AWS Identity Security Engineer (Contract)
At KeyData Cyber, we’re shaping the future of identity security. Recognized by Gartner and KuppingerCole as a leading IAM professional services firm, we specialize exclusively in designing, deploying, and managing end-to-end Identity and Access Management programs for organizations across North America.
With 20 years of experience, 50M+ identities managed, and 1,000+ successful deployments, our team is our strongest asset and is built by design to help clients protect critical infrastructure, enable digital transformation, and ensure compliance with confidence.
We deliver comprehensive solutions across IAM domains, including:
- Workforce IAM (Access Management, Identity Governance and Administration, Privileged Access Management)
- Consumer IAM (Identity Verification, Authentication and Access, Threat Detection) in highly regulated industries.
If you’re ready to grow your career alongside some of the industry’s best, come join us — you’re key to our success
As an AWS Security Engineer, you will be part of our Delivery Services Team. This position will be responsible for implementing and maintaining secure access controls, hardening cloud infrastructure, and automating security operations across AWS environments. As a key contributor to our clients' cloud security initiatives, you will play an integral role in protecting critical systems, ensuring compliance, and enabling secure access to cloud resources.
Location: Canada
Employment Type: 3 months contract, Remote
Vacancy Status: Immediate Opening: This position is currently available, and hiring is underway.
What You'll Do:
- Configure and maintain AWS IAM roles, policies, permission boundaries, and resource-based policies.
- Implement least-privilege access controls for engineers, administrators, applications, and automated workloads.
- Manage federated access and permission sets through AWS IAM Identity Center and enterprise identity providers.
- Configure secure cross-account access and troubleshoot access-related issues across AWS environments.
- Review and remediate excessive permissions, inactive credentials, and inappropriate privileged access.
- Support AWS Organizations and Service Control Policies (SCPs), ensuring proper governance and understanding of their impact on effective permissions.
- Harden Amazon EC2 instances running Linux and/or Windows Server using approved security baselines and industry standards such as CIS Benchmarks.
- Configure operating system permissions, host firewalls, audit logging, endpoint security controls, and secure administrative access mechanisms.
- Implement patching, vulnerability remediation, and configuration compliance processes using AWS Systems Manager and supporting tools.
- Build, maintain, and manage hardened Amazon Machine Images (AMIs).
- Reduce unnecessary services, exposed ports, and direct administrative access to improve security posture.
- Investigate configuration drift and validate that security improvements do not impact application availability or business operations.
- Develop Python, Bash, and/or PowerShell scripts to automate access provisioning, security checks, hardening activities, and remediation processes.
- Utilize Terraform and/or AWS CloudFormation to deploy secure, repeatable, and scalable infrastructure configurations.
- Automate patching, configuration enforcement, compliance validation, and operational tasks through AWS Systems Manager.
- Integrate security controls, policy validation, and compliance checks into CI/CD pipelines.
- Implement logging, monitoring, and alerting capabilities to identify unauthorized changes, access violations, and configuration issues.
- Maintain version-controlled infrastructure code, technical documentation, operational procedures, and security runbooks.
- Collaborate with cloud infrastructure, identity, security, and application teams to design and implement practical security controls.
- Troubleshoot IAM policy evaluations, instance profiles, workload credentials, operating system access issues, and cloud security incidents.
- Support security assessments, audits, and compliance initiatives by providing evidence of access controls, system hardening, and remediation activities.
- Execute infrastructure and security changes following appropriate testing, rollback planning, and production change management procedures.
Who We're Looking For:
- 3–5 years of hands-on experience administering, securing, and supporting AWS cloud environments.
- Bachelor's or Master's degree in Computer Science, Computer Engineering, Information Technology, Cybersecurity, or equivalent experience.
- Strong understanding of AWS IAM concepts, including policy evaluation, roles, trust relationships, temporary credentials, permission boundaries, and cross-account access.
- Experience administering and hardening Linux and/or Windows Server workloads hosted on Amazon EC2.
- Hands-on experience with AWS Systems Manager, including patch management, remote administration, automation, and compliance monitoring.
- Proficiency in at least one scripting language, including Python, Bash, or PowerShell.
- Experience implementing Infrastructure as Code (IaC) solutions using Terraform and/or AWS CloudFormation.
- Experience integrating AWS access controls with Identity Governance and Administration (IGA) platforms such as Saviynt.
- Strong understanding of cloud networking and security principles, including VPCs, security groups, encryption, identity controls, and logging frameworks.
- Experience identifying, analyzing, and remediating security vulnerabilities and configuration weaknesses.
- Strong troubleshooting, analytical, and problem-solving skills with the ability to independently implement and document technical solutions.
- Excellent verbal and written communication skills and the ability to effectively communicate technical concepts to both technical and non-technical stakeholders.
- Ability to work independently and collaboratively within cross-functional teams.
- Previous consulting experience would be considered an asset.
Nice-to-Have Skills
- Experience working with AWS Organizations, Service Control Policies (SCPs), and multi-account AWS environments.
- Familiarity with AWS CloudTrail, AWS Config, IAM Access Analyzer, Amazon Inspector, AWS Security Hub, and related AWS security services.
- Experience automating hardened image creation using EC2 Image Builder, Packer, or similar tools.
- Experience integrating AWS access controls with enterprise identity platforms such as Microsoft Entra ID, Saviynt, and BeyondTrust.
- Familiarity with secrets management, credential vaulting, and Privileged Access Management (PAM) solutions.
- Experience implementing security controls within DevSecOps and CI/CD environments.
- AWS certifications such as AWS Certified Security – Specialty, AWS Certified Solutions Architect, or AWS Certified SysOps Administrator are considered an asset.
Compensation
The hourly rate range for this position is $50–$58 CAD per hour. The final rate will be determined based on the candidate's experience, overall fit for the role, and expected ramp-up time. This is a 3-month, full-time contract role, working 40 hours per week. At KeyData Cyber, we are committed to fair and competitive compensation. We regularly benchmark across positions, industries, sectors, and experience levels, ensuring our approach recognizes each person's unique strengths, contributions, and the value they bring to the organization. #LI-AS1
Why You’ll Love Working Here
At KeyData Cyber, we put people first, valuing learning, growth, and work-life balance. We offer extensive opportunities to advance your career through leading digital identity projects across North America. Our culture is built on respect, inclusion, and equal opportunity for everyone.
Accessibility & Accommodations
If you require accommodation due to a disability at any time during the recruitment and/or assessment process, please contact Talent Acquisition , and we will make all reasonable efforts to accommodate your request.
Fraud Prevention & Identity Verification
We may use information provided during the application process to help prevent fraud and verify identity. These checks may be conducted automatically through trusted third‑party service providers as part of our standard application screening process.
Apply now to join the KeyData Cyber team and be part of our mission to secure the future of digital identity across North America.
About the Company
End-to-end IAM solutions for a secure, connected world. Protect your business, empower your people. With 20+ years of experience, over 1000 successful deployments and 50M+ identities managed, we have the field expertise to guide your IAM efforts and ensure seamless, secure operations with full lifecycle management—from strategy to implementation to managed services, ensuring hands-on delivery and accountability at every step. We execute with precision. Our tailored, turnkey services are designed to solve complex identity challenges, helping organizations secure their digital ecosystems, ensure compliance, and scale with confidence. Our extensive industry expertise makes us the go-to IAM partner for highly regulated sectors requiring tailored solutions and uncompromising security. We provide peace of mind that your IAM needs are supported by industry veterans who understand the demands of IAM at scale and at any maturity level.
More jobs at KeyData Cyber
-
Identity & Endpoint Security Engineer (Windows Hello)(Contract)(Contract)
USA · Contract · Sep 14, 2026
-
Identity & Endpoint Security Engineer (Windows Hello) (Contract)
Canada · Contract · Sep 14, 2026
-
AWS Identity Security Engineer(Contract)
India · Contract · Sep 14, 2026
-
AWS Identity Security Engineer(Contract)
USA · Contract · Sep 14, 2026
-
Identity & Endpoint Security Engineer (Windows Hello)
India · Contract · Sep 14, 2026