Security & Compliance Engineer

AMAZON WEB SERVICES SINGAPORE PRIVATE LIMITED

Singapore

On-site

SGD 120,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

AWS Security Assurance Services is seeking a Security & Compliance Engineer to design, build, and deploy AWS security and compliance solutions for highly regulated customers in Singapore. You will own engineering deliverables across secure design, implementation, testing, deployment, and maintenance, translating SOC2, HIPAA, PCI-DSS, CIS, NIST, and FedRAMP into secure AWS implementations.

You will write code, ship custom controls, run security investigations, lead design and code reviews,

Qualifications

  • 3+ years of programming in Python, Ruby, Go, Java, .Net, C++ or similar
  • 3+ years of scripting, programming, and security code review
  • Knowledge of networking protocols (HTTP, DNS, TCP/IP)
  • Experience with threat modeling or risk identification techniques

Responsibilities

  • Lead threat modeling, design reviews and architecture reviews for customer engagements
  • Design and implement custom preventive, detective, and proactive controls (SCPs, RCPs, policy-as-code)
  • Build secure-by-design IaC controls for Landing Zones and AWS architectures
  • Apply AWS security best practices for authentication, data handling, encryption, least privilege
  • Write and review IaC, scripts, enforcements and detections in Python, Terraform, CDK, CloudFormation and Rego
  • Develop continuous compliance monitoring and audit-ready evidence pipelines
  • Integrate custom controls with AWS-native and third-party tools
  • Travel to customer sites as needed

Skills

Threat modeling
Security design reviews
Proficient in secure coding
CI/CD security pipelines
Technical writing

Tools

Terraform
AWS CDK
CloudFormation
OPA Rego
Cfn-Guard

Job description

AWS Security Assurance Services (SAS) is hiring a Security & Compliance Engineer to design, build, and deploy AWS security and compliance solutions for highly regulated customers. You will own engineering deliverables across the full lifecycle — secure design, implementation, testing, deployment, and maintenance — translating compliance frameworks (SOC2, HIPAA, PCI-DSS, CIS, NIST, FedRAMP) into secure-by-design AWS implementations. You will work autonomously within your team, deliver cross-functional projects with partner teams, and drive measurable risk reduction for customers at scale. You’ll write code, ship custom controls, run security investigations, lead design and code reviews on your team, and mentor junior engineers. You will identify systemic issues, propose pragmatic solutions, and improve the team’s mechanisms over time.

Key job responsibilities
  • Lead threat modeling, security design reviews, and architecture reviews for customer engagements; identify and mitigate risks across systems and applications.
  • Design and implement custom preventive, detective, and proactive controls — Service Control Policies (SCPs), Resource Control Policies (RCPs), policy-as-code (cfn-guard, OPA Rego, Cedar), and automated remediation workflows.
  • Build secure-by-design Infrastructure-as-Code controls for Landing Zones, AWS Control Tower customizations, Zero-Trust architectures, and AI/ML workloads.
  • Apply AWS security best practices for authentication and authorization, data handling, least privilege, encryption, micro-segmentation, tagging strategy, and API/MCP integration.
  • Write and review IaC, scripts, enforcements and detections in Python, Terraform, AWS CDK, CloudFormation, and Rego.
  • Build continuous compliance monitoring, automated evidence collection, visualization, reporting, and remediation pipelines that hold up in audit.
  • Integrate custom controls with AWS-native and third-party security and compliance tooling.
  • Drive emerging-edge ideas into prototyping end-to-end to inform new security and compliance solutions and products.
  • Identify risks and edge cases; propose implementation paths and go/no-go gates.
  • Apply systematic approaches to risk identification; propose compensating controls when direct remediation isn’t possible.
  • Help develop technical content
  • Identify cross-team patterns, gaps, improvements.
  • Travel to customer sites as needed.
About the team

The AWS Security Assurance Services team, within AWS Support, leverages the expertise and ingenuity of our builders to establish scalable security solutions for both internal and external customers that drive business outcomes. Our goal of securing the world’s workloads requires reliable delivery of bar-raising security outcomes and investment in security mechanisms and automation on behalf of our customers.

AWS Security Assurance Services LLC, a PCI-QSAC and HITRUST External Assessor Firm, is a team of industry-certified assessors and Compliance Engineers with DevOps and Cloud Infrastructure Architect backgrounds, helping our customers achieve, maintain, and automate compliance in the cloud by tying applicable audit standards to AWS service-specific features and functionality. The SAS team works with our largest enterprise customers to operationalize the shared responsibility model as they migrate to the cloud.

Basic qualifications
  • 3+ years of programming in Python, Ruby, Go, Swift, Java, .Net, C++ or similar object oriented language experience
  • 3+ years of scripting, programming, and security code review in a common programming language (non-internship) experience
  • Knowledge of networking protocols such as HTTP, DNS and TCP/IP
  • Experience applying threat modeling or other risk identification techniques or equivalent
Preferred qualifications
  • 2+ years of any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security experience
  • Knowledge of networking protocols such as HTTP(S), DNS, and TCP/IP
  • Experience performing security activities across one or more phases of the software development lifecycle (SDLC), such as security design review, threat modeling, secure code review, and security testing
  • Experience writing for developer and technical audiences: blog, product documentation, technical information
  • Strong programming and scripting skills in Python, TypeScript, Node.js, Go, Java, or .NET.
  • Hands-on Infrastructure-as-Code skills in Terraform, AWS CDK, or CloudFormation.
  • Hands-on experience with AWS security and governance services: Config, Security Hub, IAM, KMS, VPC, Lambda, CloudTrail, CloudWatch/EventBridge.
  • Experience deploying SCPs and RCPs in multi-account AWS Organizations.
  • Experience writing and deploying policy-as-code (cfn-guard, OPA Rego, Cedar, or equivalent).
  • Experience designing CI/CD pipelines for security or compliance control deployment.
  • Experience with AWS Control Tower customizations, Landing Zones, or Zero-Trust architectures.
  • Working knowledge of at least one compliance framework: SOC2, HIPAA, PCI-DSS, CIS, or NIST.
  • Experience producing audit-ready evidence and working with third-party assessors.
  • Spec-driven development; AI agentic design and Model Context Protocol (MCP) experience.
  • Industry and AWS certifications: AWS Solutions Architect Associate or Professional, AWS Security Specialty, CISSP, or equivalent.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer
Security Engineer

SISTIC.com Pte Ltd • Singapore

On-site
SGD 90,000 - 150,000
Cloud Security & Compliance Engineer
Cloud Security & Compliance Engineer

AMAZON WEB SERVICES SINGAPORE PRIVATE LIMITED • Singapore

On-site
SGD 120,000 - 180,000
Head of Security Engineering & Architecture- FS (SG/India)- 10k
Head of Security Engineering & Architecture- FS (SG/India)- 10k

Argyll Scott Singapore • Singapore

On-site
SGD 180,000 - 280,000
G01 - IT Security Officer
G01 - IT Security Officer

FPT Asia Pacific Pte Ltd • Singapore

On-site
SGD 120,000 - 180,000
Sr. Security Engineer, Security Search and Observability, Field Innovation, Security Search and[...]
Sr. Security Engineer, Security Search and Observability, Field Innovation, Security Search and[...]

Amazon Web Services (AWS) • Singapore

On-site
SGD 120,000 - 180,000
Cloud Engineering
Cloud Engineering

ITCAN Pte Limited • Singapore

On-site
SGD 120,000 - 180,000
Senior Security Engineer
Senior Security Engineer

Webot • Singapore

On-site
SGD 120,000 - 180,000
Principal/Senior Principal Engineer (Cloud Security & Governance)
Principal/Senior Principal Engineer (Cloud Security & Governance)

DSTA • Singapore

On-site
SGD 90,000 - 130,000
DevSecOps Engineer
DevSecOps Engineer

LINKTRIX Consultants, Asia Pacific • Singapore

On-site
SGD 120,000 - 180,000
Tech Risk or Assurance Analyst
Tech Risk or Assurance Analyst

FLINTEX CONSULTING PTE. LTD. • Singapore

On-site
SGD 100,000 - 180,000