Senior Cloud Security Engineer
You will own the security posture of the AWS infrastructure for a cryptocurrency derivatives exchange. You will verify that infrastructure implementations match the security model, build automated compliance checks and drift detection, review Terraform changes for IAM, SCP, and network security gaps, manage credential rotation and privileged access, write OpenSearch SIEM detection rules, create security evidence dashboards, and evaluate security tooling.
Responsibilities
- Verify that infrastructure implementations continuously match the security model
- Build automated compliance checks and drift detection
- Review Terraform pull requests for IAM, SCP, and network security gaps before production deployment
- Own credential rotation, PAM, just-in-time access, and session recording
- Write and tune detection rules in OpenSearch SIEM
- Build evidence dashboards that demonstrate security posture to non-security leadership
- Evaluate security tooling and document build-versus-buy recommendations and tradeoffs
Requirements
- 5+ years of experience in infrastructure or security engineering, including at least 2 years focused on AWS security
- Advanced understanding of IAM policy evaluation logic, permission boundaries, and cross-account access patterns
- Experience building automated security checks that run in production
- Ability to read and critically review Terraform for security posture
- Experience operating PAM tooling or credential rotation in production
- Ability to own a security domain end-to-end without constant direction
- Experience with multi-account AWS Organizations or SCPs is advantageous
- Production experience writing SIEM detection rules is advantageous
- Experience in regulated fintech, exchange, or payments environments is advantageous
- Experience building security evidence or reporting used by non-security staff is advantageous