AWS Cloud Security Engineer

Synechron

City of Melbourne

On-site

AUD 120,000 - 190,000

Full time

29 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Synechron is seeking an experienced AWS Cloud Security Engineer to design, implement, and maintain security governance, guardrails, and compliance controls across large-scale multi-account AWS environments in Melbourne, Australia. You will work with cloud platform, DevOps, and security teams to ensure secure, compliant, and scalable AWS operations.

The role emphasizes Terraform, CloudFormation, IAM, and automated remediation using Python and PowerShell, with strong emphasis on policy-as-code and

Qualifications

  • Strong experience with AWS Organizations, SCP design and implementation.
  • Hands-on experience implementing cloud security governance and guardrails in multi-account AWS environments.
  • In-depth understanding of AWS IAM, permission boundaries, federation, and access control models.
  • Experience with AWS security services including AWS Config, CloudTrail, Security Hub, GuardDuty, IAM Access Analyzer.

Responsibilities

  • Design and implement AWS governance frameworks across multi-account environments using AWS Organizations, SCPs, and RCPs.
  • Establish cloud security guardrails and enforce security standards across AWS accounts and workloads.
  • Develop and manage IAM solutions, including permission boundaries and least-privilege models.
  • Build IaC solutions using Terraform and CloudFormation.
  • Automate security controls, compliance monitoring, and remediation activities with Python and PowerShell.
  • Integrate security policies and compliance checks into CI/CD pipelines for DevSecOps.

Skills

AWS Organizations
SCP design
IAM fundamentals
Terraform
CloudFormation
Python
PowerShell
AWS Config
CloudTrail
GuardDuty
Cloud security automation
DevSecOps

Tools

Terraform
CloudFormation
IAM Access Analyzer
Cloud Custodian

Job description

We are seeking an experienced AWS Cloud Security Engineer to design, implement, and maintain security governance, guardrails, and compliance controls across large-scale multi-account AWS environments. The ideal candidate will have deep expertise in AWS security, cloud governance, Infrastructure as Code (IaC), policy automation, and security remediation frameworks. This role will work closely with cloud platform, DevOps, and security teams to ensure AWS environments remain secure, compliant, and scalable.

Key Responsibilities
  • Design and implement AWS governance frameworks across multi-account environments using AWS Organizations, Service Control Policies (SCPs), and Resource Control Policies (RCPs).
  • Establish cloud security guardrails and enforce security standards across AWS accounts and workloads.
  • Develop and manage AWS Identity and Access Management (IAM) solutions, including permission boundaries, role-based access controls, and least-privilege models.
  • Build and maintain Infrastructure as Code (IaC) solutions using Terraform and CloudFormation.
  • Automate security controls, compliance monitoring, and remediation activities using Python and PowerShell scripting.
  • Implement and manage AWS security services including AWS Config, CloudTrail, Security Hub, GuardDuty, and related services.
  • Develop policy-as-code solutions using AWS Config Rules, Cloud Custodian, and similar frameworks.
  • Create automated detection, compliance, and remediation workflows for cloud security risks.
  • Integrate security policies and compliance checks into CI/CD pipelines to enable DevSecOps practices.
  • Conduct cloud security assessments, reviews, and audits to ensure adherence to organizational and regulatory requirements.
  • Collaborate with platform engineering, cloud operations, and application teams to improve security posture and operational efficiency.
  • Maintain documentation, security standards, and governance frameworks for cloud environments.
Required Skills & Experience
AWS Security & Governance
  • Strong experience with AWS Organizations, SCP design and implementation.
  • Hands-on experience implementing cloud security governance and guardrails in multi-account AWS environments.
  • In-depth understanding of AWS IAM, permission boundaries, federation, and access control models.
  • Experience with AWS security services including:
  • AWS Config
  • AWS CloudTrail
  • AWS Security Hub
  • AWS GuardDuty
  • IAM Access Analyzer
Infrastructure as Code & Automation
  • Strong proficiency in Terraform (preferred).
  • Experience with AWS CloudFormation.
  • Advanced scripting skills in Python and PowerShell.
  • Experience building automated security controls and remediation workflows.
Policy as Code & Compliance
  • Experience with:
  • Compliance automation tools and frameworks
  • Strong understanding of security compliance and cloud governance best practices.
DevSecOps
  • Experience integrating security controls into CI/CD pipelines.
  • Knowledge of security scanning, compliance validation, and policy enforcement within deployment pipelines.
  • Experience with modern DevOps and automation practices.
Preferred Qualifications
  • AWS Certified Security Specialty, AWS Solutions Architect, or equivalent certifications.
  • Experience working in highly regulated environments such as Financial Services, Banking, Insurance, or Government.
  • Familiarity with cloud risk management, security architecture reviews, and incident response processes.
  • Knowledge of container security, Kubernetes, and cloud-native security patterns.
  • Experience with enterprise-scale cloud transformation initiatives.
  • Strong problem-solving and analytical skills.
  • Excellent stakeholder management and communication abilities.
  • Ability to balance security, compliance, and business requirements.
  • Strong automation mindset with a focus on scalability and operational excellence.
  • Ability to work effectively in cross-functional Agile teams.
Ideal Candidate Profile:

A highly skilled AWS Cloud Security professional who can establish enterprise-wide cloud governance, implement automated security controls, enforce compliance through policy-as-code, and drive security-by-design principles across AWS platforms and delivery pipelines.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Platform Engineer (Cloud / DevOps Architect – AWS)
Platform Engineer (Cloud / DevOps Architect – AWS)

Synechron • Sydney

On-site
AUD 180,000 - 260,000
Security Leader, Global Proserve Security
Security Leader, Global Proserve Security

Amazon • Canberra

On-site
AUD 130,000 - 160,000
AWS Cloud Security Architect — Governance & Automation
AWS Cloud Security Architect — Governance & Automation

Synechron • City of Melbourne

On-site
AUD 120,000 - 190,000
Cloud Architect
Cloud Architect

Talent Corp • Geelong

On-site
AUD 180,000 - 240,000
Cloud Security Engineer
Cloud Security Engineer

NTT DATA, Inc. • Sydney

On-site
AUD 170,000 - 230,000
Security Engineer, AWS Customer Incident Response Team (CIRT)
Security Engineer, AWS Customer Incident Response Team (CIRT)

Amazon • City of Brisbane

On-site
AUD 150,000 - 190,000
Cloud Security Engineer
Cloud Security Engineer

Michael Page • City of Melbourne

On-site
AUD 150,000 - 200,000
Cyber Security Specialist
Cyber Security Specialist

Logical • City of Melbourne

On-site
AUD 120,000 - 190,000
Senior AWS Devops Engineer
Senior AWS Devops Engineer

Osborne Richardson • City of Melbourne

Hybrid
AUD 157,000 - 212,000
Superannuation
Sr. Specialist Solutions Architect, Security, AWS
Sr. Specialist Solutions Architect, Security, AWS

Amazon • Sydney

On-site
AUD 180,000 - 240,000