About the Role
The client is seeking a Senior AWS Cloud Security Consultant to help design and enforce enterprise cloud security controls within a highly regulated environment. This role sits at the intersection of cloud security architecture, policy engineering, and AWS governance, with a primary focus on preventing data exfiltration through policy-as-code, data perimeter controls, and proactive threat modeling. You will evaluate AWS services before they are introduced into production environments, identify potential security risks at the API and configuration level, and implement preventive controls using AWS Organizations policies, IAM guardrails, and Rego-based policy frameworks. This is an opportunity to work on complex cloud security challenges supporting critical business platforms where security, compliance, and operational rigor are non-negotiable.
Responsibilities
- Design and enforce enterprise cloud security controls within a highly regulated environment.
- Focus on preventing data exfiltration through policy-as-code, data perimeter controls, and proactive threat modeling.
- Evaluate AWS services before they are introduced into production environments.
- Identify potential security risks at the API and configuration level.
- Implement preventive controls using AWS Organizations policies, IAM guardrails, and Rego-based policy frameworks.
Requirements
- 8+ years of cloud engineering, cloud security, or infrastructure security experience.
- Deep expertise in AWS security architecture and governance.
- Demonstrated experience performing API-level threat modeling for AWS services.
- Strong hands-on experience with Open Policy Agent (OPA), Rego policy development, and policy testing and validation.
- Advanced knowledge of AWS IAM, AWS Organizations, SCPs and RCPs, and data perimeter architecture.
- Experience designing least-privilege access models in regulated environments.
- Strong understanding of cloud security controls, compliance requirements, and enterprise governance frameworks.
- Experience with Kivera.io, Cloudflare One, or similar cloud API policy enforcement platforms.
- Experience with Regal policy linting and OPA coverage reporting.
- Infrastructure-as-Code expertise using Terraform.
- CI/CD experience with GitHub Actions, OIDC federation, policy validation pipelines, and approval-based deployment models.
- Experience with Checkov, Conftest, Policy Sentry, and Cloudsplaining.
- Strong AWS observability experience using CloudWatch, CloudTrail, and VPC Flow Logs.
- Amazon EKS security and governance experience.
- Experience working directly with AWS Support and Technical Account Managers.
- Financial services, banking, capital markets, or other highly regulated industry experience.
Skills
- AWS security architecture
- AWS governance
- API-level threat modeling
- Open Policy Agent (OPA)
- Rego policy development
- Policy testing
- Policy validation
- AWS IAM
- AWS Organizations
- SCPs
- RCPs
- Data perimeter architecture
- Least-privilege access models
- Cloud security controls
- Compliance requirements
- Enterprise governance frameworks
- Kivera.io
- Cloudflare One
- Regal policy linting
- OPA coverage reporting
- Terraform
- GitHub Actions
- OIDC federation
- Policy validation pipelines
- Approval-based deployment models
- Checkov
- Conftest
- Policy Sentry
- Cloudsplaining
- CloudWatch
- CloudTrail
- VPC Flow Logs
- Amazon EKS security
- Amazon EKS governance
- AWS Support
- AWS Technical Account Managers
Location
- Manhattan, NY
Work Type
- Full-time
- Permanent
Experience Level
- Senior
About the Company
- Our client is a 3rd-generation management consulting firm that is expanding its team.
