Security Infrastructure Engineer
Hands-on engineer owning security, scalability, and cost optimization of AWS infrastructure. Hardens IAM, networking, secrets management; leads threat modeling, incident response, and architecture reviews for high-sensitivity legal systems. Requires 5+ years AWS production experience.
About the job
What You'll Own
Infrastructure Security
- Design and enforce least-privilege IAM across services
- Implement permission boundaries and SCP strategy
- Reduce attack surface across networking and service exposure
- Improve secrets management and KMS key segmentation
- Lead threat modeling across core systems
- Design blast-radius containment strategies
Detection & Response
- Strengthen logging, monitoring, and anomaly detection
- Ensure logs are immutable and auditable
- Build and test incident response playbooks
- Review new infrastructure designs for security risks
Scale & Cost
- Optimize AWS architecture for reliability and efficiency
- Improve Lambda/SQS concurrency and scaling patterns
- Evaluate and improve RDS scaling strategy
- Drive principled tradeoffs between isolation, performance, and cost
What We're Looking For
- 5+ years operating AWS infrastructure in production
- Deep IAM expertise (roles, policies, trust relationships, STS)
- Strong AWS networking knowledge (VPC, PrivateLink, Security Groups)
- Experience designing multi-account AWS environments
- Hands-on experience responding to real security incidents
- Strong understanding of cloud attack vectors and privilege escalation
- Experience reducing cloud cost without compromising security
- Comfortable working directly in CDK/Terraform and reviewing infrastructure code
Strong plus: Experience in legal, fintech, government, or other high-sensitivity environments.
Skills
AWS, IAM, Vpc, Privatelink, Security Groups, Cdk, Terraform, Kms, AWS Lambda, SQS, Rds, Guardduty
Similar jobs
Security Engineering jobsThe Application Security Engineer will embed security practices throughout the SaaS software development lifecycle, including threat modeling, automated testing, vulnerability remediation, and incident response. The role requires 5+ years of application or product security experience and expertise with DevSecOps workflows, web applications, and CI/CD automation.
The Cyber Threat Intel Analyst tracks, investigates, attributes, and reports on advanced threats targeting cloud, AI, and developer environments. The role requires at least three years of security or threat research experience and strong technical analysis and writing skills.
The GRC Analyst will operate and mature security and compliance programs across major privacy and security frameworks, supporting risk assessments, access reviews, third-party risk, control monitoring, and audits. The role requires 3–5 years of GRC or information security experience and strong cross-functional communication.
Manages FedRAMP compliance for a cloud service provider by implementing security controls, supporting audits and remediation, maintaining SSP documentation, and coordinating authorization activities. Requires 5+ years of IT audit or compliance experience and hands-on FedRAMP ATO leadership.
Develops safety requirements, analyses, and fail-operational architectures for autonomous-vehicle sensing and perception systems. The role requires 3+ years analyzing safety-critical systems and familiarity with functional-safety standards, sensing hardware, perception, and cross-functional systems engineering.