AWS Security Subject Matter Expert (SME)
Posted Updated 3
views
Job Description: AWS Security Subject Matter Expert (SME)
Role Summary
The AWS Security Subject Matter Expert (SME) will serve as the go-to technical expert for security architecture, governance, compliance, and operational security posture across Minfy's AWS environments. This individual brings deep, hands-on expertise in AWS-native security services and best practices, advising on secure configurations, driving remediation of security gaps, enabling DevSecOps practices, and ensuring secure, compliant, and resilient AWS operations for both Minfy-managed and customer-managed environments.
The individual will work closely with SRE, Cloud Engineering, FinOps, Product Engineering, AI/ML teams, Customer Success, and Strategic Account teams, providing AWS security subject matter expertise to embed security into every aspect of cloud service delivery.
Key Responsibilities
AWS Security Architecture & Best Practices
- Define and maintain enterprise security architecture standards for AWS, serving as the subject matter expert on AWS-native security services and configurations.
- Develop secure AWS Landing Zones (AWS Control Tower, Organizations), reference architectures, and security guardrails.
- Establish architecture patterns for:
- AWS multi-account/multi-region deployments
- Hybrid cloud environments (AWS to on-premises)
- SaaS platforms
- AI/ML workloads (SageMaker, Bedrock)
- Kubernetes platforms (Amazon EKS)
- Review and approve security designs for new cloud initiatives and customer engagements.
- Drive Zero Trust Architecture adoption across AWS environments.
AWS Security Engineering & DevSecOps
- Embed security controls into CI/CD and Infrastructure-as-Code pipelines.
- Implement Security-as-Code and Policy-as-Code frameworks.
- Automate compliance validation and security posture assessments.
- Establish secure software supply chain controls.
- Drive secure container, Kubernetes, and serverless security practices.
- Integrate automated vulnerability and misconfiguration detection into engineering workflows.
Security Operations & Threat Management
- Define and oversee cloud security monitoring, detection, and response capabilities.
- Establish AWS-native threat detection strategies using GuardDuty, Security Hub, and Detective.
- Lead security incident response and forensic investigations.
- Drive vulnerability management programs across AWS environments (Amazon Inspector, ECR scanning).
- Implement cloud-native threat intelligence and proactive threat hunting capabilities.
- Develop operational runbooks and security response automation.
Governance, Risk & Compliance
- Develop cloud security governance frameworks and policies.
- Establish cloud risk management and control assessment processes.
- Lead compliance initiatives including:
- ISO 27001
- SOC 2
- PCI DSS
- GDPR
- HIPAA
- NIST CSF
- CIS Benchmarks
- Support customer security reviews and regulatory audits.
- Build continuous compliance monitoring capabilities.
Identity, Access & Data Security
- Define enterprise IAM strategy for AWS, including IAM, AWS Organizations, and AWS IAM Identity Center.
- Implement Zero Trust and least-privilege access models.
- Standardize:
- MFA
- SSO
- Federated Identity
- Privileged Access Management
- Lead secrets management (AWS Secrets Manager) and encryption strategy (AWS KMS).
- Define enterprise data classification and protection controls.
AI & Emerging Security
- Secure GenAI and AI/ML platforms deployed in cloud environments.
- Establish governance controls for AI workloads.
- Define security standards for LLM deployments and AI-assisted operations.
- Assess risks associated with AI services and third-party integrations.
- Collaborate with AI engineering teams to implement secure AI architectures.
SME & Collaboration Responsibilities
- Serve as the AWS security subject matter expert within the Cloud Security Center of Excellence in SRE.
- Provide technical guidance and mentorship to Cloud Security Engineers and Security Analysts on AWS best practices.
- Partner with Strategic Account Directors, TAMs, Cloud Architects, and Delivery Leaders.
- Provide technical reporting and recommendations on AWS security posture, risks, and remediation plans.
- Support customer-facing security discussions and solution reviews.
Required Qualifications
- 10–14+ years of experience in Infrastructure, Cloud, Security, or SRE domains.
- Minimum 6+ years of hands-on AWS security experience.
- Demonstrated depth as a go-to AWS security subject matter expert (team leadership experience not required).
- Deep, hands-on expertise across AWS security services (IAM, GuardDuty, Security Hub, KMS, Macie, Inspector, Control Tower, Organizations); working knowledge of Azure or GCP is a plus.
- Strong understanding of:
- Cloud-native architectures
- Kubernetes
- DevSecOps
- Identity Security
- Compliance frameworks
- Security Operations
- Experience supporting enterprise-scale SaaS environments.
- Strong customer-facing and consulting capabilities.
Mandatory Technical Skills
Candidates must demonstrate hands-on, working knowledge of the following:
- AWS Web Application Firewall (AWS WAF)
- Amazon Athena (for security log analytics and querying)
- AWS Security Hub
- Amazon GuardDuty
- Amazon Inspector
- CIS Benchmarks
- NIST Cybersecurity Framework (NIST CSF)
- ISO 27001
Preferred Certifications
- AWS Certified Security – Specialty
- AWS Solutions Architect Professional
- AWS Certified Advanced Networking – Specialty
- AWS Certified DevOps Engineer – Professional
- CISSP
- CCSP
- CISM
- CKS (Certified Kubernetes Security Specialist)
Success Metrics (KPIs)
- Reduction in critical cloud security findings.
- Cloud Security Posture Management (CSPM) score improvement.
- Compliance audit pass rates.
- Security incident reduction.
- MTTD and MTTR improvements.
- Percentage of infrastructure compliant by default.
- Vulnerability remediation SLA adherence.
- Customer security audit success rate.
- Security automation coverage across AWS environments.
Reporting Structure
Reports To: Delivery Leader
Manages: Individual contributor / SME role — no direct reports; provides technical guidance to Cloud Security Engineers, Security Analysts, DevSecOps Engineers, and Security Compliance Specialists
This role becomes the AWS security subject matter expert within the SRE organization, partnering with leaders for Cloud Operations, FinOps, Platform Engineering, Observability, and Automation to ensure secure and compliant operations across AWS customer environments.
Skills
- AI
- Analytics
- Athena
- Automation
- AWS
- Azure
- CI/CD
- Cism
- Cissp
- Cloud
- Cloud Native
- Cloud Security
- Cybersecurity
- DevOps
- DevSecOps
- EKS
- FinOps
- Firewall
- GCP
- Gdpr
- Generative AI
- Hipaa
- IAM
- Infrastructure as Code
- ISO 27001
- Kubernetes
- LLM
- Machine Learning
- Networking
- Nist
- Observability
- Pci Dss
- SaaS
- SageMaker
- Secrets Management
- Serverless
- SOC 2
- SSO
- Threat Hunting
- WAF
- Zero Trust