DevSecOps: shift-left, dependency management, pipeline guardrails.
- IaC security with Terraform and/or CloudFormation.
- Automation scripting in Python or Bash.
- Familiarity with scanning tools: Inspector, Snyk, Trivy, Dependabot, Prisma/Tenable.
**Nice to have:**
- AWS Security Specialty or Solutions Architect certification.
- Container/serverless security experience.
- Policy‑as‑code tools (OPA, Conftest).
**Required Education & Certifications:**
- Bachelor's degree in Computer Science, Information Security, or related field, or equivalent professional experience.
- Valid AWS Security Specialty certification preferred (not mandatory but advantageous).