Principal Security Engineer — DevSecOps (AWS)
Remote JobsHiring: Principal Security Engineer — DevSecOps (AWS)
Remote | Contract | Hands-on
Manizh is staffing a principal-level security engineer for an active enterprise engagement on AWS.
This is not a governance seat. You will threat-model live systems, build the detections, and close the distance between "we found it" and "it can't happen again" — in code, in the pipeline, and in the account structure.
What we are looking for:
- 8+ years in application and cloud security, with a track record at principal or senior-lead level, while remaining hands-on.
- Threat modeling as a working practice using STRIDE, attack trees, and abuse cases across microservices, APIs, CI/CD, and IAM.
- Detection engineering on AWS, including GuardDuty, Security Hub, CloudTrail, and custom detections. You know the difference between an alert and a signal.
- Prevention built into delivery through IaC guardrails using Terraform / CloudFormation, SAST/DAST integrated into pipelines, and container and Kubernetes security.
- Ability to walk an engineering team through why, not just what.
Nice to have:
- Experience with vulnerability management programs such as Wiz and Qualys.
- CDN edge security experience with CloudFront, Cloudflare, or Akamai, including WAF, bot management, and cache poisoning.
- AWS Security Specialty certification.
Location and schedule:
- Remote.
- Contract, long-running.
- Based in the U.S. or nearshore, including Canada and LATAM.
- Availability to work U.S. Eastern hours.
Environment:
- Senior architecture.
- Lean teams.
- Outcomes—not utilization.