Sr Infrastructure Cloud Security Engineer - AWS - Remote

SitusAMC

United States

On-site

USD 135,000 - 180,000

Full time

2 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

PTO and paid holidays
Medical, dental, vision benefits
401K plan

Job summary

SitusAMC is seeking a Senior Cloud & Infrastructure Security Engineer to design, implement and maintain security controls across cloud and infrastructure. This hands-on role partners with SRE, Platform, Infrastructure, and DevOps teams to bake secure configurations into cloud platforms from day one.

The ideal candidate will lead with expertise in AWS IAM, VPC, encryption, logging, and GuardDuty, combining security engineering with automation using Terraform/CloudFormation and CI/CD integrations.

Qualifications

  • Bachelor’s degree in a technical field or equivalent experience.

Responsibilities

  • Design and maintain AWS security controls across IAM, VPC, encryption, monitoring, and cloud-native services.
  • Apply least-privilege access, secure networking, encryption, logging and monitoring standards.
  • Define secure baselines, hardening standards, reusable guardrails, and preventive controls for infrastructure technologies.
  • Build and maintain security controls through IaC using Terraform and CloudFormation.

Skills

AWS IAM
Kubernetes
CI/CD
Infrastructure as Code
Python scripting
Networking and security
Security engineering
Cloud security
Troubleshooting
Communication

Education

Bachelor’s degree in a technical field
6+ years cloud security or related

Tools

Terraform
CloudFormation
AWS services (GuardDuty, Config, CloudTrail)
Git
Terraform modules
EKS / Kubernetes platforms

Job description

SitusAMC is where the best and most passionate people come to transform our client’s businesses and their own careers. Whether you’re a real estate veteran, a passionate technologist, or looking to get your start, join us as we work together to realize opportunities for everyone, we proudly serve. At SitusAMC, we are looking to match your unique experience with one of our amazing careers, so that we can help you realize your potential and career growth within the Real Estate Industry. If you are someone who can be yourself, advocate for others, stay nimble, dream big, own every outcome, and think global but act local – come join our team! The Senior Cloud & Infrastructure Security Engineer is a senior technical member of the Information Security organization responsible for designing, implementing, and maintaining security controls across cloud and infrastructure environments. This is a hands‑on engineering role that works closely with Site Reliability Engineering (SRE), Platform Engineering, Infrastructure, DevOps, and application development teams to ensure security is engineered into cloud platforms and infrastructure from the outset. The objective is to make secure configurations the default, allowing engineering teams to move quickly while maintaining appropriate security controls. The successful candidate will combine deep cloud and infrastructure expertise with strong security engineering skills. This individual will have the technical capability and authority to implement security controls directly, including AWS IAM policies and roles, VPC and network security controls, cloud security guardrails, logging and monitoring, encryption controls, and Infrastructure-as-Code (IaC).

Essentials Job Functions
Cloud Security Engineering
  • Design and maintain AWS security controls across IAM, VPC, encryption, monitoring, and cloud-native services.
  • Apply least-privilege access, secure networking, encryption, logging, and monitoring standards.
  • Support secure adoption of AWS services by translating cloud risks into technical safeguards.
Infrastructure & Platform Security
  • Partner with SRE, Platform, Infrastructure, DevOps, and development teams to secure enterprise platforms and cloud infrastructure.
  • Define secure baselines, hardening standards, reusable guardrails, and preventative controls for infrastructure technologies.
  • Review infrastructure designs to identify security gaps and recommend scalable remediation.
Infrastructure-as-Code & DevSecOps
  • Build and maintain security controls through Infrastructure-as-Code using Terraform, CloudFormation, reusable modules, and templates.
  • Integrate automated policy, configuration, vulnerability, and compliance checks into CI/CD pipelines.
  • Embed security testing and guardrails into deployment workflows to reduce manual review.
Cloud Security Monitoring & Respons

e

  • Centralize and protect cloud security telemetry for monitoring, detection, and incident response.
  • Partner with Security Operations to investigate incidents and build automated detection and remediation capabilities.
  • Use logs, alerts, and findings to improve detection coverage and response readiness.
Security Architecture & Risk Management
  • Conduct security architecture reviews and translate risk requirements into practical technical controls.
  • Communicate cloud and infrastructure risks, business impact, and remediation options to stakeholders.
  • Develop reference architectures, security patterns, technical standards, and engineering guidance.
  • Other tasks as assigned by manager
Qualifications/ Requirements
  • Bachelor’s degree in a technical field from an accredited college/university, or equivalent job experience.
  • Minimum of 8+ years of industry and/or relevant experience, typically with 2+ years in an AVP level role or external equivalent.
  • At least 7+ years of direct relevant work experience in cloud security engineering, application/product security or a similar role
  • At least 5+ years of experience in cloud engineering, infrastructure engineering, security engineering, DevSecOps, SRE, or related technical disciplines.
  • Relevant certifications such as CISSP, CEH, GIAC, ISSAP, CISM or other relevant security-focused certifications preferred
  • Significant hands‑on experience securing production AWS environments including: Strong understanding of AWS IAM, including policies, roles, trust policies, permission boundaries, federation, cross‑account access, and least‑privilege design; Strong knowledge of AWS networking, including VPCs, subnets, routing, security groups, network ACLs, VPC endpoints, load balancers, DNS, and private connectivity.
  • Experience securing Kubernetes and containerized environments, including EKS or comparable managed Kubernetes platforms.
  • Hands‑on experience with AWS security services such as CloudTrail, Config, GuardDuty, Security Hub, Inspector, IAM Access Analyzer, KMS, and Secrets Manager.
  • Experience implementing infrastructure using Terraform, CloudFormation, or comparable Infrastructure-as-Code technologies.
  • Experience with Git-based development and CI/CD workflows.
  • Strong understanding of networking concepts, including TCP/IP, DNS, TLS, routing, firewalls, proxies, and network segmentation.
  • Working knowledge of Linux and common infrastructure technologies.
  • Highly motivated self‑starter that can manage multiple deliverables independently in a fast‑paced environment
  • Ability to develop automation using Python, PowerShell, Bash, or similar scripting languages.
  • Understanding of common cloud attack techniques, identity‑based attacks, privilege escalation, credential compromise, and infrastructure security vulnerabilities.
  • Demonstrated ability to independently troubleshoot complex technical security and infrastructure problems.
  • Strong written and verbal communication skills with the ability to communicate effectively with security professionals, engineers, architects, and technology leadership.
  • Highly motivated self‑starter that can manage multiple deliverables independently in a fast‑paced environment
  • Broad knowledge across the security, insider threat, risk management and compliance domains.
  • Proficiency in scripting and automation (e.g., Python, PowerShell, Terraform)
  • Familiarity with container security technologies (Docker, Kubernetes).
  • Have familiarity with infrastructure as code (IaC) tooling
  • Knowledge of encryption and key management practices.
  • Excellent risk based problem‑solving, analytical, and communication skills.
  • Ability to work independently and as part of a team.

Note: This job description is not intended to be all inclusive or exclusive. At any time, employees may perform other related duties as required to meet the ongoing needs of the organization and participate in additional trainings. SitusAMC does not accept unsolicited resumes from staffing agencies, search firms or any third parties. Any unsolicited resume submitted to SitusAMC in any manner will be considered SitusAMC property, and SitusAMC will not pay a fee for any placement resulting from the receipt of an unsolicited resume. The annual full time base salary range for this role is $135,000.00 - $180,000.00 Specific compensation is determined through interviews and a review of relevant education, experience, training, skills, geographic location and alignment with market data. Additionally, certain positions may be eligible to receive a discretionary bonus as determined by bonus program guidelines, position eligibility and SitusAMC Senior Management approval. SitusAMC offers PTO and paid holidays, the terms of which are set forth in the program policies. All full time employees also are eligible to participate in various benefit plans, including medical, dental, vision, life, disability insurance and 401K; in each case in accordance with the terms of the applicable plans. SitusAMC is an Equal Opportunity Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, age, sex, national origin, disability, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state, or local laws. Pay Transparency Nondiscrimination Provision SitusAMC is an Equal Opportunity Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, age, sex, national origin, disability, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state, or local laws. Know Your Rights, Workplace Discrimination is Illegal

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr Site Reliability Engineer -Remote US
Sr Site Reliability Engineer -Remote US

SitusAMC • United States

On-site
USD 81,000 - 135,000
PTO & holidays
Medical/Dental/Vision
401K Plan
Sr. Platform Engineer - Jfrog Expert - Remote US
Sr. Platform Engineer - Jfrog Expert - Remote US

SitusAMC • Frankfort (KY)

Remote
USD 110,000 - 180,000
PTO & Holidays
Medical Insurance
401K
Sr Project Manager- CRE Technology - Remote
Sr Project Manager- CRE Technology - Remote

SitusAMC • Annapolis (MD)

Remote
USD 110,000 - 135,000
PTO and paid holidays
Healthcare, dental, vision insurance
Life insurance
+2
Product Support Analyst - Remote US
Product Support Analyst - Remote US

SitusAMC • United States

On-site
USD 70,000 - 100,000
PTO and paid holidays
Medical, dental, vision, life, and 401
Vice President, Product Management
Vice President, Product Management

SitusAMC Holdings Corporation • Northern (KY)

Hybrid
USD 110,000 - 170,000
PTO
Paid holidays
Medical insurance
+5
AVP, Legal Operations - Data Governance
AVP, Legal Operations - Data Governance

SitusAMC • Annapolis (MD)

On-site
USD 95,000 - 130,000
PTO and paid holidays
401K; medical, dental, vision, life, &
Disability insurance
AVP, Legal Operations - Data Governance
AVP, Legal Operations - Data Governance

SitusAMC • Nashville (TN)

On-site
USD 95,000 - 130,000
PTO
Paid holidays
Medical insurance
+5
AVP, Legal Operations - Data Governance
AVP, Legal Operations - Data Governance

SitusAMC • Frankfort (KY)

On-site
USD 95,000 - 130,000
PTO
Paid holidays
Medical insurance
+5
AVP, Legal Operations - Data Governance
AVP, Legal Operations - Data Governance

SitusAMC • Bismarck (ND)

On-site
USD 95,000 - 130,000
AVP, Legal Operations - Data Governance
AVP, Legal Operations - Data Governance

SitusAMC • Providence (RI)

On-site
USD 95,000 - 130,000
PTO & holidays
401K plan
Medical benefits