Responsibilities
- Design and enforce least-privilege IAM architectures, network segmentation, and cloud security controls (SCPs, secrets management, encryption, runtime threat detection) across multiple AWS accounts.
- Build automated detection and response pipelines, using AI tools to turn security findings into fast, actionable remediation.
- Maintain GitHub-based CI/CD pipelines and automation frameworks alongside the engineering team.
- Lead cross-functional security initiatives, embedding threat modeling and security reviews into the architecture and development lifecycle.
- Own vulnerability management, AWS security posture monitoring, incident detection and response, and HIPAA compliance programs.
- Shape cloud architecture decisions — balancing security, cost, and reliability — around zero-trust and defense-in-depth principles.
- Review and document the workflows, staffing, and tooling for each active care program, and produce a written summary of gaps and immediate priorities.
Requirements
- 5+ years of hands-on AWS cloud security and infrastructure engineering (IAM, network security, threat detection, compliance) in production — ideally including building a security program from scratch.
- Deep fluency with AWS security services (GuardDuty, Security Hub, Config, CloudTrail, KMS, Inspector) and IAM policy design.
- Experience with multi-account AWS governance (Control Tower, Organizations, VPC/network design) and container/serverless infrastructure (ECS, EKS, Lambda).
- Familiarity with security frameworks and compliance standards (CIS, HIPAA, HITRUST, AWS Well-Architected).
- US Citizenship is required.
Additional Information
- Remote opportunity with the ability to work ET or CT hours.
- You must be authorized to work in the US without sponsorship.
- Periodic travel to practice sites or Chamber offices may be required.