AWS Security Engineer(SC Eligible)
We have one open position of AWS Security Engineer with one of our client based in London, UK. This is a Contract/Freelance position. Below is the job description for your reference. Please share your application once you are interested.
Role: AWS Security Engineer(SC Eligible/SC Cleared)
Location: London, UK(1-2 Days work from office per week)
Mode: Contract/Freelance
Job Description:
Role Overview
- We're looking for an AWS Security Engineer who can take ownership of cloud security across discovery, design, implementation, and large-scale workload migration.
- This role sits at the centre of a major AWS transformation program including Landing Zone establishment, EUC/Citrix-to-WorkSpaces modernisation, and full datacentre migration.
- You'll shape identity, compliance, guardrails, monitoring, MFA/Conditional Access, and ongoing hardening for production.
Key Responsibilities
- Validate MFA, Conditional Access, encryption, logging in discovery phase.
- Design and embed IAM, RBAC, federation and authentication patterns into architectures.
- Define AWS security guardrails, SCPs, monitoring and compliance baselines.
- Configure IAM roles, key management, encryption, logging, CloudTrail, Config, GuardDuty, Security Hub.
- Support Landing Zone build-out including identity federation, tagging, audit, multi-account governance.
- Implement VDI/WorkSpaces/Citrix security hardening, MFA, Conditional Access and admin console security.
- Validate security during pilot migration and bulk migration (200+ workloads) across IAM, MFA, encryption, BCP.
- Support CIS benchmarking, public-sector standards, compliance tests and penetration test readiness.
- Tune monitoring dashboards, alerting and incident triage in hypercare.
Required Skills & Experience
- Strong hands-on AWS security engineering background.
- Deep IAM/RBAC/SCP/AWS Organizations experience.
- Experience with MFA, Conditional Access, Entra AD federation.
- Knowledge of CIS, compliance, encryption, KMS, RPO/RTO.
- Experience enabling GuardDuty, Security Hub, CloudTrail, Config.
- Exposure to migration-scale security validation.