Booz Allen Hamilton
Booz Allen Hamilton
Booz Allen Hamilton is a management and technology consulting company serving government and commercial clients with advanced technical and strategic expertise. Its work spans national security, defense, intelligence, civil government, and critical infrastructure, bringing together teams focused on artificial intelligence, cybersecurity, cloud computing, digital transformation, engineering, and mission and operations support. The company is particularly engaged in complex, high-assurance challenges for military, intelligence, and federal agencies, alongside selected commercial sectors.

AWS Cloud Security Engineer - San Diego Onsite

Secure enterprise AWS environments for Booz Allen Hamilton clients through cloud assessments, Terraform guardrails, and automated security controls. The role combines AWS architecture review, security engineering, and scalable cloud governance.

Description

  • Conduct hands-on AWS cloud security assessments and engineering initiatives for large enterprise environments
  • Evaluate AWS Organizations, accounts, landing zones, identity, networking, security services, workloads, policies, Infrastructure as Code, and current security tools
  • Find cloud security weaknesses and recommend ways to improve client security postures
  • Use AWS Organizations, IAM, IAM Identity Center, Service Control Policies, VPC networking, CloudTrail, Config, GuardDuty, Security Hub, KMS, Systems Manager, and other native AWS services
  • Define minimum secure configuration standards for AWS services
  • Build reusable Terraform modules and Infrastructure as Code
  • Design security policies and preventive cloud guardrails
  • Review current cloud security tools and improve their effectiveness
  • Produce technical documentation that can directly guide implementation
  • Contribute to AWS security assessments, landing zone evaluations, identity and access management, network security, SCP development, secure service baselines, security automation, application architecture reviews, tooling improvements, and cloud governance
  • Convert technical requirements into scalable, repeatable engineering solutions
  • Partner with cloud architects, security engineers, cloud platform teams, security stakeholders, application owners, governance groups, and client leaders
  • Help organizations continue adopting AWS securely

Requirements

  • At least three years of experience in AWS cloud engineering, cloud security, infrastructure engineering, DevSecOps, site reliability engineering, or enterprise cloud delivery
  • Experience with AWS Organizations, organizational units, multi-account environments, IAM, roles, policies, Service Control Policies, or cross-account access
  • Experience with AWS networking, including VPCs, subnets, security groups, routing, Transit Gateway, private connectivity, DNS, load balancing, or ingress and egress controls
  • Experience with AWS security and monitoring services such as CloudTrail, AWS Config, GuardDuty, Security Hub, KMS, IAM Access Analyzer, CloudWatch, Systems Manager, or AWS Inspector
  • Experience creating or reviewing Terraform, AWS CloudFormation, or other Infrastructure as Code
  • Experience supporting cloud security standards, secure configuration baselines, technical guardrails, policies, or reusable security patterns
  • Experience with scripting or automation using Python, Bash, PowerShell, AWS CLI, SDKs, APIs, or engineering tools
  • Experience evaluating technical environments, finding security or architecture gaps, and turning findings into recommendations, implementation actions, or technical documentation
  • Ability to work directly with cloud engineers, architects, cybersecurity teams, application teams, governance stakeholders, and client leadership
  • Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, Engineering, or Information Systems
  • Experience with AWS IAM Identity Center, SAML, OIDC, permission sets, privileged access, enterprise federation, or identity governance
  • Experience designing, reviewing, or supporting AWS landing zones, AWS Control Tower, account vending, centralized logging, shared services, or enterprise AWS platform architectures
  • Experience creating AWS Service Control Policies, IAM policies, resource policies, permission boundaries, or preventive cloud security controls
  • Experience creating secure baselines and Infrastructure as Code for multiple AWS services in a large enterprise environment
  • Experience with cloud security platforms such as Wiz, Prisma Cloud, Orca Security, Lacework, CSPM, or CNAPP technologies
  • Experience incorporating security requirements into CI/CD pipelines, Git workflows, DevSecOps processes, automated testing, or policy-as-code
  • Experience with NIST, CIS Benchmarks, ISO 27001, FedRAMP, or other cloud security control frameworks
  • Experience reviewing application architectures, dependencies, and infrastructure components
  • Experience supporting large enterprise, Fortune 500, regulated, or multi-account cloud environments
  • Knowledge of Microsoft Azure or Google Cloud security
  • Must complete identity verification and remain on camera during interviews and assessments
  • AI tools may not be used during interviews unless explicitly authorized

Benefits

  • Health coverage
  • Life insurance coverage
  • Disability benefits
  • Financial benefits
  • Retirement benefits
  • Paid leave
  • Professional development opportunities
  • Tuition assistance
  • Work-life programs
  • Dependent care support
  • Recognition awards for exceptional performance and strong demonstration of company values
  • Identity verification using advanced biometrics and artificial intelligence
  • Camera-on requirement during interviews and assessments
  • Certain benefits are available to eligible employees working fewer than 20 hours per week

Related Jobs

Esperta Health

Bilingual Intake Coordinator, Esperta Health (Remote, U.S.)

Esperta Health

Coordinate referrals for Esperta Health’s in-home wound care services, from intake and eligibility checks through admission or final disposition. Work with members, providers, payors, and clinical teams in English and Spanish.

Open