Responsibilities:
- Collaborate with cross-functional teams to understand business requirements and design scalable and secure AWS solutions.
- Architect, design, and implement cloud security solutions to protect sensitive information and ensure compliance with industry standards.
- Provide expertise in identity and access management, encryption, network security, and other security-related AWS services.
- Conduct security assessments including penetration tests and recommend enhancements to address vulnerabilities and mitigate risks.
- Conduct regular system audits to identify vulnerabilities and ensure compliance with security standards.
- Develop and maintain our incident response plan, including monitoring systems for anomalies and responding to security incidents.
- Work closely with development and operations teams to integrate security controls into the CI/CD pipeline.
- Stay up to date on industry best practices, AWS security features, and emerging threats to continually improve the security posture of our systems.
- Develop and deliver security training and awareness programs to staff.
- Assist in the creation and maintenance of security policies, procedures, and documentation.
Minimum Requirements:
- CISSP certified.
- Proven experience as a Cybersecurity Engineer with a focus on security in AWS.
- In-depth knowledge of AWS services, including but not limited to EC2, S3, Lambda, IAM, VPC, KMS, Cloud Watch, and Cloud Trail.
- Strong understanding of security principles, best practices, and standards in cloud environments.
- Experience with designing and implementing secure, multi-tier, highly available architectures on AWS.
- Ability to perform security audits on applications even though they are not hosted on the cloud.
- Knowledge in fundamental database security and application security to address vulnerabilities such as Cross-Site Scripting, Cross-Site Request Forgery, SQL Injection, HTML Injection, etc.
- Familiarity with compliance frameworks such as GDPR, HIPAA, and SOC 2.
- Hands-on experience with security tools and technologies, such as AWS Security Hub, Guard Duty, and WAF.
- Knowledge of disaster recovery, computer forensic tools, technologies, and methods.
- Excellent communication and collaboration skills with the ability to explain complex security concepts to technical and non-technical stakeholders.
- Other certifications such as CISM, CEH, Comp TIA Security+, or similar will be advantageous.