AWS Cloud Security Engineer

ON.energy

Argentina

Presencial

ARS 136.147.000 - 196.657.000

Jornada completa

Hace 2 días
Sé de los primeros/as/es en solicitar esta vacante

Recibe más respuestas de empleadores

Envía un currículum específico para el puesto de trabajo en cuestión de minutos.

Descripción de la vacante

ON.energy is revolutionizing energy and AI infrastructure with hyperscale power systems and secure, resilient data centers worldwide. This senior security role focuses on cloud security in multi-account AWS environments, delivering infrastructure as code and rigorous identity controls.

You will own security tooling, threat detection, and site-to-cloud connectivity, partnering with IT and OT teams to protect critical facilities and data across global campuses.

Formación

  • 5+ years in cloud security or cloud operations with deep AWS hands-on experience.
  • Production experience in multi-account AWS environments.
  • Ability to map intrusion paths and explain detection/mitigation steps.
  • Strong English (B2-C1) for daily work and security documentation.
  • Experience with IAM Identity Center and external IdP integrations.

Responsabilidades

  • Design and implement multi-account AWS security foundations using infrastructure as code.
  • Enforce security standards and review gates to block risky changes.
  • Manage AWS identity and access using IAM Identity Center and Entra ID.
  • Own cloud-to-site connectivity and segmentation between IT and OT.
  • Develop threat detection, monitoring, and mitigation using GuardDuty, Detective, Security Hub, etc.
  • Lead vulnerability management across workloads and dependencies.

Conocimientos

Cloud security
AWS
Security infrastructure
Networking security
English (B2-C1)

Herramientas

AWS
CDK
CloudFormation
Terraform
GuardDuty

Descripción del empleo

ON.energyis building the backbone of energy and AI infrastructure powering grid-safe data centers and mission-critical facilities. The company supplies and operates hyperscale power systems that solve the toughest resilience challenges, delivering custom solutions for AI data centers, mission-critical facilities, and front-of-the-meter assets. ON recently announced a 5GW partnership, with 3GW currently under construction across multiple hyperscale data center campuses. With patented technology and proprietary software,ON.energydevelops projects worldwide that set new benchmarks for resilience.

Key Responsibilities
  • The multi-account security foundation. AWS Organizations structure, SCPs, guardrails, a security tooling account, centralized logging, and secure baselines — delivered as infrastructure as code, not console clicks.
  • Security standards and review gates. You can mandate controls and block deploys that introduce unacceptable risk, through review gates on identity and network changes, a documented exception path, and a defined escalation route.
  • AWS identity and access. IAM Identity Center as the single front door, federated with Entra ID in partnership with IT, who own Entra as the source of truth. Role and group model mapping job functions to permissions; joiner/mover/leaver; privileged and break-glass access; workload identity; recurring access reviews. Hands-on at first, progressively automated so it stops being manual work.
  • Cloud-to-site connectivity and segmentation — the defining part of this role. Every plant, BESS site, and remote asset that reaches our cloud does so over a path you design and defend: site-to-cloud VPN and private connectivity, hard segmentation between IT and OT zones, DMZ and broker patterns for site telemetry, certificate and device identity for field gateways, remote vendor access to sites, and strict control over what may initiate traffic in each direction. You own the cloud side of that boundary and share the path itself with the OT security owner.
  • Threat detection, monitoring, and mitigation. You are expected to know how attacks actually run — credential and token abuse, cross-account privilege escalation, exposed control and management interfaces, lateral movement from a compromised site network into cloud, supply-chain and dependency compromise, ransomware staging — and to build the monitoring that catches them. GuardDuty, Security Hub, Detective, Inspector, Config, and CloudTrail tuned for real signal-to-noise, detections mapped to MITRE ATT&CK and ATT&CK for IC... runbooks the wider team can execute, and the mitigations driven to done.
  • Vulnerability management. Scanning coverage across workloads, images, and dependencies; risk-based triage and prioritization; remediation SLAs and exception handling; posture reporting. You identify and prioritize; the AWS engineers remediate in the workloads they own.
Key Requirements
  • 5+ years in cloud security, security-focused infrastructure, or cloud operations, with deep hands-on AWS.
  • Production experience in multi-account AWS environments.
  • Demonstrable command of attacker techniques and the detections and mitigations that counter them — you can walk an intrusion path end to end and explain how you would catch it, contain it, and close it.
  • Hybrid and site-to-cloud network security: segmentation, VPN, private connectivity, firewalls, routing, DNS, CIDR and subnetting — securing connections between cloud and physical facilities.
  • Strong AWS identity: roles, policies, permission sets, MFA, least privilege, access reviews; IAM Identity Center federated with an external IdP, ideally Microsoft Entra ID.
  • AWS-native security services: GuardDuty, Detective, Security Hub, Inspector, Config, CloudTrail, KMS, WAF.
  • Infrastructure as code — CDK, CloudFormation, or Terraform. You build controls, you don't click them.
  • Advanced English (B2–C1) for daily work with English-speaking teams and written security documentation.
Preferred Qualifications
  • Security experience in OT- or IC... environments: IT/OT segmentation, Purdue-model zoning, secure remote access to field sites, and protocols such as Modbus, DNP3, OPC UA, or MQTT crossing into cloud.
  • Detection engineering and SIEM work; threat modelling; incident response you have personally run.
  • Regulated or compliance-driven environments where access control, monitoring, and audit evidence are held to an external standard.
  • Turning scanner output and audit findings into prioritized, actionable work for engineers who do not report to you.
  • Troubleshooting security, identity, networking, and infrastructure issues across cloud and hybrid environments.
  • Landing zones, Control Tower, and security account patterns.
  • IEC 62443 or NIST SP 800-82 familiarity.
  • Containers and serverless workloads.
  • Energy, utilities, or other mission-critical environments.
  • Wazuh, Datadog, Grafana, or similar.
  • Security documentation and ADRs.
Certifications

Valued as a signal, not a substitute for experience: AWS Certified Security – Specialty; AWS Certified Advanced Networking – Specialty; AWS Certified Solutions Architect; GICSP or GIAC GRID; CISSP; CCSP; Microsoft Certified: Identity and Access Administrator Associate.

#LI-AD1

For US-based roles - What you’ll get:

  • Competitive salary + annual performance-based bonus eligibility
  • Medical, dental, and vision insurance
  • 401(k) with company match
  • Paid time off and company holidays

For Mexico-based roles - What you’ll get:

  • Competitive salary + annual performance bonus eligibility
  • Major medical expenses and life insurance
  • Paid time off and holidays (per local policy)

For all roles:

  • Professional development and growth opportunities
  • Opportunity to grow with a mission-driven team shaping the future of clean energy
  • Equal Opportunity: ON.energy is committed to equal employment opportunity and to maintaining a work environment free of harassment, discrimination, or retaliation.
  • Benefits vary by role and location and are subject to change.
Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Senior AWS Cloud Engineer
Senior AWS Cloud Engineer

On.Energy • Buenos Aires

Presencial
ARS 1.800.000 - 3.200.000
Medical, dental, and vision insurance
Professional development opportunities
AWS Cloud Security Engineer for OT-Grid & Multi-Account
AWS Cloud Security Engineer for OT-Grid & Multi-Account

ON.energy • Argentina

Presencial
ARS 136.147.000 - 196.657.000
Sr. Security Solutions Architect, AWS
Sr. Security Solutions Architect, AWS

Amazon Web Services (AWS) • Buenos Aires

Presencial
ARS 3.500.000 - 5.500.000
Senior AWS Cloud Platform Engineer — Architect & Automate
Senior AWS Cloud Platform Engineer — Architect & Automate

On.Energy • Buenos Aires

Presencial
ARS 1.800.000 - 3.200.000
Medical, dental, and vision insurance
Professional development opportunities
Senior AWS Platform Engineer — IaC & Networking
Senior AWS Platform Engineer — IaC & Networking

ON.energy • Municipio de Esquel

Presencial
ARS 176.967.000 - 265.452.000
Medical, dental, and vision insurance
401(k) with company match
Paid time off and holidays
Aws Technical Lead / Architect (Buenos Aires)
Aws Technical Lead / Architect (Buenos Aires)

Hitachi Digital • Buenos Aires

Presencial
ARS 70.000 - 90.000
Flexible work arrangements
Industry-leading benefits
Support for holistic health and wellbeing
Senior Security Consultant
Senior Security Consultant

Scale Up Recruiting Partners • Córdoba

Presencial
ARS 178.909.546 - 268.364.320
Senior Security Consultant
Senior Security Consultant

Scale Up Recruiting Partners • Ciudad de Mendoza

Presencial
ARS 178.909.546 - 268.364.320
Senior Security Consultant
Senior Security Consultant

Scale Up Recruiting Partners • Municipio de Rincón de los Sauces

Presencial
BRL 618.876 - 928.314
Delivery Consultant - Cloud Security, Professional Services, Professional Services
Delivery Consultant - Cloud Security, Professional Services, Professional Services

Amazon Web Services (AWS) • Buenos Aires

Presencial
ARS 133.982.000 - 178.643.000