Cloud Engineering Professional
bt
Job Description
- Manage the security posture of the AWS infrastructure supporting the Common Data Fabric platform.
- Conduct regular vulnerability assessments across cloud infrastructure and serverless workloads, driving remediation activities to closure.
- Operate and maintain cloud security scanning tools including Prowler, AWS Security Hub, Amazon Inspector, Guard Duty, and AWS Config.
- Analyse vulnerability findings and security risks, prioritising remediation activities based on risk exposure and business impact.
- Partner with engineering teams to implement secure-by-default infrastructure patterns and automated compliance controls.
- Design and implement robust observability solutions covering security monitoring, platform health, logging, tracing, and alerting.
- Troubleshooting and root-cause analysis of incidents involving serverless services, infrastructure components, and security controls.
- Support and optimise AWS serverless services including AWS Lambda, Step Functions, SQS, Amazon Event Bridge, Glue, Amazon S3, Athena and Amazon API Gateway.
- Drive cloud cost optimisation initiatives by identifying inefficiencies, reducing waste, rightsizing resources, and improving utilisation.
- Implement security monitoring dashboards and automated alerting for infrastructure, applications, and cloud-native services.
- Develop operational runbooks, resilience testing strategies, disaster recovery procedures, and platform support documentation.
- Support security audits, risk reviews, regulatory compliance activities and platform assurance assessments (Pen tests).
Essential Skills / Experience
- Strong hands-on experience operating and supporting enterprise-scale AWS cloud environments.
- Decent knowledge of AWS security services including AWS security hub, guard duty, inspector, IAM, KMS, CloudTrail, AWS WAF, Shield, Secret manager etc.
- Proven experience operating Prowler for AWS security posture assessments and compliance validation.
- Experience performing vulnerability assessments, security investigations, risk analysis, and remediation management.
- Proven experience designing and implementing observability solutions using services such as Amazon CloudWatch, Grafana, Open Telemetry and Centralised logging and dashboarding solutions.
- Strong understanding of cloud networking, Zero Trust principles, identity management, access controls, encryption, and key management.
- Experience conducting root cause analysis and driving incident resolution for production-critical services.
- Knowledge of infrastructure automation and Infrastructure as Code (Terraform preferred).
- Security-first mindset with strong attention to detail.
- Excellent analytical and troubleshooting skills in complex cloud environments.
- Proactive in identifying risks and driving remediation activities.
- Strong ownership and accountability for operational resilience and platform security.
- Effective communicator capable of collaborating across engineering, security, architecture, and operational teams.
- Passionate about automation, continuous improvement, and secure cloud engineering practices.