Enter a job title or keyword

Lead AWS IAM Security Engineer

EPAM Systems


Job Location:

New York City, NY - USA

Monthly Salary: Not provided by the employer
Posted: 12 September 2026 (3 hours ago)
Application Deadline: 10 December 2026
Vacancies: 1 Vacancy

Job Summary

We are looking for a specialized Cloud Security Engineer to secure our next-generation multi-region this role you will architect implement and automate robust security controls across AWS spanning enterprise IAM Public Key Infrastructure (PKI) secrets management and cloud security posture management (CSPM) while ensuring strict compliance for PCI-scoped fintech workloads.

Req.#

Responsibilities
  • Identity & Access Management: Design and enforce secure AWS IAM policies roles permission boundaries Service Control Policies (SCPs) and EKS Pod Identity / IRSA configurations
  • Cloud Detection & Posture Management: Implement and manage security monitoring and posture tools including Amazon GuardDuty AWS Security Hub AWS CloudTrail Macie and IAM Access Analyzer
  • PKI & Certificate Management: Build and manage automated certificate lifecycle workflows using AWS Private CA (FIPS 140-2 Level 3 HSM-backed) ACM and mTLS trust stores coordinating closely with the clients Security approvals
  • Secrets & Encryption: Secure sensitive data using AWS KMS (including Multi-Region Keys) Secrets Manager and the External Secrets Operator
Requirements
  • Baseline (Mandatory): Strong hands-on experience with AWS CDK and TypeScript for security-as-code automation
  • AWS PKI & TLS: Deep expertise in AWS Private CA (HSM-backed) ACM mTLS trust stores automated certificate issuance/rotation/revocation and PayPal Security compliance workflows
  • Proficiency with Amazon GuardDuty Security Hub (AWS FSBP CIS NIST benchmarks) Macie and IAM Access Analyzer
  • Experience supporting strict PCI-scoped fintech audits and CSPM frameworks
  • Identity & Secrets Management: Advanced IAM expertise (roles trust policies permission boundaries SCPs IRSA/EKS Pod Identity) Secrets Manager External Secrets Operator and KMS/MRK envelope encryption
  • Supply Chain & Application Security: SAST tools (SonarQube CodeQL) Dependabot and software supply chain security (image signing and provenance via Cosign/SLSA) integrated with CDK & TypeScript
Nice to have
  • Experience with Wiz (CSPM/CNAPP)
  • Advanced deployments of AWS Private CA (PCA) and complex KMS key hierarchies

Required Experience:

Staff IC