AWS Identity Security Engineer(Contract)

KeyData Cyber · India · Engineering

Posted 2026-09-14

Apply for this role →

As an AWS Security Engineer, you will be part of our Delivery Services Team. This position will be responsible for implementing and maintaining secure access controls, hardening cloud infrastructure, and automating security operations across AWS environments. As a key contributor to our clients' cloud security initiatives, you will play an integral role in protecting critical systems, ensuring compliance, and enabling secure access to cloud resources.

Location: India

Employment Type: 3 months contract, Remote

What You'll Do:

Configure and maintain AWS IAM roles, policies, permission boundaries, and resource-based policies.

Implement least-privilege access controls for engineers, administrators, applications, and automated workloads.

Manage federated access and permission sets through AWS IAM Identity Center and enterprise identity providers.

Configure secure cross-account access and troubleshoot access-related issues across AWS environments.

Review and remediate excessive permissions, inactive credentials, and inappropriate privileged access.

Support AWS Organizations and Service Control Policies (SCPs), ensuring proper governance and understanding of their impact on effective permissions.

Harden Amazon EC2 instances running Linux and/or Windows Server using approved security baselines and industry standards such as CIS Benchmarks.

Configure operating system permissions, host firewalls, audit logging, endpoint security controls, and secure administrative access mechanisms.

Implement patching, vulnerability remediation, and configuration compliance processes using AWS Systems Manager and supporting tools.

Build, maintain, and manage hardened Amazon Machine Images (AMIs).

Reduce unnecessary services, exposed ports, and direct administrative access to improve security posture.

Investigate configuration drift and validate that security improvements do not impact application availability or business operations.

Develop Python, Bash, and/or PowerShell scripts to automate access provisioning, security checks, hardening activities, and remediation processes.

Utilize Terraform and/or AWS CloudFormation to deploy secure, repeatable, and scalable infrastructure configurations.

Automate patching, configuration enforcement, compliance validation, and operational tasks through AWS Systems Manager.

Integrate security controls, policy validation, and compliance checks into CI/CD pipelines.

Implement logging, monitoring, and alerting capabilities to identify unauthorized changes, access violations, and configuration issues.

Maintain version-controlled infrastructure code, technical documentation, operational procedures, and security runbooks.

Collaborate with cloud infrastructure, identity, security, and application teams to design and implement practical security controls.

Troubleshoot IAM policy evaluations, instance profiles, workload credentials, operating system access issues, and cloud security incidents.

Support security assessments, audits, and compliance initiatives by providing evidence of access controls, system hardening, and remediation activities.

Execute infrastructure and security changes following appropriate testing, rollback planning, and production change management procedures.

Who We're Looking For:

3–5 years of hands-on experience administering, securing, and supporting AWS cloud environments.

Bachelor's or Master's degree in Computer Science, Computer Engineering, Information Technology, Cybersecurity, or equivalent experience.

Strong understanding of AWS IAM concepts, including policy evaluation, roles, trust relationships, temporary credentials, permission boundaries, and cross-account access.

Experience administering and hardening Linux and/or Windows Server workloads hosted on Amazon EC2.

Hands-on experience with AWS Systems Manager, including patch management, remote administration, automation, and compliance monitoring.

Proficiency in at least one scripting language, including Python, Bash, or PowerShell.

Experience implementing Infrastructure as Code (IaC) solutions using Terraform and/or AWS CloudFormation.

Experience integrating AWS access controls with Identity Governance and Administration (IGA) platforms such as Saviynt.

Strong understanding of cloud networking and security principles, including VPCs, security groups, encryption, identity controls, and logging frameworks.

Experience identifying, analyzing, and remediating security vulnerabilities and configuration weaknesses.

Strong troubleshooting, analytical, and problem-solving skills with the ability to independently implement and document technical solutions.

Excellent verbal and written communication skills and the ability to effectively communicate technical concepts to both technical and non-technical stakeholders.

Ability to work independently and collaboratively within cross-functional teams.

Previous consulting experience would be considered an asset.

Nice-to-Have Skills

Experience working with AWS Organizations, Service Control Policies (SCPs), and multi-account AWS environments.

Experience with Microsoft Azure, including Entra ID, role-based access control (RBAC), virtual machine hardening, and security automation.

Familiarity with AWS CloudTrail, AWS Config, IAM Access Analyzer, Amazon Inspector, AWS Security Hub, and related AWS security services.

Experience automating hardened image creation using EC2 Image Builder, Packer, or similar tools.

Experience integrating AWS access controls with enterprise identity platforms such as Microsoft Entra ID, Saviynt, and BeyondTrust.

Familiarity with secrets management, credential vaulting, and Privileged Access Management (PAM) solutions.

Experience implementing security controls within DevSecOps and CI/CD environments.

AWS certifications such as AWS Certified Security – Specialty, AWS Certified Solutions Architect, or AWS Certified SysOps Administrator are considered an asset.#LI-AS1

Apply for this role →

← Back to all jobs