
Cloud Specialist – Security
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Peru.
• Design and implement comprehensive security architectures utilizing IAM, VPC, and data encryption both in transit and at rest.
• Manage network and perimeter security through AWS VPC, Security Groups, AWS WAF, AWS Shield, and AWS Network Firewall.
• Optimize secure content delivery with Amazon CloudFront and implement secure APIs using Amazon API Gateway.
• Deploy and manage EC2 instances, optimizing costs and performance with Spot Instances and Reserved Instances.
• Configure serverless solutions with AWS Lambda and design high availability and fault-tolerant disaster recovery systems.
• Create scalable architectures using Elastic Load Balancing and Auto Scaling Groups.
• Develop Infrastructure as Code (IaC) modules and templates with Terraform and CloudFormation.
• Integrate security into CI/CD pipelines through AWS CodePipeline, static analysis, vulnerability scanning, and penetration testing.
• Conduct threat modeling and risk assessments.
• Educate development and DevOps teams on security practices and AWS features.
• Automate security policies and incident response using AWS Lambda and AWS Systems Manager.
• Configure metrics, alarms, logging, and traceability through CloudWatch and AWS X-Ray.
• Identify and assess regulatory requirements such as HIPAA, PCI DSS, and SOC 2.
• Monitor environments using CloudTrail, AWS Config, and AWS Security Hub.
• Generate compliance reports and remediate security gaps.
• Participate in application design reviews and write post-mortem reports with root cause analysis.
• Active AWS Certified Security - Specialty certification (mandatory due to client contract).
• Proven experience configuring and managing AWS Control Tower and AWS Organizations.
• Demonstrable ability to create and apply Service Control Policies (SCPs) and Resource Control Policies (RCPs).
• Advanced proficiency in AWS IAM Identity Center and trust policies.
• Implementation of the Least Privilege principle at scale.
• Operational experience with AWS Security Hub, GuardDuty, and Inspector.
• Ability to prioritize and remediate security findings.
• Advanced configuration skills with AWS WAF, AWS Network Firewall, Security Groups, and NACLs.
• Expert use of AWS KMS, including Customer Master Keys (CMKs), key rotation, and access policies.
• Experience with AWS Certificate Manager (ACM).
• Familiarity with Backlogs (Jira/Azure DevOps), participation in daily scrums, and execution of Security Epics.
• Ability to create Runbooks and architecture diagrams using Lucidchart/Visio.
• Nice to have: programming automated remediations with Boto3/Lambda; Python is the preferred language.
• Nice to have: experience with Terraform or CloudFormation for deploying security guardrails.
• Nice to have: knowledge of CIS Benchmarks, NIST, or ISO 27001 as applied to AWS.
• Nice to have: experience in the energy/utility sector.
• Nice to have: experience integrating logs with Splunk, QRadar, or Datadog.
• Effective communication, Well-Architected mindset, and post-mortem analysis capability.
• 100% remote and flexible work arrangement allowing you to work from anywhere in the world.
• Full coverage for AWS certifications.
• Access to free learning platforms to enhance your knowledge.
• 15 business days per year to recharge and continue growing.
• Day off for your birthday.
• Paid holidays according to the national holiday calendar of your residing country.
• Special gifts to celebrate important moments in your life.
• Extended parental leave.
OpenLoop
Funcional Health Tech
Salesforce
CNO Financial Group
Get handpicked remote jobs straight to your inbox weekly.