AWS Security Engineer

schedule10 hours ago
badgeEmployment:Full-time
historyMinimum experience:4+ years
Apply Nowopen_in_new

Job description

AWS Security Engineer

Location: Singapore

Experience: Minimum 4 years of relevant experience

About the Role

We are looking for an AWS Security Engineer to design, implement, and maintain security controls across cloud infrastructure and workloads. You will assess cloud security risks, strengthen security architecture, automate security operations, and support compliance with organisational and project requirements.

You will work closely with Cloud, DevOps, Application, Engineering, and Operations teams to embed security throughout the development and operations lifecycle. The role requires practical technical expertise, strong analytical skills, and the ability to translate security requirements into effective solutions.

Key Responsibilities

Cloud Security Architecture and Engineering

  • Conduct cloud security assessments, architecture reviews, and risk assessments for AWS environments, including public sector and regulated workloads where applicable.
  • Design, implement, and maintain secure cloud architectures, landing zones, account segregation, guardrails, and baseline configurations.
  • Harden cloud infrastructure, services, virtual machines, containers, and platform components in accordance with approved security standards and benchmarks.
  • Implement and manage identity and access controls, including least privilege, federation, privileged access, secrets management, and encryption key management.
  • Configure network security controls, including segmentation, firewalls, web application firewalls, DDoS protection, private connectivity, and encryption.

Security Monitoring and Remediation

  • Configure and maintain cloud security monitoring, logging, and alerting to support threat detection, investigation, and incident response.
  • Perform vulnerability assessments and configuration reviews, prioritise findings, and track remediation through to closure.
  • Collaborate with Engineering and Operations teams to investigate security findings and implement corrective actions.
  • Improve security processes, operational playbooks, and tools to strengthen cloud security posture and operational efficiency.

Security Automation and DevSecOps

  • Develop scripts and Infrastructure as Code to automate security hardening, monitoring, compliance checks, and remediation.
  • Integrate security controls and automated security testing into CI/CD pipelines and software delivery processes.
  • Support container and Kubernetes security, including image scanning, runtime protection, and secrets management.
  • Undertake related DevSecOps or Cloud Platform Security responsibilities as required by project needs.

Governance and Collaboration

  • Review cloud environments for compliance with security policies, cloud governance standards, data residency controls, and applicable public sector requirements.
  • Maintain security documentation, assessment findings, configuration standards, and remediation records.
  • Work with technical teams and stakeholders to understand requirements, communicate risks, and recommend practical security solutions.

Required Qualifications and Experience

  • Degree or Diploma in Computer Science, Computer Engineering, Electronics Engineering, Information Technology, or a related discipline.
  • Minimum 4 years of experience in cloud security engineering, security assessments, risk analysis, and remediation.
  • Hands-on experience securing AWS infrastructure and workloads.
  • Working knowledge of AWS security and governance services, such as IAM, Organizations, Control Tower, KMS, CloudTrail, AWS Config, GuardDuty, Security Hub, Inspector, and WAF.
  • Practical understanding of identity and access management, network security, encryption, secrets management, and cloud logging.
  • Ability to assess security configurations, investigate findings, and work with technical teams to resolve vulnerabilities.
  • Strong analytical and problem-solving skills, with the ability to work independently and manage competing priorities.
  • Clear communication skills in English and the ability to explain technical security issues to different stakeholders.

Preferred Qualifications and Experience

  • Experience with Singapore Government Commercial Cloud (GCC), public sector, or other regulated cloud environments.
  • Experience designing secure landing zones, multi-account architectures, and cloud governance controls.
  • Experience with Infrastructure as Code tools such as Terraform or AWS CloudFormation.
  • Experience with CI/CD tools such as GitLab, GitHub Actions, Jenkins, or Azure DevOps, preferably within an Agile environment.
  • Familiarity with cloud security posture management (CSPM), cloud workload protection (CWPP), or cloud-native application protection platform (CNAPP) tools, such as Wiz, Prisma Cloud, or equivalent.
  • Experience with container and Kubernetes security, particularly Amazon EKS.
  • Familiarity with PAM, zero trust, PKI, SIEM/SOAR, and incident response.
  • Experience with SAST, DAST, software composition analysis, and secrets scanning.
  • Familiarity with CIS Benchmarks, NIST, ISO 27001, SOC 2, PCI DSS, or applicable public sector security requirements.
  • Experience securing Azure environments using services such as Microsoft Entra ID, Azure Policy, Key Vault, Defender for Cloud, Microsoft Sentinel, or Azure Firewall.
  • Relevant certifications such as AWS Certified Security – Specialty, AWS Certified Solutions Architect, CCSP, CCSK, CISSP, or CISM.
  • Security testing certifications such as CEH, OSCP, GPEN, or GWAPT.

Skills mentioned

Apply for this job

Use the application link supplied with this listing to apply to VINOVA. Check the destination before entering personal information.

Apply Nowopen_in_new