AVP, AWS Security Engineer

Jobtailor

North Carolina

On-site

USD 150,000 - 210,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

LPL is seeking a senior cloud security engineer to codify and evolve the cloud control library across Security Hub CSPM, AWS Config conformance packs, and related guardrails. You will drive triage of findings, partner with Security Engineering, and contribute to secure-by-default foundations in multi-account Terraform environments.

The role demands hands-on Terraform, vulnerability triage, on-call resilience, and collaboration with cross-functional pods to raise the security posture of the

Qualifications

  • 7+ years of progressive technical experience including 3+ years in a senior cloud security, network security, or cloud infrastructure engineering role
  • Bachelor's degree in Computer Science, Engineering, or a related discipline (or equivalent work experience)
  • 3+ years of hands-on production AWS at scale in a multi-account landing zone with strong production Terraform delivered through Terraform Cloud and GitHub Actions
  • 3+ years experience operating as a senior individual contributor (AVP, Senior Engineer, Staff Engineer, or equivalent), influencing technical direction and uplifting peer engineers without direct authority — including code review leadership, design-review participation, and technical mentorship
  • 3+ years experience personally participating in 24x7 production on-call rotations in a fast-paced, security-conscious, regulated environment (financial services strongly preferred)
  • 5+ years hands-on production experience codifying cloud security controls in Security Hub CSPM and AWS Config (including custom conformance packs), with awareness of the broader CSPM and control-management landscape (Wiz, Prisma Cloud, Lacework, Orca) and how those systems integrate with Security Hub

Responsibilities

  • Codify and continuously improve cloud control library — Security Hub CSPM as today’s AWS-native control system and triage Security Hub findings within CCOE
  • Partner with Security Engineering to monitor Wiz signal and drive resolution of Wiz findings
  • Contribute to Account Factory for Terraform — security-control modules, AWS Config conformance packs, and reference patterns
  • Support enterprise vulnerability management by triage, prioritization, and remediation guidance for AWS-related findings
  • Operate as security & governance partner across all CCOE teams and pods; embed security review into design, code, and delivery touchpoints
  • Collaborate with Network Engineering on shared network-security controls including segmentation, encryption, WAF, and certificate lifecycle
  • Evaluate, pilot, and operationalize CNAPP, CSPM, CWPP, runtime defense, DSPM, and secrets scanning to meet InfoSec requirements
  • Translate FINRA, SEC, PCI, SOX into automated controls; lead cloud-security incident response and drive durable control improvements
  • Embed AI capabilities into engineering practice and platform self-service for internal customers
  • Embed AI in security governance via automated control authoring and SQL-like queryable views
  • Hands-on senior cloud engineer focusing on Terraform code, security tooling, vulnerability remediation, and incident response
  • Participate in 24x7 on-call rotations as a senior technical responder and escalation point
  • Align roadmaps across CCOE teams and foundations pods to remove blockers
  • Champion AWS Well-Architected Framework adoption with emphasis on Security pillar
  • Contribute to private Terraform module library and AFT base layer
  • Raise engineering quality through code review and design partnership
  • Participate in Agile/Scrum ceremonies and coordinate with RTE/PMO
  • Represent pod security posture in architecture reviews, audits, and customer engagements

Skills

AWS Cloud Security
Terraform
AWS Config
Security Hub CSPM
Wiz
GitHub Actions
On-call rotations
CSPM tooling

Education

Bachelor's degree in Computer Science or Engineering

Tools

Terraform
GitHub Actions
Terraform Cloud
AWS Config
Security Hub
Wiz

Job description

  • Codify and continuously improve LPL's cloud control library — Security Hub CSPM as today's AWS-native control system, AWS Config with custom conformance packs to express controls as code, and additional control-management systems as the landscape evolves — and triage, investigate, and drive resolution of Security Hub findings within CCOE
  • Partner with the Security Engineering team within LPL's enterprise Information Security organization (a peer of Security Architecture), which manages Wiz, to jointly monitor Wiz signal and drive resolution of Wiz findings, recognizing that Wiz and Security Hub findings frequently diverge
  • Contribute directly to the Account Factory for Terraform (AFT) foundational base layer — security-control modules, Service Control Policies, AWS Config conformance packs, and reference patterns — so the secure-by-default posture is a property of the platform every account inherits
  • Support LPL's enterprise vulnerability management department on cloud‑workload findings: assist with triage, prioritization, and remediation guidance for findings that originate in or affect AWS, without owning vulnerability management end‑to‑end
  • Operate as the security & governance partner across every CCOE team and pod — Foundations (FinOps, Functional Design Engineering & Strategy, Network Engineering, Monitoring), Platforms, Containers, Support, and Delivery — since Security & Governance is involved in every aspect of CCOE; embed security and governance review into design, code, and delivery touchpoints
  • Partner closely and day‑to‑day with the Network Engineering pod within Foundations (VP, AVP, and engineers) on shared network‑security controls: segmentation and micro‑segmentation, ingress/egress inspection, encryption in transit, WAF, Shield, and certificate lifecycle
  • Collaborate cross‑organization with Security Architecture and Security Engineering — peer teams within LPL's Information Security organization — to evaluate, pilot, and operationalize additional security solutions (CNAPP, CSPM, CWPP, runtime defense, DSPM, secrets scanning) and to ensure CCOE's posture meets InfoSec and application‑team requirements
  • Translate regulatory requirements (FINRA, SEC, PCI, SOX) into automated, code‑reviewed controls; lead cloud‑security incident response within CCOE's scope as a senior responder; partner with Internal Audit and Information Security on evidence collection, attestation, and audit response; drive blameless post‑incident reviews to durable control improvements
  • Embed agentic AI capabilities into the team's engineering practice (e.g., Cursor, Claude Code, Bedrock, MCP servers, agentic IaC and review workflows) and into the platform's self‑service experience for internal customers
  • Embed agentic AI capabilities into security governance: AI‑assisted triage of Security Hub and Wiz findings, automated control authoring (Terraform and AWS Config conformance pack drafts from natural‑language intent), conversational interfaces for control inquiries, and MCP‑backed agents that join Security Hub, AWS Config, Wiz signal, and Terraform context into one queryable view
  • Operate as a hands‑on senior cloud engineer: spend the majority of your time in Terraform code, security tooling configuration, vulnerability remediation, design reviews, peer reviews, and incident response — hands‑on engineering is the primary leverage point
  • Personally participate in 24x7 on‑call rotations as a senior technical responder and escalation point for production incidents
  • Partner with peer engineers, AVPs, and VPs across the Cloud Center of Excellence — the five CCOE teams (Foundations, Platforms, Containers, Support, Delivery) and the five Foundations pods (Security & Governance, FinOps, Functional Design Engineering & Strategy, Network Engineering, Monitoring) — to align roadmaps and remove cross‑team and cross‑pod blockers
  • Champion AWS Well‑Architected Framework adoption (with emphasis on the Security pillar) and drive continuous improvement against operational, security, reliability, and compliance outcomes
  • Contribute to the private Terraform module library and the Account Factory for Terraform (AFT) foundational base layer, including security‑control modules and reference patterns
  • Raise engineering quality across the pod through code review, design partnership, and technical pairing — acting as a force multiplier without direct reports
  • Participate in Agile/Scrum ceremonies (sprint planning, standups, backlog grooming, retrospectives) and partner with the RTE and PMO on delivery commitments and dependencies
  • Represent the pod's security posture in architecture review boards, internal audit, and customer engagements; communicate technical risk and trade‑offs clearly to engineers and to non‑technical executives
Requirements
  • 7+ years of progressive technical experience including 3+ years in a senior cloud security, network security, or cloud infrastructure engineering role
  • Bachelor's degree in Computer Science, Engineering, or a related discipline (or equivalent work experience)
  • 3+ years of hands‑on production AWS at scale in a multi‑account landing zone with strong production Terraform delivered through Terraform Cloud and GitHub Actions
  • 3+ years experience operating as a senior individual contributor (AVP, Senior Engineer, Staff Engineer, or equivalent), influencing technical direction and uplifting peer engineers without direct authority — including code review leadership, design‑review participation, and technical mentorship
  • 3+ years experience personally participating in 24x7 production on‑call rotations in a fast‑paced, security‑conscious, regulated environment (financial services strongly preferred)
  • 5+ years hands‑on production experience codifying cloud security controls in Security Hub CSPM and AWS Config (including custom conformance packs), with awareness of the broader CSPM and control‑management landscape (Wiz, Prisma Cloud, Lacework, Orca) and how those systems integrate with Security Hub
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cloud Engineer
Senior Cloud Engineer

LPL Financial • Austin (TX)

On-site
USD 90,000 - 120,000
Senior Security Engineer
Senior Security Engineer

Novacoast • Salt Lake City (UT)

On-site
USD 100,000 - 130,000
VP, Functional Design Engineering
VP, Functional Design Engineering

Jobtailor • North Carolina

On-site
USD 150,000 - 190,000
Principal Engineer, Cloud Strategy Lead
Principal Engineer, Cloud Strategy Lead

Jobtailor • North Carolina

On-site
USD 180,000 - 240,000
Senior AWS Cloud Security Engineer — CSPM & Terraform
Senior AWS Cloud Security Engineer — CSPM & Terraform

Jobtailor • North Carolina

On-site
USD 150,000 - 210,000
Principal Security Architect
Principal Security Architect

Francisco Partners • United States

On-site
USD 130,000 - 165,000
AWS Solution architect
AWS Solution architect

Russell Tobin • Alpharetta (GA)

On-site
USD 120,000 - 150,000
Comprehensive healthcare coverage
401(k)-retirement savings
Life & disability insurance
Staff Cloud Security Engineer
Staff Cloud Security Engineer

Jobtailor • Menlo Park (CA)

On-site
USD 185,000 - 240,000
Cybersecurity Engineer - Cloud, Ops (human)
Cybersecurity Engineer - Cloud, Ops (human)

NEURA Robotics • Germany (OH)

On-site
USD 120,000 - 160,000
Security Architect
Security Architect

YASH Technologies • Chicago (IL)

On-site
USD 120,000 - 150,000