AWS Security Operator
Position Summary
The Security Operator plays a crucial role in maintaining the security posture of an organization's AWS environment. They combine operational security skills with AWS-specific knowledge to protect cloud resources, respond to incidents, and ensure compliance with security standards and regulations.
Job Description
- Monitor AWS environments for security threats and anomalies using tools like AWS CloudWatch, GuardDuty, and Security Hub.
- Respond to and investigate security incidents, performing initial triage and escalation as needed.
- Implement and maintain security controls across AWS services, including IAM, VPC, Security Groups, and KMS.
- Assist in configuring and managing AWS security services such as AWS WAF, Shield, and Macie.
- Perform regular security assessments and vulnerability scans of AWS resources.
- Maintain and update security policies and procedures for AWS environments.
- Collaborate with DevOps teams to ensure security best practices are followed in CI/CD pipelines.
- Assist in implementing and managing identity and access management (IAM) policies.
- Participate in on-call rotations to provide 24/7 security coverage.
Additional Responsibilities
- Assist in developing and maintaining security documentation and runbooks.
- Contribute to security awareness training for other team members.
- Stay updated on the latest security threats and AWS security features.
- Participate in disaster recovery and business continuity planning.
- Assist in preparing for and supporting security audits.
Skills
- Require 5-7 years of technology experience.
- At least 1-3 years of experience in AWS Cloud Operations with large multinational organisations.
- Strong understanding of AWS services and security best practices.
- Experience with AWS security tools and features (e.g., AWS Config, CloudTrail, IAM).
- Familiarity with security information and event management (SIEM) systems.
- Knowledge of network security principles and common attack vectors.
- Understanding of compliance frameworks relevant to cloud environments (e.g., PCI DSS, HIPAA, SOC 2).
- Scripting skills in languages such as Python or Bash for automation tasks.
- Experience with infrastructure-as-code tools like CloudFormation or Terraform.
- 2+ years of experience in IT security roles, preferably in cloud environments.
- AWS Certified Security - Specialty certification preferred.