GuidePoint Security logo
GuidePoint Security

Founded in 2011 and headquartered in Herndon, Virginia, GuidePoint Security furnishes commercial and federal organizations with customized information security

Principal AWS Cloud Security Consultant

Location

United States

Posted

71 days ago

Salary

0

Seniority

Lead

Job Description

Principal AWS Cloud Security Consultant

GuidePoint Security

• Provide oversight for delivery teams, ensuring quality, consistency, and alignment with client objectives while fostering knowledge transfer and consistent execution • Manage and resolve client escalations, balancing client satisfaction with project scope and delivery constraints • Present findings and recommendations to executive stakeholders, lead technical workshops, and facilitate security strategy sessions • As an individual contributor, provide consulting services on customer engagements and deliver security outcomes. Tasks may include: • Design secure cloud architectures and reference models for AWS and multi-cloud environments • Conduct in-depth cloud security assessments to identify security misconfigurations, architecture and cloud operational risks, and compliance gaps • Assist clients with continuous compliance and audit readiness in cloud environments • Conduct AWS security workshops, technical interviews, and stakeholder briefings • Prepare and present client deliverables including security roadmaps, process improvements, gap analyses, architecture diagrams, cloud security strategies, and custom deliverables based on client needs • Contribute to internal methodologies, templates, and reusable assessment frameworks • Mentor junior consultants and support knowledge sharing within the consultancy • Assist with scoping and pre-sales activities including proposals and statements of work (SOWs) • Collaborate with internal pre-sales teams to identify use-cases and opportunities for third-party security tooling (e.g., CNAPP, secrets management, data security, cloud detection and response, NHI [Non-Human Identity], etc.)

Job Requirements

  • Minimum of 5 years designing AWS architecture and operating AWS workloads at scale
  • AWS knowledge must include networking, data security, identity and access management, automation, and extensive hands-on with Amazon’s cloud-native security tooling services
  • Demonstrated knowledge of emerging security patterns and best practices for AI/ML workloads in AWS, including securing SageMaker environments, implementing guardrails for generative AI services (Bedrock), and applying data protection controls for model training and inference pipelines
  • Strong knowledge of IAM patterns (RBAC, ABAC), federated access, permission boundaries, SCPs, and RCPs
  • Proficiency in Infrastructure as Code (Terraform, CloudFormation, CDK) and secure coding practices
  • Experience with CIEM, CSPM, or CWPP tools
  • Familiarity with DevSecOps practices and integrating security into CI/CD pipelines
  • Scripting and automation skills (e.g., Python, Bash, or PowerShell)
  • Experience securing Kubernetes environments, including Amazon EKS and other managed Kubernetes platforms, with knowledge of pod security, RBAC, network policies, and container security best practices
  • Bachelor's or equivalent experience in Cybersecurity, Computer Science, Engineering, or related field.
  • Preferred certifications: CISSP, CCSP, CCSK
  • AWS Cloud certifications: AWS Certified Security – Specialty, AWS Certified Solutions Architect – Professional
  • Other CSP Certifications: Microsoft Certified: Azure Security Engineer Associate, Google Professional Cloud Security Engineer

Benefits

  • Group Medical Insurance options: Zero Deductible PPO Plan (GuidePoint pays 90% of the premium for employees and 70% for family plans (spouse/children/family) or High Deductible Health Plan with HSA (GuidePoint pays 100% of the employees premiums and 75% for family plans (spouse/children/family).
  • Group Dental Insurance: GuidePoint pays 100% of the premium for employees and 75% of family plans
  • 12 corporate holidays and a Flexible Time Off (FTO) program
  • Healthy mobile phone and home internet allowance
  • Eligibility for retirement plan after 2 months at open enrollment
  • Pet Benefit Option

Related Categories

Related Job Pages

More Security Engineer Jobs

Full TimeRemoteTeam 1,001-5,000Since 1973H1B No Sponsor

• Works as a part of the Global Security Office (GSO) to lead and influence initiatives pertaining to security governance, security risk management reporting, and cybersecurity risk assessments. • This role requires excellent people, communication and soft skills to maintain strong global business relationships while promoting GSO services and engagement. • This role is responsible for continuously driving team innovation and improvements in all aspects of services being provided by the GSO. • Manages a team to ensure timely and effective risk management reporting, maintain the security risk register, and escalate newly identified risks in alignment with established risk thresholds, appetite, and rating methodologies. • Oversees process to evaluate the security risks associated with vendors and suppliers. • Facilitates cross-functional review of findings and determine a proper risk-based outcome and resource availability for management response of remediation activities and timelines. • Adhere to risk management framework and adoption of improvements supporting continuous program maturity. • Oversees technical security assessments and other control validation activities, ensuring results are accurately interpreted, risk-rated, and integrated into the security risk management process. • Manages, mentors, and directs activities of associates within the department and performs supervisory duties including but not limited to, hiring, training, evaluating, and coaching of direct reports. • Leads the development and implementation of cyber security risk management initiatives and maintain technical security expertise to properly evaluate risks. • Participate in GSO's governance processes and process improvement workshops.

Missouri
$126.7K - $188.8K / year
Job Closed
Full TimeRemoteTeam 10,001+H1B Sponsor

Be part of a team that unleashes the power of leading-edge technologies to help improve the health and well-being of those most vulnerable in our country and communities. Working at Gainwell carries its rewards. You’ll have an incredible opportunity to grow your career in a company that values work flexibility, learning, and career development. You’ll add to your technical credentials and certifications while enjoying a generous, flexible vacation policy and educational assistance. We also have comprehensive leadership and technical development academies to help build your skills and capabilities. Summary The Senior Manager, Security Delivery is responsible for people management and operational leadership over multiple teams of security engineers and analysts who directly support client accounts. This role provides day-to-day management and career development for staff delivering services such as vulnerability management, endpoint security, monitoring, incident response support, and related security operations. The Senior Manager ensures consistent, high-quality delivery across accounts, drives operational excellence, and partners with program owners (e.g., Senior Principal, Vulnerability Management) to align frontline activities with enterprise standards. Your role in our mission - Manage and develop a team of vulnerability analysts and security engineers (and potentially one or more Supervisors of Security Delivery). - Provide coaching, mentorship, performance feedback, and career development for direct reports. - Ensure consistent, high-quality delivery of security services across client accounts. - Act as the operational escalation point for client-facing delivery issues that go beyond an individual account team or supervisor. - Own day-to-day operations of scanning, triage, ticketing, remediation coordination, and validation across assigned environments and accounts. - Ensure effective use of tooling such as Tenable (sc/Tenable.io/Tenable One), Tanium, SCCM, and ServiceNow Vulnerability Response for consistent, repeatable processes. - Monitor SLA adherence for remediation timelines by severity, platform, and account; escalate chronic SLA breaches and bottlenecks. - Run regular operational reviews (e.g., weekly delivery stand-ups, monthly service reviews with stakeholders) to review backlog, current risk posture, and upcoming changes. - Serve as the primary operational point of contact for vulnerability management for designated business units or client accounts. - Communicate vulnerability exposure, remediation requirements, and timeline expectations to technical and non-technical stakeholders. What we're looking for - 10+ years of total IT / security experience, including: - 5–7+ years in security operations, vulnerability management, or related disciplines. - 4–6+ years of people management responsibility over technical teams (team lead, manager, or higher). - Hands-on experience with at least several of the following: - Vulnerability scanning platforms (e.g., Tenable.sc, Tenable.io, Tenable One, Rapid7). - Endpoint/patch management tools (e.g., Tanium, SCCM). - ITSM and/or ServiceNow Vulnerability Response. - Security analytics platforms (e.g., Splunk). - Demonstrated experience managing operational queues, SLAs, and ticket workflows across multiple technology teams. - Strong understanding of vulnerability lifecycle management, risk-based prioritization, patch management, and secure configuration (CIS baselines). - Ability to translate vulnerability and risk data into clear, actionable tasks for resolver teams and concise updates for leadership. What you should expect in this role - Remote position (US only) - Opportunities to travel through your work (0-10%) - Video cameras must be used during all interviews, as well as during the initial week of orientation - The deadline to submit applications for this posting is 4/30/2026 The pay range for this position is $120,000 - $190,000 per year, however, the base pay offered may vary depending on geographic region, internal equity, job-related knowledge, skills, and experience among other factors. Put your passion to work at Gainwell. You’ll have the opportunity to grow your career in a company that values work flexibility, learning, and career development. All salaried, full-time candidates are eligible for our generous, flexible vacation policy, a 401(k) employer match, comprehensive health benefits, and educational assistance. We also have a variety of leadership and technical development academies to help build your skills and capabilities. We believe nothing is impossible when you bring together people who care deeply about making healthcare work better for everyone. Build your career with Gainwell, an industry leader. You’ll be joining a company where collaboration, innovation, and inclusion fuel our growth. Learn more about Gainwell at our company website and visit our Careers site for all available job role openings. Gainwell Technologies is an Equal Opportunity Employer, where all qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical condition), age, sexual orientation, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics. Gainwell Technologies defines “wages” and “wage rates” to include “all forms of pay, including, but not limited to, salary, overtime pay, bonuses, stock, stock options, profit sharing and bonus plans, life insurance, vacation and holiday pay, cleaning or gasoline allowances, hotel accommodations, reimbursement for travel expenses, and benefits.

United States
$120K - $190K / year
NBCUniversal logo

Sr Staff Cyber Security Engineer (AI)

NBCUniversal

Here you can create the extraordinary. Join us.

Full TimeRemoteTeam 10,001+Since 2004H1B Sponsor

Company Description NBCUniversal is one of the world's leading media and entertainment companies. We create world-class content, which we distribute across our portfolio of film, television, and streaming, and bring to life through our global theme park destinations, consumer products, and experiences. We own and operate leading entertainment and news brands, including NBC, NBC News, NBC Sports, Telemundo, NBC Local Stations, Bravo, and Peacock, our premium ad-supported streaming service. We produce and distribute premier filmed entertainment and programming through our powerhouse film and television studios, including Universal Pictures, DreamWorks Animation, and Focus Features, and the four global television studios under the Universal Studio Group banner, and operate industry-leading theme parks and experiences around the world through Universal Destinations & Experiences, including Universal Orlando Resort, home to Universal Epic Universe, and Universal Studios Hollywood. NBCUniversal is a subsidiary of Comcast Corporation. Visit www.nbcuniversal.com for more information. Our impact is rooted in improving the communities where our employees, customers, and audiences live and work. We have a rich tradition of giving back and ensuring our employees have the opportunity to serve their communities. We champion an inclusive culture and strive to attract and develop a talented workforce to create and deliver a wide range of content reflecting our world. Job Description We are looking for a Senior Staff Cyber Security Engineer to be part of our NBCU Security Architecture team, focused on emerging technologies including AI. This Senior Staff Cyber Security Engineer will partner with the various NBCUniversal businesses, enterprise IT, and Cyber Security organization to ensure technology is designed and deployed securely and aligned with Cyber Security and enterprise technology strategies. This individual will function as a security subject matter expert with broad knowledge across various domains, embedded with engineering teams delivering solutions for NBCUniversal. Initially the primary focus will be on security controls applicable to AI systems and other emerging technologies. You must be cognizant of the wide variety of threats all systems must be protected against and developing threat models and control strategies that are fully integrated into the design, development, and operation of new and evolving technology platforms. The analysis will involve collaboration across the Cyber organization, partnership with business stakeholders, and will result in security guidance and/or mitigation requirements. Finally, you will effectively communicate the importance of key Cyber programs and services to obtain support, trust and buy-in from business and technology teams to ensure security goals are being met. Qualifications Requirements: - 10+ years of experience partnering with business and technical teams to architect secure products and maintain a secure posture throughout their lifecycle - Ability to explain common threats to components including Network, Cloud, Web and Application environments and design mitigations with context of product and business needs - Some knowledge and awareness of ML and generative AI technologies, including common security concerns and mitigations - Knowledge of best practices in the Cyber Security industry, including OWASP Top 10 and CWE/SANS Top 25 - Advanced technical knowledge in one or more security domains, with specific expertise designing complex systems and mitigating significant risk - Ability to give and receive constructive feedback in a team environment, fostering a culture of continual improvement and excellence - Willingness to provide mentorship to more junior members of the team - Strong written/verbal communication and presentation skills with the ability to tailor to both technical, and non-technical audiences - Constant learner, actively experimenting and working with new technologies with quick instincts for picking up and developing expertise in new problem domains - Experience developing and documenting security guidelines or security best practices - Excellent time management skills to appropriately prioritize multiple concurrent projects Desired Characteristics: - Formal Degree is not required, relevant experience in the above-mentioned areas prioritized - Experience performing Threat Analysis and modeling leveraging best in industry frameworks such as MITRE ATT&CK, indicating your proficiency in implementing robust security measures - Familiarity with security control frameworks such as Cloud Security Matrix, NIST CSF, CIS Critical Security Controls - In-depth knowledge of generative AI platforms such as Azure OpenAI services and various models including GPT-4, Llama, Midjourney and the underlying technologies and safety and security risks - Understanding of various data and privacy regulations, including PCI DSS, SOX, HIPAA, GDPR, CCPA - In depth knowledge of common Cloud services and platforms (IaaS, PaaS, SaaS) - A firm understanding of Cybersecurity Engineering/Operations, Incident Response, and GRC functions - Empathy for engineering teams with the ability to balance security guidelines and policies with operational needs to maintain desired end-state corporate security posture Additional Requirements: - Fully Remote: This position has been designated as fully remote, meaning that the position is expected to contribute from a non-NBCUniversal worksite, most commonly an employee’s residence. This position is eligible for company sponsored benefits, including medical, dental and vision insurance, 401(k), paid leave, tuition reimbursement, and a variety of other discounts and perks. Learn more about the benefits offered by NBCUniversal by visiting the Benefits page of the Careers website. Salary range: $145,000 - $175,000 (bonus eligible) Additional Information As part of our selection process, external candidates may be required to attend an in-person interview with an NBCUniversal employee at one of our locations prior to a hiring decision. NBCUniversal's policy is to provide equal employment opportunities to all applicants and employees without regard to race, color, religion, creed, gender, gender identity or expression, age, national origin or ancestry, citizenship, disability, sexual orientation, marital status, pregnancy, veteran status, membership in the uniformed services, genetic information, or any other basis protected by applicable law. If you are a qualified individual with a disability or a disabled veteran, you have the right to request a reasonable accommodation if you are unable or limited in your ability to use or access nbcunicareers.com as a result of your disability. You can request reasonable accommodations by emailing [email protected]. For LA County and City Residents Only: NBCUniversal will consider for employment qualified applicants with criminal histories, or arrest or conviction records, in a manner consistent with relevant legal requirements, including the City of Los Angeles' Fair Chance Initiative For Hiring Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act, where applicable. - Business Segment: Operations & Technology - Compensation: USD 145000 - USD 175000 - yearly

New York
$145K - $175K / year
Full TimeRemoteTeam 201-500H1B No Sponsor

• Design, implement, and manage security solutions, including firewalls, intrusion detection/prevention systems, endpoint protection, and encryption mechanisms to ensure the organization's networks and systems remain secure. • Conduct regular security assessments to identify vulnerabilities and weaknesses in systems, networks, and applications. • Develop and implement incident response plans to effectively address security breaches, incidents, and breaches. • Collaborate with cross-functional teams to establish and enforce security policies, standards, and procedures. • Monitor network traffic, system logs, and security alerts to detect and respond to potential security incidents. • Analyze and investigate anomalies and security breaches, taking appropriate actions to mitigate risks. • Work closely with cross-functional teams, including IT, software development, and compliance, to integrate security into all phases of the development lifecycle and ensure a comprehensive approach to cybersecurity. • Maintain thorough and accurate documentation of security processes, procedures, and configurations. Prepare detailed reports on security findings, incidents, and actions taken.

United States
$106K - $115K / year
Job Closed