Home/Job List/SipraHub - AWS Cloud Engineer - Network Security & IOM Remediation (India)
Siprahub

SipraHub - AWS Cloud Engineer - Network Security & IOM Remediation (India)

Siprahub

India
Contract
Posted 1 month ago

Job Description & Responsibilities

Role : AWS Cloud Engineer(Network Security & IOM Remediation)

Level:- Senior (Individual Contributor)

Experience:- 10 Years to 16 Years

Duration:- Long-term / Ongoing

Location :- Remote

About the Role

We are seeking a contract AWS Cloud Engineer to own the resolution of security findings and Indicators of Misconfiguration (IOMs) across a multi-account AWS environment.

You will architect, harden, and maintain the cloud networking and infrastructure layer - VPCs, Transit Gateways, security groups, IAM policies, and encryption controls - while systematically triaging and remediating findings surfaced by CrowdStrike Falcon Cloud Security, AWS Security Hub, and GuardDuty.

You will partner with a US-based Platform Engineering team (which owns EKS clusters, CI/CD pipelines, and application workloads) to ensure the underlying AWS infrastructure meets security baselines and compliance requirements.

This is a fully remote, long-term contract engagement requiring a minimum of 4 hours daily overlap with US Eastern business hours. Robust written and verbal English communication is essential - you will collaborate daily with US-based engineers and stakeholders via Teams, Jira, and Confluence.

Core Responsibilities

Security Finding Triage & IOM Remediation

  • Own the full lifecycle of IOMs and security findings: triage, prioritize, remediate, validate, and document across all AWS accounts.
  • Remediate misconfigurations across VPCs, security groups, NACLs, S3 bucket policies, IAM roles/policies, encryption settings, and logging configurations.
  • Build automated remediation workflows using Lambda, Step Functions, or EventBridge to address recurring finding patterns at scale.
  • Perform root cause analysis on IOMs and implement preventive controls (SCPs, Config rules, guardrails) to prevent recurrence.
  • Track remediation progress against severity-based SLAs and provide regular reporting to security leadership.
  • Coordinate with InfoSec and the CrowdStrike team on finding validation, exception requests, and risk acceptance documentation.

Network Architecture & Security

  • Design and implement secure VPC architectures: subnet segmentation, route tables, NAT gateways, VPC peering, and Transit Gateway topologies across a multi-account AWS Organizations structure.
  • Architect and manage network security controls: security groups, NACLs, AWS Network Firewall policies, and prefix list management for hybrid connectivity.
  • Implement and maintain hybrid connectivity (Direct Connect, Site-to-Site VPN) with appropriate encryption and access controls.
  • Design internal ALB/NLB ingress patterns with proper TLS termination, certificate management (ACM), and origin restriction via security group prefix lists.
  • Configure and manage PrivateLink endpoints, VPC endpoint policies, and DNS resolution (Route 53 private/public hosted zones) for secure service access.
  • Enforce network segmentation aligned with zero-trust principles - no public-facing resources without explicit approval and compensating controls.

IAM & Access Architecture

  • Design and enforce IAM strategies following least-privilege principles: permission boundaries, SCPs, role trust policies, and condition keys.
  • Audit and remediate overly permissive IAM policies, cross-account trust relationships, and unused credentials.
  • Implement and maintain OIDC-based authentication patterns for CI/CD runners and workload identities (IRSA for EKS).
  • Manage AWS Organizations SCPs and Control Tower guardrails to enforce security baselines across all accounts.

Infrastructure-as-Code & Compliance

  • Implement and enforce IaC security standards using Terraform with policy-as-code validation (OPA, Sentinel, cfn-guard, tfsec).
  • Author and maintain AWS Config rules and conformance packs for continuous compliance monitoring.
  • Build and maintain Terraform modules for secure-by-default infrastructure patterns (VPCs, security groups, IAM roles) that application teams consume.
  • Ensure all infrastructure changes flow through code review and automated validation - no manual console changes in production accounts.

Monitoring & Observability

  • Configure and maintain VPC Flow Logs, CloudTrail, DNS query logging, and S3 access logging with centralized analysis (Athena, CloudWatch Logs Insights).
  • Build dashboards and alerting for security posture metrics: open finding counts, MTTR trends, compliance drift, and SLA adherence.
  • Participate in security incident response related to network intrusion, unauthorized access, or data exfiltration indicators.
  • Maintain audit trails and compliance evidence for SOC 2 / PCI workloads as applicable.

Required Technical Skills

AWS Networking & Architecture

  • Over all 10+ years of IT experience and 5+ years of AWS experience with deep expertise in networking services: VPC, Transit Gateway, Direct Connect, Route 53, ALB/NLB, CloudFront, PrivateLink, and Network Firewall.
  • Multi-account AWS Organizations architecture: account vending, centralized networking, shared services patterns, and cross-account resource access.
  • Strong understanding of TCP/IP networking, DNS resolution, TLS/mTLS, and network security protocols.
  • Practical experience with EKS networking: VPC CNI, security groups for pods, network policies, and ingress controller integration (AWS ALB Controller).

Security & Compliance

  • 3+ years working directly with CSPM tools (CrowdStrike Falcon Cloud Security, AWS Security Hub, or equivalent) and remediating findings at scale (hundreds/thousands of IOMs).
  • Hands-on IAM expertise: policy authoring, permission boundaries, SCPs, role trust policies, condition keys, and cross-account access patterns.
  • Working knowledge of compliance frameworks (CIS AWS Benchmarks, NIST 800-53, SOC 2) and how they map to specific AWS controls.
  • Experience with AWS native security services: GuardDuty, Inspector, Macie, Config, CloudTrail, and Security Hub.

Infrastructure-as-Code

  • Terraform (required): module authoring, state management, workspace patterns, and CI/CD integration for infrastructure pipelines.
  • Policy-as-code: OPA/Rego, tfsec, checkov, cfn-guard, or HashiCorp Sentinel for pre-deployment validation.
  • Git-based workflows for infrastructure changes with peer review and automated plan/apply patterns.

Automation & Scripting

  • Python or Go for building security automation, remediation lambdas, and custom Config rules.
  • Bash scripting for operational automation and runbook implementation.
  • Experience with AWS SDK (boto3) and CLI for programmatic infrastructure management.

Communication & Collaboration

  • Professional English proficiency - written and verbal - sufficient for daily technical collaboration with US-based engineers, product managers, and InfoSec stakeholders.
  • Availability for a minimum 4-hour daily overlap with US Eastern business hours (8am-6pm EST/EDT); core collaboration windows will be scheduled within this window.
  • Comfort working in a distributed, async-first team: proactive written status updates, well-documented pull requests and runbooks, and clear escalation communication.
  • Proficiency with standard remote collaboration tooling: Microsoft Teams (chat, video, channels), Jira (ticket tracking and sprint ceremonies), and Confluence (documentation).
  • Experience working as an external contractor or vendor resource embedded in a client engineering team; ability to ramp independently with minimal hand-holding.

Preferred / Nice-to-Have

  • AWS Solutions Architect Professional or AWS Security Specialty certification.
  • Experience with AWS Network Firewall, Gateway Load Balancer, or third-party NGFW integration (Palo Alto, Fortinet).
  • Background in automating security remediation at scale - event-driven architectures that auto-resolve known finding patterns.
  • Experience with eBPF-based network observability or runtime security tools.
  • Familiarity with Kubernetes security primitives (Pod Security Standards, RBAC, network policies) from an infrastructure perspective.
  • Experience working in regulated environments (SOC 2, PCI-DSS, HIPAA) with compliance-as-code tooling.
  • Knowledge of DNS security (DNSSEC, DNS firewall, Route 53 Resolver rules) and DDoS mitigation (Shield Advanced, WAF).

Success Metrics (6-12 Months)

  • Critical and high IOMs reduced by 80%+ with documented root cause and preventive controls in place for each resolved finding category.
  • Mean time to remediate (MTTR) for critical findings under 72 hours; high findings under 14 days - consistently meeting SLA targets.
  • All VPCs, security groups, and IAM roles audited and hardened; zero public-facing resources without explicit approval and compensating controls.
  • Secure-by-default Terraform modules published and adopted by platform teams - new infrastructure deploys pre-validated against CIS benchmarks.
  • Automated remediation workflows handling 30%+ of recurring finding patterns without manual intervention.
  • Continuous compliance dashboards operational with real-time visibility into security posture across all accounts.
  • Network architecture documented end-to-end: topology diagrams, connectivity patterns, firewall rules, and data-flow documentation current and maintained.

Required Skills

PythonGoAWSKubernetesGitCI/CDTerraformJIRALeadership

Job Details

Employment TypeContract
Work ModeRemote
Experience1015 years
Positions1

Posted by

N/A

Posted on:

10 Jul 2026

About Siprahub

More open roles

Browse all jobs →