Eclipsos Corp is an AWS Select Tier Services Partner focused on AWS security architecture, Zero Trust, and secure cloud modernization. They are looking for an experienced AWS Cloud Security Engineer to assess, design, and secure AWS environments, emphasizing a hands-on technical role that incorporates Zero Trust principles and AWS-native security controls.
Responsibilities:
- Conduct technical security assessments of AWS environments
- Identify security misconfigurations, excessive privilege, implicit trust relationships, unnecessary network paths, and architectural risks
- Evaluate AWS environments across identity, network, workloads, data protection, logging, detection, and governance
- Review multi-account AWS architectures and AWS Organizations configurations
- Assess security controls against AWS security best practices and Zero Trust principles
- Document findings based on technical evidence and business risk
- Help develop security gap analyses, remediation roadmaps, and architecture recommendations
- Evaluate trust relationships between users, workloads, AWS services, accounts, and data
- Identify and reduce unnecessary blast radius within AWS environments
- Design architectures based on least privilege and explicit authorization
- Engineer identity and workload trust boundaries using AWS-native security controls
- Apply Zero Trust principles to human-to-application, workload-to-workload, and service-to-service communication
- Design network segmentation and micro-segmentation strategies appropriate to AWS workloads
- Translate Zero Trust principles into practical and implementable AWS controls
- Review and design AWS IAM architectures
- Analyze IAM roles, policies, trust policies, and cross-account access
- Implement and review RBAC and ABAC patterns
- Design and evaluate permission boundaries
- Review Service Control Policies (SCPs) and Resource Control Policies (RCPs)
- Identify excessive permissions and privilege escalation risks
- Evaluate federated access and AWS IAM Identity Center architectures
- Apply least privilege principles to human and machine identities
- Review VPC architectures, subnet segmentation, route tables, and connectivity patterns
- Assess Security Groups and Network ACL configurations
- Identify unnecessary communication paths and lateral movement risks
- Design secure workload connectivity and service-to-service communication
- Evaluate AWS PrivateLink, VPC endpoints, AWS Verified Access, and Amazon VPC Lattice where appropriate
- Assess and secure Amazon EC2, serverless, containerized, and Kubernetes workloads
- Review Amazon EKS security controls, including IAM integration, Kubernetes RBAC, pod security, network policies, and workload identity
- Assess AWS data protection architectures
- Review AWS KMS key architectures, key policies, grants, and rotation strategies
- Evaluate encryption controls for AWS services including Amazon S3, Amazon RDS, DynamoDB, and other AWS workloads
- Identify inappropriate data access paths and overly permissive resource policies
- Help establish secure encryption and key management baselines
- Review AWS CloudTrail, AWS Config, Amazon GuardDuty, AWS Security Hub, and related AWS-native security services
- Evaluate logging coverage and security visibility across AWS accounts and Regions
- Identify gaps in threat detection and security monitoring
- Assist with the design of centralized security and logging architectures
- Support the implementation of scalable AWS security guardrails
- Help automate security controls and remediation where appropriate
- Review and develop secure Infrastructure as Code using Terraform, AWS CloudFormation, or AWS CDK
- Integrate security controls into CI/CD pipelines
- Identify security risks within deployment and automation workflows
- Support policy-as-code and automated security validation
- Use scripting and automation to improve security assessment and remediation processes
- Participate in technical discovery sessions and AWS security workshops
- Conduct technical interviews with client engineering and cloud teams
- Clearly explain security risks and architectural findings
- Contribute to architecture diagrams, technical reports, security roadmaps, and remediation plans
- Present technical recommendations to engineering and technical leadership teams
- Support Eclipsos architects during client engagements and technical pre-sales discussions
Requirements:
- Minimum of 5 years of hands-on AWS experience designing, operating, or securing AWS environments
- Strong understanding of AWS security architecture and cloud security principles
- Deep knowledge of AWS IAM, including policies, roles, trust policies, federation, and cross-account access
- Strong understanding of AWS networking, including VPCs, subnets, route tables, Security Groups, NACLs, VPC endpoints, and private connectivity
- Hands-on experience with AWS Organizations and multi-account environments
- Experience with AWS-native security services such as AWS CloudTrail, AWS Config, Amazon GuardDuty, and AWS Security Hub
- Strong understanding of encryption and AWS KMS
- Experience with Infrastructure as Code using Terraform, AWS CloudFormation, or AWS CDK
- Familiarity with DevSecOps and CI/CD security practices
- Scripting or automation experience using Python, Bash, or PowerShell
- Ability to analyze complex AWS environments and identify architectural security risks
- Strong technical documentation and communication skills
- Ability to communicate in English and Spanish
- Experience conducting AWS security assessments or architecture reviews
- Experience implementing Zero Trust principles in cloud environments
- Knowledge of threat modeling and cloud security risk analysis
- Familiarity with the AWS Well-Architected Framework and Security Pillar
- Knowledge of CIS AWS Foundations Benchmark
- Experience mapping security controls to frameworks such as NIST, CIS, SOC 2, or HIPAA
- Experience securing Amazon EKS or other Kubernetes environments
- Familiarity with CSPM, CNAPP, or cloud security posture management technologies
- Experience working directly with customers or technical stakeholders
- Preferred certifications include: AWS Certified Security – Specialty, AWS Certified Solutions Architect – Professional, AWS Certified Solutions Architect – Associate, CISSP, CCSP, CCSK