Cloud Security and Infrastructure Engineer
Build and mature AWS cloud security program and infrastructure for a cardiology platform company. Own security architecture, detection/response, HIPAA compliance, and infrastructure decisions balancing security, cost, and reliability.
About the job
Key Responsibilities
- Design and enforce least-privilege IAM architectures, network segmentation, and cloud security controls (SCPs, secrets management, encryption, runtime threat detection) across multiple AWS accounts.
- Build automated detection and response pipelines, using AI tools to turn security findings into fast, actionable remediation.
- Maintain GitHub-based CI/CD pipelines and automation frameworks alongside the engineering team.
- Lead cross-functional security initiatives, embedding threat modeling and security reviews into the architecture and development lifecycle.
- Own vulnerability management, AWS security posture monitoring, incident detection and response, and HIPAA compliance programs.
- Shape cloud architecture decisions — balancing security, cost, and reliability — around zero-trust and defense-in-depth principles.
- Review and document the workflows, staffing, and tooling for each active care program, and produce a written summary of gaps and immediate priorities.
First 90 Days
- Complete a security/configuration gap analysis against CIS, HIPAA, and existing tooling (AWS Inspector, Security Hub, Datadog).
- Identify automation opportunities and standardize AWS account deployment using Control Tower.
- Validate SIEM logging ingestion and flag gaps.
- Evaluate next-gen vulnerability scanners and build a comparison scorecard.
Requirements
- 5+ years of hands-on AWS cloud security and infrastructure engineering (IAM, network security, threat detection, compliance) in production — ideally including building a security program from scratch.
- Deep fluency with AWS security services (GuardDuty, Security Hub, Config, CloudTrail, KMS, Inspector) and IAM policy design.
- Experience with multi-account AWS governance (Control Tower, Organizations, VPC/network design) and container/serverless infrastructure (ECS, EKS, Lambda).
- Familiarity with security frameworks and compliance standards (CIS, HIPAA, HITRUST, AWS Well-Architected).
- US Citizenship is required.
Nice-to-Haves
- Experience building a security program from scratch.
- Familiarity with Datadog, GitHub CI/CD, AI tools for security remediation.
Skills
AWS, IAM, Guardduty, Security Hub, Cloudtrail, Kms, Inspector, Control Tower, Organizations, Vpc, ECS, EKS, AWS Lambda, HIPAA, Cis
Similar jobs
Security Engineering jobsThe Security Engineer will track advanced adversaries targeting frontier AI infrastructure, build intelligence pipelines, conduct threat hunts, and create production detections. The role requires hands-on malware and infrastructure analysis, production programming, and close collaboration with detection and incident response teams.
Security Scientist analyzing attacker and user behavior, building data-driven detections, and leading security investigations and design reviews. Requires strong security and anti-abuse knowledge, SQL fluency, scripting proficiency, and experience with distributed data systems and statistical methods.
Own and build the company’s security program as its first full-time security hire, covering product, cloud, infrastructure, incident response, compliance, and customer trust. The role requires hands-on security engineering and incident leadership, with experience operating SOC 2 or comparable frameworks.
Conduct proactive threat hunting and adversary simulation to uncover financial fraud tactics, enrich threat intelligence, and improve platform controls. The role requires at least five years of relevant cybersecurity, abuse, or trust experience plus strong Python, SQL, investigative, and data-analysis skills.
Conduct offensive security operations, red-team engagements, penetration testing, and adversarial simulations across cloud, endpoint, and bare-metal environments. The role requires at least five years of experience, strong engineering skills, and expertise across multiple security domains.