About the job
AWS Security & Vulnerability Remediation Engineer (DevSecOps / Cloud Security)
Initial Contract Duration: 3 Months (Outside IR35)
Role Overview
We are seeking a skilled AWS Security Engineer to spearhead the remediation of vulnerabilities within our cloud and application infrastructure on AWS. Collaborating closely with Developers, Data Engineers, and our AWS Security Lead, you will validate security findings, prioritize risks, implement remedial measures, and enhance our security framework. Your expertise in AWS security is paramount, complemented by a solid understanding of software development, DevSecOps methodologies, and effective vulnerability management.
Key Responsibilities
- Lead the complete remediation process for AWS and workload vulnerabilities: verify findings, evaluate impact, prioritize actions, and ensure closure.
- Collaborate with Developers and Data Engineers to integrate secure solutions in code, infrastructure, and CI/CD pipelines (IaC, containers, serverless, OS/packages).
- Coordinate with the AWS Security Lead to ensure remediation processes comply with AWS security standards, internal risk policies, and regulatory requirements.
- Enhance and automate vulnerability management workflows (e.g., scanning coverage, SLAs, exception management, evidence collection).
- Incorporate security throughout the CI/CD pipeline and Software Development Life Cycle (SDLC): implement shift-left reviews, provide secure coding guidance, manage dependencies, and establish pipeline guardrails.
- Configure, optimize, and manage AWS security services (e.g., GuardDuty, Security Hub, Inspector, Config, IAM Access Analyzer) to mitigate risks and prevent recurrent issues.
- Generate clear remediation documentation, runbooks, and reporting dashboards tailored for both technical and non-technical audiences.
- Assist in incident response and validation efforts post-remediation for high-risk vulnerabilities.
Required Qualifications
AWS / Cloud Security Expertise (Essential)
- Extensive hands-on experience with AWS security, covering IAM, networking, compute, storage, serverless, and managed data services.
- Profound understanding of the AWS Well-Architected Security Pillar and relevant control frameworks (CIS AWS Foundations, NIST/ISO-aligned controls).
- Demonstrated experience in implementing and validating AWS security controls, including:
- IAM least privilege, roles, permission boundaries, SCPs, and access audits
- VPC segmentation, security group/NACL design, private endpoints, WAF/Shield
- Data encryption in transit and at rest using KMS, TLS, and secrets management solutions
- Monitoring and logging: CloudTrail, CloudWatch, Config, centralized SIEM configurations
- Threat detection and security posture management using AWS native tools
Dev / DevSecOps / Vulnerability Management Proficiency (Essential)
- Strong grasp of modern Software Development Life Cycle (SDLC), CI/CD practices, and DevSecOps methodologies.
- Proven track record in managing...

