AWS Security Engineer Contract

With Intelligence

Greater London

Remote

GBP 70,000 - 110,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

A technology firm specializing in security seeks an AWS Security & Vulnerability Remediation Engineer for an initial 3-month contract. Candidates must have strong AWS security experience, deep knowledge of vulnerability management, and the ability to implement secure practices across DevSecOps. This role involves partnering with developers to remediate vulnerabilities and optimize security controls. The position offers a flexible work environment outside IR35.

Qualifications

  • Deep, hands-on AWS security experience across multiple services.
  • Strong knowledge of AWS Well-Architected Security Pillar.
  • Experience managing full vulnerability lifecycle.
  • Proven experience in CI/CD and DevSecOps.

Responsibilities

  • Lead remediation of AWS and application vulnerabilities.
  • Partner to implement secure fixes in delivery pipelines.
  • Ensure remediation aligns with AWS security controls.
  • Improve and automate vulnerability management processes.
  • Support incident response and post-remediation validation for high-risk findings.
  • Embed security into CI/CD and SDLC with shift-left reviews and secure coding guidance.

Skills

AWS security expertise
Deep understanding of DevSecOps
Strong knowledge of vulnerability management
Infrastructure as Code
Scripting skills (Python, Bash)

Tools

AWS Inspector
Terraform
Security Hub
Snyk

Job description

AWS Security & Vulnerability Remediation Engineer (DevSecOps / Cloud Security)

3 month initial contract outside IR35

Role Summary

We are looking to hire an AWS-focused security engineer to lead the remediation of cloud and application vulnerabilities across our AWS environment. You will work closely with Developers, Data Engineers, and our AWS Security Lead to validate findings, prioritise risk, implement fixes, and strengthen security controls. AWS security is your primary technical skill; a strong understanding of software development, DevSecOps practices, and vulnerability management is essential.

Key Responsibilities
  • Own end-to-end remediation of AWS and workload vulnerabilities: confirm findings, assess impact, prioritise actions, and track through to closure
  • Partner with Developers and Data Engineers to implement secure fixes in code, infrastructure, and delivery pipelines (IaC, containers, serverless, OS/packages)
  • Work with the AWS Security Lead to ensure remediation aligns with AWS security controls, internal risk policies, and compliance requirements
  • Improve and automate vulnerability management processes (e.g., scanning coverage, SLAs, exception handling, evidence capture)
  • Embed security into CI/CD and the SDLC: shift-left reviews, secure coding guidance, dependency management, and pipeline guardrails
  • Configure, tune, and operate AWS security services (e.g., GuardDuty, Security Hub, Inspector, Config, IAM Access Analyzer) to reduce exposure and prevent repeat issues
  • Produce clear remediation guidance, runbooks, and reporting dashboards for both technical and non-technical stakeholders
  • Support incident response and post-remediation validation where high-risk findings are exploited or trending
Requirements
AWS / Cloud Security (Primary)
  • Deep, hands-on AWS security experience across IAM, networking, compute, storage, serverless, and managed data services
  • Strong knowledge of the AWS Well-Architected Security Pillar and common control frameworks (CIS AWS Foundations, NIST/ISO-aligned controls)
  • Demonstrable experience implementing and validating AWS security controls, including:
    • IAM least privilege, roles, permission boundaries, SCPs, and access reviews
    • VPC segmentation, security group/NACL design, private endpoints, WAF/Shield
    • Encryption in transit and at rest using KMS, TLS, and secrets management
    • Logging and monitoring: CloudTrail, CloudWatch, Config, centralised SIEM patterns
    • Threat detection and posture management using AWS native services
Dev / DevSecOps / Vulnerability Management (Primary)
  • Strong understanding of modern SDLC, CI/CD, and DevSecOps approaches
  • Proven experience managing the full vulnerability lifecycle: triage, prioritisation (CVSS/EPSS/KEV), remediation, verification, and reporting
  • Comfortable remediating a wide range of findings: OS/package CVEs, container images, third-party libraries, serverless runtimes, and cloud misconfigurations
  • Able to translate security findings into clear, practical tasks for engineering teams and coach on secure implementation
Engineering & Tooling
  • Infrastructure as Code: Terraform and/or CloudFormation; able to review and fix security weaknesses in IaC
  • Scripting/automation skills in Python, Bash, or similar to streamline remediation and control validation
  • Familiarity with container and serverless security (ECR, ECS/EKS, Lambda, image scanning, runtime hardening)
  • Experience with common vulnerability and scanning tools (e.g., AWS Inspector/Security Hub, Snyk, Trivy, Dependabot, Prisma/Qualys/Tenable, etc.)
Nice to Have
  • Security certifications such as AWS Security Specialty, AWS Solutions Architect, or equivalent
  • Experience supporting data platforms on AWS (Glue, EMR, Redshift, Athena, RDS, OpenSearch, Kafka/MSK)
  • Knowledge of secure coding practices in Python/Node/Java or your core development stack
  • Experience with policy-as-code and automated control enforcement (OPA/Conftest, tfsec, Checkov)
Personal Attributes
  • Highly collaborative and pragmatic; you enjoy working directly with engineers to ship secure fixes quickly
  • Strong risk judgement and the ability to balance urgency with operational impact
  • Clear communicator who can write concise remediation guidance and present progress to stakeholders
  • Ownership mindset: you drive remediation through to completion, not just identification
Benefits

Outside IR35

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

AWS Security & Remediation Engineer (DevSecOps)
AWS Security & Remediation Engineer (DevSecOps)

With Intelligence • Greater London

Remote
GBP 70,000 - 110,000
AWS Security Consultant
AWS Security Consultant

I-confidential • City of Edinburgh

On-site
AWS Security & Cloud Architect
AWS Security & Cloud Architect

Third Nexus Group Limited • Greater London

On-site
GBP 50,000 - 83,000
AWS Security Consultant
AWS Security Consultant

i-confidential Limited • Easter Howgate

On-site
GBP 60,000 - 90,000
AWS Cloud Security Architect
AWS Cloud Security Architect

Anson McCade • Greater London

On-site
GBP 85,000 - 94,000
£7,000 security clearance allowance
10% annual bonus
Private medical insurance
+3
AWS Security & Cloud Platform Consultant
AWS Security & Cloud Platform Consultant

United States Digital Space LLC • Greater London

On-site
GBP 90,000 - 140,000
Security Engineer, AWS Security
Security Engineer, AWS Security

Amazon • Greater London

On-site
GBP 70,000 - 90,000
DevOps Engineer (Security focus)
DevOps Engineer (Security focus)

Allwyn UK • Watford

On-site
GBP 60,000 - 80,000
Company Bonus Scheme
Matched pension contributions up to 8.5%
26 days annual leave + 2 Life Days
+5
AWS Security & Cloud Platform Consultant
AWS Security & Cloud Platform Consultant

Kryptos Technologies limited • Greater London

On-site
GBP 111,000 - 221,000
AWS DevOps - SC Cleared
AWS DevOps - SC Cleared

Scrumconnect Consulting • Newcastle upon Tyne

Hybrid
GBP 50,000 - 70,000