Lead AWS IAM Security Engineer
We are looking for a specialized Cloud Security Engineer to secure our next-generation multi-region architecture. In this role, you will architect, implement, and automate robust security controls across AWS — spanning enterprise IAM, Public Key Infrastructure (PKI), secrets management, and cloud security posture management (CSPM) — while ensuring strict compliance for PCI-scoped fintech workloads.
Req.#1080529720
Responsibilities
- Identity & Access Management: Design and enforce secure AWS IAM policies, roles, permission boundaries, Service Control Policies (SCPs), and EKS Pod Identity / IRSA configurations
- Cloud Detection & Posture Management: Implement and manage security monitoring and posture tools including Amazon GuardDuty, AWS Security Hub, AWS CloudTrail, Macie, and IAM Access Analyzer
- PKI & Certificate Management: Build and manage automated certificate lifecycle workflows using AWS Private CA (FIPS 140-2 Level 3 HSM-backed), ACM, and mTLS trust stores, coordinating closely with the client's Security approvals
- Secrets & Encryption: Secure sensitive data using AWS KMS (including Multi-Region Keys), Secrets Manager, and the External Secrets Operator
Requirements
- Baseline (Mandatory): Strong hands-on experience with AWS CDK and TypeScript for security-as-code automation
- AWS PKI & TLS: Deep expertise in AWS Private CA (HSM-backed), ACM, mTLS trust stores, automated certificate issuance/rotation/revocation, and PayPal Security compliance workflows
- Proficiency with Amazon GuardDuty, Security Hub (AWS FSBP, CIS, NIST benchmarks), Macie, and IAM Access Analyzer
- Experience supporting strict PCI-scoped fintech audits and CSPM frameworks
- Identity & Secrets Management: Advanced IAM expertise (roles, trust policies, permission boundaries, SCPs, IRSA/EKS Pod Identity), Secrets Manager, External Secrets Operator, and KMS/MRK envelope encryption
- Supply Chain & Application Security: SAST tools (SonarQube, CodeQL), Dependabot, and software supply chain security (image signing and provenance via Cosign/SLSA) integrated with CDK & TypeScript
Nice to have
- Experience with Wiz (CSPM/CNAPP)
- Advanced deployments of AWS Private CA (PCA) and complex KMS key hierarchies
Benefits
- Medical, Dental and Vision Insurance (Subsidized)
- Health Savings Account
- Flexible Spending Accounts (Healthcare, Dependent Care, Commuter)
- Short-Term and Long-Term Disability (Company Provided)
- Life and AD&D Insurance (Company Provided)
- Employee Assistance Program
- Unlimited access to LinkedIn learning solutions
- Matched 401(k) Retirement Savings Plan
- Paid Time Off – the employee will be eligible to accrue 15-25 paid days, depending on specific level and tenure with EPAM (accrual eligibility may change over time)
- Paid Holidays - nine (9) total per year
- Legal Plan and Identity Theft Protection
- Accident Insurance
- Employee Discounts
- Pet Insurance
- Employee Stock Purchase Program
- If otherwise eligible, participation in the discretionary annual bonus program
- If otherwise eligible and hired into a qualifying level, participation in the discretionary Long-Term Incentive (LTI) Program
About the Company
More jobs at EPAM Systems
-
Solution Architect - .NET Full Stack with Cloud
· · Sep 10, 2026
-
Senior DevOps Engineer - Azure
Turkiye · remote · Sep 10, 2026
-
Lead Software Engineer - Mainframe
· · Sep 10, 2026
-
Data Software Engineer (Upskilling position for Python Developers)
Poland · remote · Sep 10, 2026
-
Lead Security Engineer - AI Security Governance
Lithuania, Latvia · remote · Sep 10, 2026