Cloud Security & DevSecOps Consultant (AWS)
Cloud Security & DevSecOps Consultant (AWS)
Vertical Relevance is looking for an Cloud Security & DevSecOps Consultant (AWS) to join our team as a full-time employee in our work remotely. This person is responsible for the end-to-end planning, building, and deploying of software systems. He/she will be able to drive the programming of well-constructed, testable code.
As an Cloud Security & DevSecOps Consultant (AWS) you will implement technical solutions as part of a team for customer engagements. This role requires strong teamwork, communication, patience and organization skills needed to drive customer success.
At Vertical Relevance we deliver with excellence through teamwork, automating everything, constantly learning and taking ownership for the outcomes our customers experience. Are you ready to join the team?
Key Responsibilities
Cloud Strategy & Advisory
- Partner with customers to shape their cloud adoption journey, providing both technical and strategic guidance.
- Design, plan, and implement secure cloud architectures aligned with business and compliance requirements.
- Serve as a trusted advisor and deep technical resource to customers.
- Design and implement automated security and compliance solutions in AWS.
- Develop and maintain Infrastructure-as-Code (IaC) solutions using Terraform.
- Build and operate CI/CD pipelines (GitHub Actions, Jenkins, CircleCI) for security automation.
- Develop Python-based automation for provisioning, compliance enforcement, and remediation.
- Implement AWS Control Tower guardrails and Service Control Policies (SCPs).
- Configure AWS Config rules with automated remediation workflows.
- Develop and enforce policy-as-code frameworks (preventative, detective, responsive controls).
- Align implementations with industry standards such as CIS AWS Foundations.
- Design and deploy centralized security monitoring and analytics frameworks.
- Implement AWS-native security services, including:
- Security Hub (centralized findings aggregation)
- GuardDuty (threat detection)
- Macie (sensitive data discovery)
- Inspector (vulnerability management)
- Enable observability and auditing via CloudTrail, VPC Flow Logs, and CloudWatch.
- Build self-service account provisioning frameworks using CI/CD pipelines.
- Develop scalable landing zone and account baseline architectures.
- Create reusable Terraform modules and automation frameworks.
- Design reference architectures and implementation playbooks.
- Create high-quality technical content (playbooks, runbooks, white papers, reference architecture).
- Translate customer needs into actionable solutions and measurable outcomes.
- Contribute to blogs, case studies, and internal knowledge sharing.
- Provide feedback to influence product roadmaps and service enhancements.
- Develop self-service AWS account provisioning frameworks with automated pipelines.
- Implement security baselines and SCPs aligned to compliance requirements.
- Build policy-as-code frameworks for automated governance enforcement.
- Design and deploy centralized security analytics dashboards.
- Create playbooks and runbooks with supporting code examples.
- Implement enterprise-scale security controls and monitoring solutions.
- Proven experience architecting and operating AWS-based security and compliance solutions.
- Hands-on experience with Terraform for infrastructure and security control implementation.
- Strong knowledge of AWS Control Tower, Organizations, and Service Control Policies (SCPs).
- Experience configuring AWS Config rules and automated remediation.
- Experience building CI/CD pipelines (GitHub Actions, Jenkins, or CircleCI).
- Proficiency in Python for automation and scripting.
- Experience working in customer-facing technical roles.
- Must be authorized to work in the United States without sponsorship.
- AWS Security Specialty certification
- Experience with AWS Outposts environments
- Experience supporting large-scale enterprise cloud migrations
Core Technologies
- AWS (Control Tower, Config, Organizations, Security Hub, GuardDuty, Macie, Inspector).
- Terraform (Infrastructure as Code)
- CI/CD (GitHub Actions, Jenkins, CircleCI)
- Python (automation and scripting)
- Compute: EC2, Lambda, EKS, ECS
- Storage: S3
- Networking: VPC, Route53, API Gateway, Direct Connect
- Security: IAM, KMS, Secrets Manager, WAF, Shield, Firewall Manager
- Governance: CloudTrail, CloudWatch, Systems Manager, Service Catalog
- Git, GitLab, Jenkins
- Vault, Splunk
- Security tools: OWASP, Palo Alto, Trend Micro, Aqua, Twistlock, Fortify
Vertical Relevance was founded to help business leaders drive value through the design and delivery of effective transformation programs across people, processes, and systems. Our mission is to help firms at any stage of their journey develop custom solutions for success and growth. We provide a full range of services from strategy and design through to implementation and training. Our collective industry expertise is our greatest asset - our professionals have an average of 20+ years’ experience within Financial Services, across Wealth Management, Asset Management, Insurance, and Banking. Within our Customer Experience practice, we add complementary industry expertise (technology and media) synergizing the most relevant and successful customer trends. We focus wholly on your success by first rigorously assessing your business and technology challenges, and then right-sizing solutions that provide a meaningful ROI. With our industry experts hitting the ground running and focusing on nimble, quality delivery, we can see rapid, tangible improvements with our clients in productivity and effectiveness. When it makes sense for your company, we leverage our product partnerships in the areas of CRM, Sales Acceleration, Predictive Analytics, Digital Knowledge Management, and Cloud Transformation.
Vertical Relevance is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to sex, gender identity, sexual orientation, race, color, religion, national origin, disability, protected Veteran status, age, or any other characteristic protected by law.