AWS Security Lead

6 days ago


London, Greater London, United Kingdom Photon Group Full time £60,000 - £120,000 per year
Description

Job Summary:

We are seeking an experienced and highly skilled AWS Security Lead with expertise in Threat Modeling to join our dynamic team. The ideal candidate will have a deep understanding of cloud security principles, threat modeling methodologies, and AWS security best practices. This individual will work closely with development, engineering, and security teams to proactively identify and mitigate potential threats in our cloud-based infrastructure.

The AWS Security Lead (Threat Modeling) will be responsible for conducting risk assessments, defining security requirements, and building threat models to guide security architecture and design in AWS environments. This role requires a strategic thinker with hands-on experience in AWS security, threat modeling, and a passion for securing cloud-native applications.

Key Responsibilities:

Threat Modeling & Risk Assessments

  • Lead the development of threat models for AWS-based applications and infrastructure.
  • Conduct regular threat assessments and risk analyses for new and existing systems.
  • Collaborate with development, architecture, and DevOps teams to design security into the cloud-native architecture.
  • Create detailed reports, diagrams, and other documentation to communicate threat models, risk levels, and mitigation strategies.

Security Architecture & Best Practices

  • Define security requirements for cloud-based applications and infrastructure, ensuring alignment with AWS security best practices.
  • Work closely with engineering teams to integrate security controls throughout the software development lifecycle (SDLC).
  • Evaluate and recommend security tools, platforms, and frameworks for effective threat detection, prevention, and response.

Cloud Security Leadership

  • Serve as the subject matter expert on AWS security and threat modeling methodologies.
  • Provide guidance on cloud security principles, including identity and access management (IAM), data protection, network security, and incident response in AWS environments.
  • Stay current on the latest cloud security trends, AWS security features, and emerging threats.

Collaboration & Cross-functional Communication

  • Partner with other security leaders to ensure security considerations are integrated into all stages of development and deployment.
  • Assist in building a culture of security awareness across engineering and operations teams.
  • Lead workshops and training sessions to raise security awareness and improve threat modeling practices within the organization.

Incident Response & Vulnerability Management

  • Lead post-incident reviews related to security breaches or vulnerabilities in AWS infrastructure.
  • Assist in the identification and resolution of security vulnerabilities related to AWS resources.
  • Collaborate with the Incident Response team to help identify root causes and implement lessons learned.

Required Qualifications:

Education:

  • Bachelor's degree in Computer Science, Information Security, or a related field. Relevant certifications or equivalent practical experience is a plus.

Experience:

  • 7+ years of experience in information security, with a focus on AWS cloud security, threat modeling, and risk management.
  • Proven experience leading threat modeling exercises and designing secure systems within AWS.
  • Proven experience with Wiz, Turbot, Custom Rego Policies, Custom Org Constraints, and AWS GraphQL.
  • Deep knowledge of AWS security services (e.g., AWS IAM, VPC, KMS, GuardDuty, Security Hub, Inspector).
  • Hands-on experience with cloud-native security tools, frameworks, and standards (e.g., CIS AWS Foundations Benchmark, NIST, OWASP).
  • Experience with secure SDLC practices and DevSecOps methodologies.

Technical Skills:

  • Strong knowledge of threat modeling methodologies (e.g., STRIDE, PASTA, OCTAVE).
  • Familiarity with cloud-native security tools for monitoring, vulnerability management, and threat detection.
  • Understanding of encryption, tokenization, and data protection strategies in the cloud.
  • Expertise in IAM and access controls, including role-based access control (RBAC), policies, and permissions in AWS.

Certifications (Preferred):

  • AWS Certified Security – Specialty.
  • Certified Information Systems Security Professional (CISSP).
  • Certified Cloud Security Professional (CCSP).
  • Certified Information Security Manager (CISM).


  • London, Greater London, United Kingdom Amazon Web Services (AWS) Full time £120,000 - £260,000 per year

    DescriptionThe Global Services, Security (GSS) team, a part of Amazon Web Services, leverages the expertise and ingenuity of our builders to establish scalable security solutions for both internal and external customers that drive business outcomes. Our goal of securing the world's workloads and building a brighter future for humanity requires us to focus on...


  • London, Greater London, United Kingdom Amazon Web Services (AWS) Full time £130,000 - £170,000 per year

    DescriptionThe Global Services, Security (GSS) team, a part of Amazon Web Services, leverages the expertise and ingenuity of our builders to establish scalable security solutions for both internal and external customers that drive business outcomes. Our goal of securing the world's workloads and building a brighter future for humanity requires us to focus on...


  • London, Greater London, United Kingdom Amazon Web Services (AWS) Full time £60,000 - £120,000 per year

    DescriptionWould you like to help implement innovative cloud computing solutions and solve the most complex problems? Are you excited by the prospect of building and running the world's largest cloud computing infrastructure to provide a better world for future generations?Amazon Web Services (AWS) builds and operates some of the largest internet...


  • London, Greater London, United Kingdom Amazon Web Services (AWS) Full time £80,000 - £120,000 per year

    DescriptionAre you ready to shape the future of secure artificial intelligence? The AWS Generative AI Innovation Center stands at the forefront of the AI revolution, where we're not just implementing technology – we're defining how the world's largest organizations will safely harness the power of generative AI.As businesses race to adopt transformative...


  • London, Greater London, United Kingdom Amazon Web Services (AWS) Full time €60,000 - €120,000 per year

    DescriptionAmazon Web Services (AWS) is the leading cloud provider, providing virtualised infrastructure, storage, networking, messaging, and many other services to customers all over the world. AWS runs a globally distributed environment, operating at massive levels of scale. Businesses, from start-ups to enterprises, run their operations and applications...

  • Security Lead

    6 days ago


    London, Greater London, United Kingdom Photon Group Full time £80,000 - £120,000 per year

    DescriptionIntroduction:We are seeking a highly skilled and experienced AWS Security Lead to join our team. This position will be crucial in overseeing the security architecture, implementation, and continuous monitoring of our AWS cloud infrastructure. The ideal candidate will possess extensive knowledge of AWS services, security best practices, and a...


  • London, Greater London, United Kingdom Amazon Web Services (AWS) Full time £60,000 - £120,000 per year

    DescriptionAmazon Web Services (AWS) serves customers and developers who rely on storage, compute, and our other service capabilities. Our customers trust us to handle their data with air-tight security measures, which is something that we guarantee.We are looking for a Data Center Security Specialist to join our expanding Data Center Operations team. Our...


  • London, Greater London, United Kingdom Amazon Full time £60,000 - £120,000 per year

    The Global Services, Security (GSS) team, a part of Amazon Web Services, leverages the expertise and ingenuity of our builders to establish scalable security solutions for both internal and external customers that drive business outcomes. Our goal of securing the world's workloads and building a brighter future for humanity requires us to focus on reliable...


  • London, Greater London, United Kingdom Amazon Web Services Full time £80,000 - £120,000 per year

    DESCRIPTIONThe Global Services, Security (GSS) team, a part of Amazon Web Services, leverages the expertise and ingenuity of our builders to establish scalable security solutions for both internal and external customers that drive business outcomes. Our goal of securing the world's workloads and building a brighter future for humanity requires us to focus on...


  • London, Greater London, United Kingdom Amazon Full time £120,000 - £180,000 per year

    The Global Services, Security (GSS) team, a part of Amazon Web Services, leverages the expertise and ingenuity of our builders to establish scalable security solutions for both internal and external customers that drive business outcomes. Our goal of securing the world's workloads and building a brighter future for humanity requires us to focus on reliable...