AWS Security Engineer

14 hours ago


City Of London, United Kingdom Op de Praatstoel Full time

AWS Security Engineer at Op de Praatstoel. Job Summary As AWS security engineer you will lead the remediation of cloud and application vulnerabilities across the AWS environment. You will work closely with Developers, Data Engineers, and the AWS Security Lead to validate findings, prioritise risk, implement fixes, and strengthen security controls. A strong understanding of software development, DevSecOps practices, and vulnerability management is essential. Key Responsibilities Own end-to-end remediation of AWS and workload vulnerabilities: confirm findings, assess impact, prioritise actions, and track through to closure. Partner with Developers and Data Engineers to implement secure fixes in code, infrastructure, and delivery pipelines (IaC, containers, serverless, OS/packages). Work with the AWS Security Lead to ensure remediation aligns with AWS security controls, internal risk policies, and compliance requirements. Improve and automate vulnerability management processes (e.g., scanning coverage, SLAs, exception handling, evidence capture). Embed security into CI/CD and the SDLC: shift-left reviews, secure coding guidance, dependency management, and pipeline guardrails. Configure, tune, and operate AWS security services (e.g., GuardDuty, Security Hub, Inspector, Config, IAM Access Analyzer) to reduce exposure and prevent repeat issues. Produce clear remediation guidance, runbooks, and reporting dashboards for both technical and non-technical stakeholders. Support incident response and post-remediation validation where high-risk findings are exploited or trending. AWS / Cloud Security Experience Deep, hands-on AWS security experience across IAM, networking, compute, storage, serverless, and managed data services. Strong knowledge of the AWS Well-Architected Security Pillar and common control frameworks (CIS AWS Foundations, NIST/ISO-aligned controls). Demonstrable experience implementing and validating AWS security controls, including: IAM least privilege, roles, permission boundaries, SCPs, and access reviews VPC segmentation, security group/NACL design, private endpoints, WAF/Shield Encryption in transit and at rest using KMS, TLS, and secrets management Logging and monitoring: CloudTrail, CloudWatch, Config, centralised SIEM patterns Threat detection and posture management using AWS native services Dev / DevSecOps / Vulnerability Management Strong understanding of modern SDLC, CI/CD, and DevSecOps approaches. Proven experience managing the full vulnerability lifecycle: triage, prioritisation (CVSS/EPSS/KEV), remediation, verification, and reporting. Comfortable remediating a wide range of findings: OS/package CVEs, container images, third‑party libraries, serverless runtimes, and cloud misconfigurations. Able to translate security findings into clear, practical tasks for engineering teams and coach on secure implementation. Engineering & Tooling Infrastructure as Code: Terraform and/or CloudFormation; able to review and fix security weaknesses in IaC. Scripting/automation skills in Python, Bash, or similar to streamline remediation and control validation. Familiarity with container and serverless security (ECR, ECS/EKS, Lambda, image scanning, runtime hardening). Experience with common vulnerability and scanning tools (e.g., AWS Inspector/Security Hub, Snyk, Trivy, Dependabot, Prisma/Qualys/Tenable, etc.). Advantageous Security certifications such as AWS Security Specialty, AWS Solutions Architect, or equivalent. Experience supporting data platforms on AWS (Glue, EMR, Redshift, Athena, RDS, OpenSearch, Kafka/MSK). Knowledge of secure coding practices in Python/Node/Java or your core development stack. Experience with policy‑as‑code and automated control enforcement (OPA/Conftest, tfsec, Checkov). Personal Attributes Highly collaborative and pragmatic; you should enjoy working directly with engineers to ship secure fixes quickly. Strong risk judgement and the ability to balance urgency with operational impact. Clear communicator who can write concise remediation guidance and present progress to stakeholders. Ownership mindset: you drive remediation through to completion, not just identification. Job Details Seniority level: Mid‑Senior level Employment type: Contract Job function: Information Technology Industries: Computer and Network Security This role is expected to fall outside IR35 and will require on-site attendance 2‑3 days per week in central London (EC2 offices). If you cannot attend then please do not apply as this is mandatory. #J-18808-Ljbffr



  • City Of London, United Kingdom Amazon Web Services (AWS) Full time

    Senior Security Engineer, AWS Security Amazon Web Services (AWS) is the leading cloud provider, offering virtualized infrastructure, storage, networking, messaging, and many other services worldwide. AWS runs a globally distributed environment at massive scale, supporting customers from startups to enterprises on our multi‑tenant infrastructure. Key...


  • City Of London, United Kingdom Amazon Web Services (AWS) Full time

    Job DescriptionAmazon Web Services (AWS) is the leading cloud provider, delivering virtualized infrastructure, storage, networking, messaging, and a wide range of services to customers worldwide. AWS operates a globally distributed environment at massive scale, enabling businesses from startups to enterprises to run their operations and applications on its...


  • City Of London, United Kingdom Amazon Web Services (AWS) Full time

    AWS Security Assurance Services, Practice Manager, AWS Security Assurance Services Join to apply for the AWS Security Assurance Services, Practice Manager, AWS Security Assurance Services role at Amazon Web Services (AWS) 4 days ago Be among the first 25 applicants Get AI-powered advice on this job and more exclusive features. Description The Global...


  • City Of London, United Kingdom Amazon Web Services (AWS) Full time

    Security Operations Centre Manager , AWS SecurityJoin to apply for the Security Operations Centre Manager , AWS Security role at Amazon Web Services (AWS)Amazon Web Services (AWS) is the leading cloud provider, providing virtualised infrastructure, storage, networking, messaging, and many other services to customers all over the world. AWS runs a globally...


  • City Of London, United Kingdom AWS EMEA SARL (UK Branch) Full time

    The Global Services, Security (GSS) team, a part of Amazon Web Services, leverages the expertise and ingenuity of our builders to establish scalable security solutions for both internal and external customers that drive business outcomes. Our goal of securing the world’s workloads and building a brighter future for humanity requires us to focus on reliable...

  • Systems Engineer, AWS

    2 weeks ago


    City Of London, United Kingdom AWS EMEA SARL (UK Branch) Full time

    Would you like to help implement innovative cloud computing solutions and solve the most complex technical problems? Are you excited by the prospect of building and running the world's largest cloud computing infrastructure to provide a better world for future generations? Amazon Web Services (AWS) builds and operates some of the largest internet...


  • City Of London, United Kingdom BT Security Full time

    A leading cybersecurity provider in London seeks a Cloud Engineering Specialist to implement core AWS infrastructure and security services. You will work directly with clients to understand requirements, design secure cloud solutions, and lead junior team members. This full-time role offers an onsite working environment with comprehensive benefits, including...


  • City Of London, United Kingdom UBDS Group Full time

    Rayo, a UBDS Group company, is looking for a hands‑on, Security Cleared AWS Security Engineer to support the secure operation and continual improvement of cloud infrastructure. This role focuses on the technical implementation of security controls, monitoring AWS environments, and responding to security incidents. The successful candidate will play a key...


  • City Of London, United Kingdom Amazon Full time

    Overview Amazon Web Services (AWS) is the leading cloud provider, providing virtualized infrastructure, storage, networking, messaging, and many other services to customers all over the world. AWS runs a globally distributed environment, operating at massive levels of scale. Businesses, from start-ups to enterprises, run their operations and applications on...


  • City Of London, United Kingdom UBDS Group Full time

    A leading technology consulting firm in the UK is seeking an experienced AWS Security Engineer to join their team. The successful candidate will be responsible for implementing security controls, monitoring AWS environments, and responding to incidents. Key requirements include SC Clearance, hands-on AWS experience, and strong scripting skills. This role...