AWS Security Engineer
- Company
- Peraton
- Location
- Remote - United States
- Work type
- Full Time
- Posted
- 2026-10-11
Job description
Job Description
Responsibilities
The AWS Security Engineer is responsible for ensuring the security, compliance and protection of our cloud-based infrastructure. The ideal candidate will have hands-on experience with AWS security services, cloud risk assessments, incident response and continuous security monitoring. This role partners with Cloud Engineering, DevOps and Application teams to maintain a secure and resilient cloud environment.
Day to Day Work Responsibilities:
Lead and support vulnerability scanning and remediation efforts for cloud resources
Strong understanding of IAM Roles/Policies and Identity Federation, Encryption, KMS, secrets management
Provision and manage AWS infrastructure using infrastructure as code (IaC) using tools such as Terraform
Write custom scripts for CloudWatch custom metrics and alarms based on application specific probes
Implement alerting and remediation automation based on probe output
Assist in incident response, investigation and root cause analysis of cloud security events.
Develop and maintain security architecture documentation, runbooks and procedure documents
Run AWS security posture assessments using automated tools
Experience with AWS cloud security monitoring and detection tooling
Contribute to best practices around DevOps, automation and deployments and work with teams to embed security best practices into CI/CD pipelines and infrastructure as code
Implement and improve AWS security controls, guardrails and baseline configurations
Continuously evaluate AWS environments for cost-effective security improvements
Conduct threat modeling, vulnerability analysis and remediation coordination
Support internal and external audits by gathering evidence, validating configurations and preparing documentation
Maintain cloud compliance requirements, NIST, FISMA and FedRAMP
Assist in risk assessments and security control testing
Support change control and documentation to reflect accurate system and process ownership
Evaluate merging cloud security tools and recommend security enhancements
Keep cloud environments compliant with security standards and best practices
Participate in on-call rotations to support 24/7 production systems and respond to incidents as they arise
Qualifications
Basic Qualifications:
Minimum of 8 years with BS/BA; Minimum of 6 years with MS/MA or 12 years of experience with HS Diploma/equivalent
6 years of experience in cloud security or cybersecurity
Proficient in scripting languages like Python and Bash
Hands-on experience with ECS, EKS, EC2, Lambda
Proficient in Git and CI/CD pipelines
Strong Terraform proficiency, writing modules, variables and workspaces
Deep knowledge of AWS security services, including IAM, KMS, GuardDuty, Security Hub, CloudTrail and Config Rules
Perform IAM policy and permissions audits to enforce least privilege
Ability to read and interpret access logs, cloud account configurations and IAM policies
Strong written and verbal communication skills for technical and non-technical stakeholders
Excellent analytical and problem-solving skills
Must be a US Citizen.
Must be able to obtain and maintain a Public Trust clearance
Preferred Qualifications:
Cloud certification (AWS Cloud Practitioner, Security Specialty)
Security compliance or audit certification