Lead AWS IAM Security Engineer @EPAM Systems
All Others
Salary unspecified
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted 2wks ago

[Hiring] Lead AWS IAM Security Engineer @EPAM Systems

2wks ago - EPAM Systems is hiring a remote Lead AWS IAM Security Engineer. πŸ’Έ Salary: unspecified πŸ“Location: USA

Role Description

We are looking for a specialized Cloud Security Engineer to secure our next-generation multi-region architecture. In this role, you will architect, implement, and automate robust security controls across AWS β€” spanning enterprise IAM, Public Key Infrastructure (PKI), secrets management, and cloud security posture management (CSPM) β€” while ensuring strict compliance for PCI-scoped fintech workloads.

Responsibilities:

  • Identity & Access Management: Design and enforce secure AWS IAM policies, roles, permission boundaries, Service Control Policies (SCPs), and EKS Pod Identity / IRSA configurations.
  • Cloud Detection & Posture Management: Implement and manage security monitoring and posture tools including Amazon GuardDuty, AWS Security Hub, AWS CloudTrail, Macie, and IAM Access Analyzer.
  • PKI & Certificate Management: Build and manage automated certificate lifecycle workflows using AWS Private CA (FIPS 140-2 Level 3 HSM-backed), ACM, and mTLS trust stores, coordinating closely with the client's Security approvals.
  • Secrets & Encryption: Secure sensitive data using AWS KMS (including Multi-Region Keys), Secrets Manager, and the External Secrets Operator.

Qualifications

  • Strong hands-on experience with AWS CDK and TypeScript for security-as-code automation.
  • Deep expertise in AWS Private CA (HSM-backed), ACM, mTLS trust stores, automated certificate issuance/rotation/revocation, and PayPal Security compliance workflows.
  • Proficiency with Amazon GuardDuty, Security Hub (AWS FSBP, CIS, NIST benchmarks), Macie, and IAM Access Analyzer.
  • Experience supporting strict PCI-scoped fintech audits and CSPM frameworks.
  • Advanced IAM expertise (roles, trust policies, permission boundaries, SCPs, IRSA/EKS Pod Identity), Secrets Manager, External Secrets Operator, and KMS/MRK envelope encryption.
  • SAST tools (SonarQube, CodeQL), Dependabot, and software supply chain security (image signing and provenance via Cosign/SLSA) integrated with CDK & TypeScript.

Requirements

  • Experience with Wiz (CSPM/CNAPP).
  • Advanced deployments of AWS Private CA (PCA) and complex KMS key hierarchies.
Before You Apply
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Lead AWS IAM Security Engineer @EPAM Systems
All Others
Salary unspecified
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted 2wks ago
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
Γ—
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews

⚑ 126,124+ remote jobs, refreshed hourly

πŸ”” Real-time alerts: Apply first

πŸ›‘οΈ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later