AWS Cloud Security Engineer

Insight Global

Reston (VA)

On-site

USD 140,000 - 200,000

Full time

12 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Insight Global is seeking experienced Cloud Security Engineers to drive security controls across AWS and Google Cloud Platform in a large multi-cloud environment. The role emphasizes practical implementation, automation, and integration with platform and application teams.

Ideal candidates bring hands-on expertise in cloud-native security, IAM, IaC, Kubernetes security, logging, and incident response, with a focus on secure, scalable, and compliant cloud deployments.

Qualifications

  • Hands-on cloud security engineering in AWS and multi-clouds.
  • Deep IAM and OIDC federation experience.
  • Experience with IaC tools (Terraform, CloudFormation, CDK).
  • Kubernetes security and container security expertise.
  • Strong logging, monitoring, and SIEM integration skills.
  • Experience with credential rotation and short-lived credentials.
  • Ability to operate in multi-account AWS environments.
  • Proficient scripting in Python or Go.
  • Knowledge of security guardrails, policies, and RBAC.
  • Familiarity with GitHub Actions OIDC for AWS.

Responsibilities

  • Design, implement, and automate cloud security controls across AWS and GCP environments.
  • Implement modern authentication and authorization solutions (IAM, OIDC, workload identity federation).
  • Develop guardrails and data perimeter protections to reduce exposure risks.
  • Build IaC and automation to support security deployment, credential management, and compliance reporting.
  • Enable cloud audit logging, SIEM pipelines, detections, and incident response capabilities.
  • Develop detections and automated response for credential abuse and anomalous activity.
  • Harden Kubernetes and containerized environments with secure patterns and access controls.
  • Protect internet-facing apps with Cloudflare WAF, DDoS protection, and secure ingress patterns.
  • Identify vulnerabilities and remediate exposed resources through testing and monitoring.
  • Collaborate with cloud, platform, and app teams to improve security posture in large-scale environments.

Skills

Cloud security engineering
AWS IAM & OIDC
IaC (Terraform, CloudFormation, CDK)
Kubernetes security
Logging & SIEM (Splunk, Sentinel)
Credential rotation & short-lived cred
Cross-account AWS multi-account
Python/Go scripting
Security policies & guardrails
GitHub Actions OIDC for AWS

Tools

Terraform
CloudFormation
CDK
GitHub Actions

Job description

Job Description

We are seeking experienced Cloud Security Engineers to support the implementation of critical cloud security initiatives across AWS and Google Cloud Platform (GCP) environments. This role is highly hands-on and focused on building, deploying, automating, and operationalizing security controls across a large-scale multi-cloud ecosystem.

The ideal candidate has deep expertise in cloud-native security, identity and access management, infrastructure-as-code, Kubernetes security, logging and detection engineering, and cloud network security. This is an engineering-focused role requiring practitioners who can implement solutions, write code, automate controls, and partner closely with platform and application teams.

Responsibilities

Design, implement, and automate cloud security controls across AWS and GCP environments, with a focus on identity security, cloud infrastructure protection, and attack surface reduction.

Implement modern authentication and authorization solutions, including IAM, OIDC, workload identity federation, service accounts, and role-based access controls, while leading efforts to eliminate long-lived credentials and adopt short-lived identities.

Develop and enforce cloud security guardrails, data perimeter protections, default-deny access models, and security policies that reduce unauthorized access, lateral movement, and data exposure risks across multi-cloud environments.

Build infrastructure-as-code and automation solutions to support security deployment, credential management, compliance reporting, monitoring, and policy enforcement at scale.

Enable, integrate, and maintain cloud audit logging, monitoring, SIEM pipelines, security detections, and incident response capabilities across AWS, GCP, Kubernetes, GitHub, and related platforms.

Develop detections and automated response mechanisms for credential abuse, anomalous activity, unauthorized access attempts, and potential data exfiltration events.

Secure Kubernetes and containerized environments by implementing hardened configurations, secure deployment patterns, access controls, and cloud-native security best practices.

Design and implement security protections for internet-facing applications and infrastructure, including Cloudflare WAF, DDoS protection, secure ingress patterns, and private-by-default cloud architectures.

Identify, assess, and remediate security vulnerabilities, exposed cloud resources, insecure network paths, and application security risks through proactive testing, monitoring, and validation activities.

Partner closely with cloud, platform, infrastructure, and application engineering teams to implement security solutions, support cloud migrations, establish operational playbooks, and improve the overall security posture of large-scale cloud environments.

We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to HR@insightglobal.com.To learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/.

Skills and Requirements
  • 5+ years of hands-on experience in AWS cloud security engineering
  • Deep expertise with AWS IAM (roles, policies, SCPs, permission boundaries, OIDC federation)
  • Experience implementing and managing AWS Organizations, SCPs, and resource control policies (RCPs)
  • Proficiency with AWS CloudTrail, GuardDuty, Security Hub, and Config for logging and monitoring
  • Hands-on experience with credential management, rotation, and migration to short-lived credentials
  • Strong infrastructure-as-code skills (Terraform, CloudFormation, or CDK)
  • Experience with network security controls (VPCs, security groups, NACLs, PrivateLink)
  • Familiarity with CI/CD pipeline security and preventive guardrails
  • Ability to write automation scripts (Python, Go, or similar)
  • Experience working in multi-account AWS environments at scale
  • Strong written and verbal communication skills; ability to produce operational playbooks and runbooks
  • Familiarity with EKS and container security - AWS Security Specialty or Solutions Architect Professional certification
  • Experience with AWS resource policies and cross-account access patterns
  • Hands-on experience migrating workloads from static credentials to OIDC/federation-based authentication
  • Familiarity with SIEM integration (Splunk, Sentinel, or similar) and detection engineering
  • Experience with GitHub Actions OIDC integration for AWS
  • Prior work in a staff augmentation or consulting engagement model
  • Experience in regulated or high-security environments (SOC 2, FedRAMP, or similar)
  • Familiarity with ClickHouse
  • Experience building reusable security patterns and frameworks for enterprise adoption
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer
Security Engineer

Insight Global • Fulton (MD)

Hybrid
USD 120,000 - 150,000
Senior Cloud Security Engineer — AWS & GCP
Senior Cloud Security Engineer — AWS & GCP

Insight Global • Reston (VA)

On-site
USD 140,000 - 200,000
Cloud Security Engineer
Cloud Security Engineer

TechDigital Group • Frisco (TX)

On-site
USD 80,000 - 120,000
AWS Cloud Engineer (Secret Clearance)
AWS Cloud Engineer (Secret Clearance)

Improvix Technologies • Washington

On-site
USD 100,000 - 130,000
Cyber Cloud Security Engineer
Cyber Cloud Security Engineer

Pierce • New York (NY)

On-site
USD 140,000 - 190,000
Staff Cloud Security Engineer
Staff Cloud Security Engineer

Jobtailor • Menlo Park (CA)

On-site
USD 185,000 - 240,000
Cloud Security Engineering Manager
Cloud Security Engineering Manager

CIBR Warriors • Town of Texas (WI)

On-site
USD 150,000 - 210,000
Cloud Security Engineer
Cloud Security Engineer

ALLTECH CONSULTING SVC INC • Alpharetta (GA)

On-site
USD 120,000 - 150,000
Cloud Security Engineer
Cloud Security Engineer

apex-technology-inc • Los Angeles (CA)

On-site
USD 180,000 - 240,000
Cybersecurity Analyst (AWS Cloud Security)
Cybersecurity Analyst (AWS Cloud Security)

Barton Malow Builders • Southfield (MI)

On-site
USD 80,000 - 110,000