Cloud Specialist – Security

Posted 1 day ago

This is a fully remote position, open to applicants in Peru.

📋 Description

• Design and implement comprehensive security architectures utilizing IAM, VPC, and data encryption both in transit and at rest.

• Manage network and perimeter security through AWS VPC, Security Groups, AWS WAF, AWS Shield, and AWS Network Firewall.

• Optimize secure content delivery with Amazon CloudFront and implement secure APIs using Amazon API Gateway.

• Deploy and manage EC2 instances, optimizing costs and performance with Spot Instances and Reserved Instances.

• Configure serverless solutions with AWS Lambda and design high availability and fault-tolerant disaster recovery systems.

• Create scalable architectures using Elastic Load Balancing and Auto Scaling Groups.

• Develop Infrastructure as Code (IaC) modules and templates with Terraform and CloudFormation.

• Integrate security into CI/CD pipelines through AWS CodePipeline, static analysis, vulnerability scanning, and penetration testing.

• Conduct threat modeling and risk assessments.

• Educate development and DevOps teams on security practices and AWS features.

• Automate security policies and incident response using AWS Lambda and AWS Systems Manager.

• Configure metrics, alarms, logging, and traceability through CloudWatch and AWS X-Ray.

• Identify and assess regulatory requirements such as HIPAA, PCI DSS, and SOC 2.

• Monitor environments using CloudTrail, AWS Config, and AWS Security Hub.

• Generate compliance reports and remediate security gaps.

• Participate in application design reviews and write post-mortem reports with root cause analysis.


⛳️ Requirements

• Active AWS Certified Security - Specialty certification (mandatory due to client contract).

• Proven experience configuring and managing AWS Control Tower and AWS Organizations.

• Demonstrable ability to create and apply Service Control Policies (SCPs) and Resource Control Policies (RCPs).

• Advanced proficiency in AWS IAM Identity Center and trust policies.

• Implementation of the Least Privilege principle at scale.

• Operational experience with AWS Security Hub, GuardDuty, and Inspector.

• Ability to prioritize and remediate security findings.

• Advanced configuration skills with AWS WAF, AWS Network Firewall, Security Groups, and NACLs.

• Expert use of AWS KMS, including Customer Master Keys (CMKs), key rotation, and access policies.

• Experience with AWS Certificate Manager (ACM).

• Familiarity with Backlogs (Jira/Azure DevOps), participation in daily scrums, and execution of Security Epics.

• Ability to create Runbooks and architecture diagrams using Lucidchart/Visio.

• Nice to have: programming automated remediations with Boto3/Lambda; Python is the preferred language.

• Nice to have: experience with Terraform or CloudFormation for deploying security guardrails.

• Nice to have: knowledge of CIS Benchmarks, NIST, or ISO 27001 as applied to AWS.

• Nice to have: experience in the energy/utility sector.

• Nice to have: experience integrating logs with Splunk, QRadar, or Datadog.

• Effective communication, Well-Architected mindset, and post-mortem analysis capability.


🏝️ Benefits

• 100% remote and flexible work arrangement allowing you to work from anywhere in the world.

• Full coverage for AWS certifications.

• Access to free learning platforms to enhance your knowledge.

• 15 business days per year to recharge and continue growing.

• Day off for your birthday.

• Paid holidays according to the national holiday calendar of your residing country.

• Special gifts to celebrate important moments in your life.

• Extended parental leave.

People also viewed

OpenLoop13 hours ago

Staff Security Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Funcional Health Tech13 hours ago

Information Security Governance Analyst (Mid-Level)

BR flagBrazil OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Salesforce14 hours ago

Security Architect Lead

US flagArizona, +13 more statesFull-timeCybersecurity / Security Engineer$150.1k – $227k/year
ApplyView job
CNO Financial Group14 hours ago

Lead IT Security Architect – SailPoint

US flagIllinois, +6 more statesFull-timeCybersecurity / Security Engineer$130.5k – $195.7k/year
ApplyView job
GuidePoint Security16 hours ago

Security Architect – AD/Entra ID

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Applied Research Solutions18 hours ago

Information System Security Engineer – ISSE

US flagOhio OnlyFull-timeCybersecurity / Security Engineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers