Application Security Engineer – AWS
Role: Certified - Application Security Engineer (AWS)
Level: Senior (8–12 years)
Location: Remote
Role Summary
We are seeking an experienced Application Security Engineer to secure applications built and operated on AWS. You will embed security across the SDLC — from secure design and code review through CI/CD integration, runtime protection, and incident response — working closely with development, DevOps, and client security teams.
Key Responsibilities
- Perform threat modeling and secure design reviews for applications and microservices deployed on AWS (EC2, ECS/EKS, Lambda, API Gateway).
- Integrate and operate security tooling in CI/CD pipelines: SAST, DAST, SCA/dependency scanning, container image scanning, and IaC scanning.
- Configure and manage AWS-native security services: WAF, Shield, GuardDuty, Inspector, Security Hub, KMS, Secrets Manager, IAM.
- Define and enforce least-privilege IAM policies, secrets management standards, and encryption (at rest/in transit) across workloads.
- Conduct secure code reviews and vulnerability triage; partner with dev teams on remediation and secure coding practices (OWASP Top 10, CWE).
- Harden infrastructure-as-code (Terraform/CloudFormation) using policy-as-code (OPA, Checkov) and guardrails (SCPs, Config rules).
- Support penetration test coordination, findings remediation, and audit/compliance requirements (SOC 2, ISO 27001, PCI-DSS as applicable).
- Respond to application-layer security incidents; contribute to detection rules and runbooks.
- Mentor engineers and champion DevSecOps culture across delivery teams.
Required Skills & Experience
- 8+ years in application security / product security, with 3+ years securing workloads on AWS.
- Hands-on expertise with AWS security services: IAM, WAF, GuardDuty, Inspector, Security Hub, KMS, Secrets Manager, CloudTrail.
- Strong knowledge of OWASP Top 10, API security, authentication/authorization patterns (OAuth 2.0, OIDC, SAML).
- Experience with security tooling: SonarQube/Checkmarx/Veracode (SAST), Snyk/Prisma/Aqua (SCA & containers), Burp Suite/OWASP ZAP (DAST).
- Proficiency in at least one language for automation — Python, Go, or similar; ability to read Java/Node.js/.NET application code.
- Experience securing containerized (Docker, EKS/ECS) and serverless (Lambda) architectures.
- IaC security: Terraform or CloudFormation with Checkov/tfsec/cfn-nag.
- CI/CD security integration: GitHub Actions, GitLab CI, Jenkins, or AWS CodePipeline.
- Certifications: AWS Certified Security – Specialty (strongly preferred); CSSLP, OSWE, or CISSP.
Preferred Qualifications
- Experience with CNAPP platforms (Wiz, Prisma Cloud, CrowdStrike Falcon Cloud).
- Threat modeling frameworks (STRIDE, PASTA) and secure SDLC program experience.
- Prior work in a client-facing or consulting/delivery environment with enterprise customers.
- Exposure to compliance frameworks: SOC 2, ISO 27001, PCI-DSS, HIPAA, FedRAMP.
Soft Skills
- Strong communication — able to explain risk and remediation to both engineers and business stakeholders.
- Pragmatic, risk-based mindset; balances security rigor with delivery velocity.
- Self-driven; comfortable operating in ambiguous, fast-moving programs.
Education
Bachelor's degree in Computer Science, Information Security, or equivalent practical experience.