JOBSEARCHER

AWS Security Technical Lead

The AWS Security Technical Lead is responsible for designing, reviewing, and validating security controls across the automation and orchestration layer powering the CUSTOMER VMware-to-AWS Outposts migration (1,321 applications, 63,169 servers, 2,642 AWS accounts).This role serves as the security subject matter expert for platform components, ensuring all tooling, IAM architecture, and CI/CD pipelines meet CUSTOMER security policies and AWS best practices. This role will report to the Security Lead on a weekly cadence to provide status on security reviews, threat models, and pipeline security deliverables.Day rate - $500-600Technical Lead ResponsibilitiesConduct Deliverable Security Reviews (DSRs) for Terraform modules, automation tools, and orchestrator components (SMO, UNO, DMO, ARA) prior to deployment. Not all reviews will utilize the full DSR methodology. The AWS Security Technical Lead will determine the appropriate DSR processes to apply to a particular review.Perform STRIDE-based threat modeling for new platform components and architecture changes.Triage automated scan findings (Checkov, Semgrep, SAST/SCA) and produce verified remediation guidance with severity classification.Review and validate cross-account IAM role designs, permission boundaries, trust policies, and OIDC federation for GitHub Actions.Assess IaC security — Terraform module review, provider/module version pinning, state file protection, and HCP workflow security.Conduct security assessments of new tooling integrations entering the platform ecosystem.Integrate and operationalize SAST/SCA scanning in CI/CD pipelines (GitHub Actions, CodeBuild, Astra Pipeline).Support supply chain security — SBOM generation, dependency scanning, and secrets scanning.Validate golden AMI security agent installation (Astra, Sentinel) on Outpost VMs.Triage vulnerability findings from Astra, Wiz, and CheckR across HAF and workload accounts.Assist in CUSTOMER CCOE security alignment across IAM, logging, CI/CD, and application security domains.Assist in compliance evidence collection for SOX, PCI DSS, and audit readiness.Ensure all project artifacts comply with both CUSTOMER and AWS security policies and standards.Experience RequirementsMinimum 5+ years of experience in cloud security with hands-on AWS implementation.Minimum 3+ years of experience with Infrastructure-as-Code security (Terraform, CloudFormation).Demonstrated experience with CI/CD pipeline security and DevSecOps practices.Certification RequirementsWe also request supporting documentation for at least one of the following active certifications:AWS Certified Security – SpecialtyAWS Certified Solutions Architect – ProfessionalThe following certification is also preferred for all AWS Security Technical Leads:CISSP (Certified Information Systems Security Professional)