- Full-time
- Quick Apply
Job#: 3046443
Job Description:
AWS DevSecOps Engineer
Duration: 1+ years extensions expected
Location: Remote (Need to be based in Canada)
Client: Top 5 Bank
Job Description
The Cloud Security DevSecOps Engineer (AWS Focus) will be responsible for maintaining and enhancing AWS cloud security patterns, governance controls, and security automation capabilities.
The role partners directly with security architects and platform teams to deliver scalable cloud security solutions through Policy-as-Code and Infrastructure-as-Code practices.
Responsibilities
Security Engineering
- Update AWS cloud security patterns and guardrails.
- Implement infrastructure security controls.
- Maintain AWS security governance standards.
Policy-as-Code
- Modify and create security policies within IaC repositories.
- Support security configuration automation.
- Manage policy lifecycle through GitHub-based workflows.
AWS Security Controls
Maintain controls related to:
- GuardDuty
- AWS Identity Center
- WAF
- API Gateway
- Network segmentation
Platform Collaboration
- Partner with engineering teams to remediate security gaps.
- Assist with cloud platform modernization initiatives.
- Support secure deployment patterns.
Top Skills Required
- Experience updating and maintaining AWS security policies and patterns using Terraform, including Policy-as-Code concepts.
- Strong knowledge of AWS security services, including GuardDuty, Identity Center, WAF, API Gateway, and identity federation/integration with Microsoft Entra ID.
- Experience reviewing and implementing cloud security configurations, network security controls, and micro-segmentation requirements.
- Hands-on experience working with GitHub repositories and DevSecOps practices, including updating security patterns and configuration templates.
- Ability to independently analyze security requirements, improve existing cloud security patterns, and operate effectively in a fast-changing engineering organization.
Nice-to-Have Skills
- Experience with Wiz Cloud, Wiz Code, Runtime/Defend, and CI/CD security integrations.
- Knowledge of JSON-based AWS policy templates and security automation.
- Understanding of Threat Modeling concepts and secure architecture reviews.
- Experience supporting both AWS and Azure environments in a multi-cloud security organization.
- Background in financial services, fintech, or mature cloud-native organizations with established DevSecOps practices.
Everforth Apex is a world-class IT services company that serves thousands of clients across the globe. When you join Everforth Apex, you become part of a team that values innovation, collaboration, and continuous learning. We offer quality career resources, training, certifications, development opportunities, and a comprehensive benefits package. Our commitment to excellence is reflected in many awards, including ClearlyRateds Best of Staffing® in Talent Satisfaction in the United States and Great Place to Work® in the United Kingdom and Mexico.
Everforth Apex Benefits Overview: In terms of professional development, Everforth Apex hosts an on-demand training program, provides access to certification prep and a library of technical and leadership courses/books/seminars once you have 6+ months of tenure, and certification discounts and other perks to associations that include CompTIA and IIBA.