Job Details

AWS Cloud Security Engineer

Contract C2C Remote

Position Summary

The AWS Cloud Security Engineer II will execute and operationalize enterprise cloud security controls across a large AWS environment. This engineer will focus on implementing approved AWS Organizations guardrails, Service Control Policies (SCPs), proactive and detective controls, policy automation, and cloud security health monitoring. The role is heavily implementation-focused and is responsible for delivering repeatable, scalable security controls using Infrastructure-as-Code and CI/CD processes rather than defining security strategy. 

Primary Responsibilities

  • Implement and manage AWS Organizations security control frameworks.
  • Deploy and maintain Service Control Policies (SCPs) across organizational units and accounts.
  • Build and maintain policy lifecycle management pipelines using Terraform and GitLab.
  • Create guardrails protecting IAM, KMS, CloudTrail, Security Hub, GuardDuty, and logging services.
  • Implement region restrictions, network restrictions, and approved preventive security controls.
  • Develop health checks for policy deployment failures, attachment drift, stale exceptions, and account misalignment.
  • Build AWS Config monitoring, conformance packs, and posture validation controls.
  • Develop remediation automation and security compliance reporting.
  • Implement Resource Control Policies (RCPs), tagging policies, Firewall Manager configurations, and WAF governance controls.
  • Create operational runbooks, rollback procedures, and deployment validation frameworks.

Required Experience

  • 3-7 years of AWS cloud engineering or cloud security experience.
  • Hands-on AWS Organizations and SCP implementation experience.
  • Knowledge of IAM, KMS, CloudTrail, AWS Config, Security Hub, and GuardDuty.
  • Terraform-based Infrastructure-as-Code experience.
  • GitLab CI/CD or similar pipeline automation experience.
  • Scripting experience using Python or PowerShell.
  • Experience supporting large enterprise cloud environments.

Desired Technologies

AWS Organizations, SCPs, RCPs, Terraform, GitLab CI/CD, AWS Config, CloudTrail, Security Hub, GuardDuty, Firewall Manager, WAF, IAM, KMS.

Deliverables

  • Production-ready SCP deployments.
  • Automated security guardrails.
  • Cloud posture dashboards.
  • Validation and rollback testing.
  • Health-check automation.
  • Operational runbooks and knowledge transfer documentation. 

Level: Engineer II (Mid-Level)

Job Overview

Date Posted:
October 5, 2026
Expiration date:
Open Until Filled
Location:
, United States
Job Title:
AWS Cloud Security Engineer
PS
Recruiter
Pradyumn Singh
Sr Technical Recruiter at Holistic Partners · Ankit Khanna

Apply for this position

PDF or Word (.doc, .docx) only. Images such as PNG are not accepted.