Requirements
- Experience in security engineering, system administration, or related roles.
- Hands-on, production-level AWS security experience (100% cloud-native environment)—not just familiarity, but deep, applied knowledge in securing AWS workloads at scale.
- End-to-end ownership of the vulnerability management lifecycle: discovery, prioritization, risk and criticality assessment, timeline assignment, progress tracking, and closure driving (excluding code fixes, which you coordinate with development teams).
- Demonstrated experience owning security incident investigations
- Proven experience owning and fine-tuning a SIEM solution in production, with the judgment to separate real security signals from noise and false positives.
- Strong scripting skills in Python, Bash, or PowerShell for automation and tooling.
- Solid understanding of network security concepts (firewalls, IDS/IPS, proxies, VPNs).
- Hands-on experience with endpoint security tools and monitoring solutions.
- Strong analytical and problem-solving skills with the ability to think like an attacker.
Nice to Have
- Experience securing containerized workloads (Docker, Kubernetes)
- knowledge of compliance frameworks (PCI-DSS, SOC 2, NIST, ISO 27001)
- experience with Infrastructure as Code (Terraform, CloudFormation)