SonicJobs Logo
Left arrow iconBack to search

Senior AWS Cloud Security Consultant

HIGH BRIDGE CONSULTING LLC
Posted 10 hours ago, valid for 14 days
Location

New York, NY, US

Salary

$100,000 - $160,000 per year

Contract type

Full Time

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

Sonic Summary

info
  • Our client, a 3rd-generation management consulting firm, is hiring a Senior AWS Cloud Security Consultant for a full-time position in Manhattan, NY.
  • The role requires 8+ years of experience in cloud engineering, cloud security, or infrastructure security, with a focus on AWS security architecture and governance.
  • Key responsibilities include designing enterprise cloud security controls, evaluating AWS services for security risks, and implementing preventive controls using various AWS policies and frameworks.
  • The position offers an opportunity to tackle complex cloud security challenges in highly regulated environments, ensuring compliance and operational rigor.
  • Salary details are not explicitly mentioned, but candidates should possess strong hands-on experience with tools like Open Policy Agent and Terraform.
Our client is a 3rd-generation management consulting firm that is expanding its team and looking to hire a Senior AWS Cloud Security Consultant on a full-time, permanent basis. This will be in Manhattan, NY.

Summary

The client is seeking a Senior AWS Cloud Security Consultant to help design and enforce enterprise cloud security controls within a highly regulated environment. This role sits at the intersection of cloud security architecture, policy engineering, and AWS governance, with a primary focus on preventing data exfiltration through policy-as-code, data perimeter controls, and proactive threat modeling.
You will evaluate AWS services before they are introduced into production environments, identify potential security risks at the API and configuration level, and implement preventive controls using AWS Organizations policies, IAM guardrails, and Rego-based policy frameworks.
This is an opportunity to work on complex cloud security challenges supporting critical business platforms where security, compliance, and operational rigor are non-negotiable.

Key Responsibilities
  • 8+ years of cloud engineering, cloud security, or infrastructure security experience.
  • Deep expertise in AWS security architecture and governance.
  • Demonstrated experience performing API-level threat modeling for AWS services.
  • Strong hands-on experience with:
  1. Open Policy Agent (OPA)
  2. Rego policy development
  3. Policy testing and validation
  • Advanced knowledge of:
  1. AWS IAM
  2. AWS Organizations
  3. SCPs and RCPs
  4. Data perimeter architecture
  • Experience designing least-privilege access models in regulated environments.
  • Strong understanding of cloud security controls, compliance requirements, and enterprise governance frameworks.

Preferred Qualifications
  • Experience with Kivera.io, Cloudflare One, or similar cloud API policy enforcement platforms.
  • Experience with Regal policy linting and OPA coverage reporting.
  • Infrastructure-as-Code expertise using Terraform.
  • CI/CD experience with:
  1. GitHub Actions
  2. OIDC federation
  3. Policy validation pipelines
  4. Approval-based deployment models
  • Experience with:
  1. Checkov
  2. Conftest
  3. Policy Sentry
  • Cloudsplaining
  • Strong AWS observability experience using:
  1. CloudWatch
  2. CloudTrail
  3. VPC Flow Logs
  • Amazon EKS security and governance experience.
  • Experience working directly with AWS Support and Technical Account Managers.
  • Financial services, banking, capital markets, or other highly regulated industry experience.

Technical Environment
  • AWS Organizations with SCP and RCP governance
  • Open Policy Agent (OPA)
  • Rego policy language
  • Kivera.io policy enforcement platform
  • Cloudflare One
  • Terraform
  • GitHub Actions
  • CloudWatch
  • CloudTrail
  • VPC Flow Logs
  • Amazon EKS
  • Enterprise Data Perimeter Architecture



Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.