AWS DevSecOps - Security and Compliance Cloud Consultant
Location
New Jersey
Posted
19 days ago
Salary
0
Seniority
Senior
No structured requirement data.
Job Description
AWS DevSecOps - Security and Compliance Cloud Consultant
Vertical Relevance
Title: AWS DevSecOps /Security & Compliance Cloud Consultant Location: ShortHills, NJ Job Description: Full Time Mid Level Summary Vertical Relevance is looking for an AWS Security & Compliance Consultant, to join our team as a full-time employee in our work remotely. This person is responsible for the end-to-end planning, building, and deploying of software systems. He/she will be able to drive the programming of well-constructed, testable code. As an AWS Security & Compliance Consultant, you will implement technical solutions as part of a team for customer engagements. This role requires strong teamwork, communication, patience and organization skills needed to drive customer success. At Vertical Relevance we deliver with excellence through teamwork, automating everything, constantly learning and taking ownership for the outcomes our customers experience. Are you ready to join the team? Responsibilities - Help customers shape their journey to adopting the cloud and provide our customers with technical and strategic guidance on their “cloud journey”. - Consult, plan, design, and implement security solutions on the cloud customers - Design and automate security and compliance solutions - Become a deep technical resource that earns our customer's trust - Develop high-quality technical content such as automation tools, reference architectures, and white papers to help our customers build on the cloud - Innovate on behalf of customers and translate your thoughts into action yielding measurable results. - Support solution development by conveying customer needs and feedback as input to technology roadmaps. Share real world implementation challenges and recommend expansion of capabilities through enhanced and new offerings. - Assist with technical briefs that document solutions - Assist with reference architecture implementations - Support internal and external brand development through thought leadership: - Work with Marketing/Alliances to write blog posts - Work with Marketing/Alliances to develop internal case studies Qualifications - Professional experience architecting/operating automated Security & Compliance / DevSecOps solutions built on AWS Experience in software/technology customer facing experience - Knowledge of NIST 800-53, CIS, · - Proficiency in policy-as-code frameworks (OPA) · - Experience designing compliance-as-code strategies and custom controls (SCPs, Config Rules) - Strong audit-readiness advisory and evidence-collection expertise - Skilled in risk management, stakeholder alignment, and executive reporting - Familiarity with Agile project governance and backlog management - Lead discovery workshops to identify in-scope controls, services, and stakeholders Sample Activities You’ll Do Creating a Self-Service Account Framework - Assist Customer with organizational hierarchy design and configuration templates - Assist Customer in the development of referenceable playbooks, supported by relevant code examples - Assist Customer in the development of sample runbooks to automate the implementation of AWS account setup and configuration - Account Framework - Developing an automated Continuous Delivery Pipeline framework that will be used to establish AWS Accounts to configured, tested infrastructure on AWS in a repeatable, reliable and secure manner eliminating the need for manual intervention. - Security Control Policies - Development of the Service Control Policies and account baselines associated with the Customer’s security and compliance requirements - Assist Customer with the development of a report and supporting sample code addressing the controls as part of the playbook Creating Security Threat Analytics and Dashboard Solutions - Creating a framework to automatically gather, transform and interpret security event data in AWS. - Selecting, defining, identifying security requirements and determine where: - Macie can be leveraged - GuardDuty can be leveraged - Inspector can be leveraged - Security Hub can be leveraged - Alternative security products can be leveraged - Codify the provisioning of security analytics and reporting workflow: - Implement Security Hub with in a central account with inputs from all accounts - Implement GuardDuty for global security events - Implement Macie for detection of sensitive data in 23 buckets - Develop AWS Config rules to enforce security configurations in CIS AWS Foundations standard - Implementing Inspector to gather findings from EC2 instances - Enable CloudTrail for monitoring API activity - Enable FlowLogs for VPC traffic Creating a Self-Service Compliance Framework - Selecting tools for building Policy-as-Code controls (preventative, detective, and responsive) - Development of referenceable playbooks, supported by relevant code examples for controls - Development of sample runbooks to automate the implementation of controls: - Policy Definition – Identification and documentation of Customer Policy in the form of specific statements that must be true about configuration of AWS resources - Policy-as-Code Development – Development of the logical tests associated with each of the policies established to be used to assert the configuration state of infrastructure on AWS in order to block a build in the pipeline, take automated reactive action, or alert on violations to the policy - Framework Development – A design allowing for the execution of logical tests against infrastructure code or running AWS infrastructure in order to assert the configuration state of infrastructure resources on AWS and block a build in the pipeline, take automated reactive action, or alert on violations to the policy - Development of a report and supporting sample code addressing the controls as part of the playbook Relevant Technical Tools - Primary Languages – Python, Java, Bash - Tooling, Services & Libraries – Jenkins, Gitlab, Terraform, Vault, Git, Splunk, OWASP, Trend Micro, Palo Alto, Fortify, Twistlock, Aqua Security - Python AWS security services (Control Tower, Security Hub, GuardDuty, AWS Config, Audit Manager) OPA, CloudFormation-guard - Knowledge of NIST 800-53, CIS, · - Proficiency in policy-as-code frameworks (OPA) · - Experience designing compliance-as-code strategies and custom controls (SCPs, Config Rules) · Strong audit-readiness advisory and evidence-collection expertise · - Skilled in risk management, stakeholder alignment, and executive reporting · - Familiarity with Agile project governance and backlog management Relevant AWS Services - AWS Infrastructure Scripting – CloudFormation, AWS CLI, AWS CDK - AWS Storage Services – S3 - AWS Compute Services – Lambda, EC2, EKS, ECS, ECR - AWS Networking Services – VPC, Route53, API Gateway, Direct Connect - AWS Developer Services – CodePipeline, CodeBuild, CodeCommit, CodeDeploy - AWS Management and Governance Services – Control Tower, Organizations, CloudWatch, Auto Scaling, Config, CloudTrail, Service Catalog, Systems Manager - AWS Security, Identity, Compliance Services – IAM, Inspector, KMS, Secrets Manager, Security Hub, Detective, GuardDuty, Macie, HSM, Certificate Manager, WAF & Shield, Firewall Manager, Detective - AWS Frameworks – Landing Zone The Company Vertical Relevance was founded to help business leaders drive value through the design and delivery of effective transformation programs across people, processes, and systems. Our mission is to help firms at any stage of their journey develop custom solutions for success and growth. We provide a full range of services from strategy and design through to implementation and training. Our collective industry expertise is our greatest asset - our professionals have an average of 20+ years’ experience within Financial Services, across Wealth Management, Asset Management, Insurance, and Banking. Within our Customer Experience practice, we add complementary industry expertise (technology and media) synergizing the most relevant and successful customer trends. We focus wholly on your success by first rigorously assessing your business and technology challenges, and then right-sizing solutions that provide a meaningful ROI. With our industry experts hitting the ground running and focusing on nimble, quality delivery, we can see rapid, tangible improvements with our clients in productivity and effectiveness. When it makes sense for your company, we leverage our product partnerships in the areas of CRM, Sales Acceleration, Predictive Analytics, Digital Knowledge Management, and Cloud Transformation. Vertical Relevance is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to sex, gender identity, sexual orientation, race, color, religion, national origin, disability, protected Veteran status, age, or any other characteristic protected by law.
Related Guides
Related Categories
Related Job Pages
More Compliance Jobs
• prepare, complete, and submit required license application forms, renewals, and periodic regulatory filings • draft responses and provide consultations for regulatory internal inquiries • collaborate with legal, product, technology, and commercial teams to embed compliance across business operations • provide training, guidance, and support on regulatory topics to internal stakeholders • continuously monitor, interpret, and communicate regulatory updates across active jurisdictions • performing other regulatory related tasks assigned by manager
Role Description Zap is seeking a diligent and detail-oriented Compliance Officer to join our team. In this role, you will ensure that the company operates within legal and regulatory requirements, maintaining the highest standards of integrity and compliance. As a Compliance Officer at Zap, you will play a critical role in managing compliance programs, assessing risks, and promoting ethical standards throughout the organisation. You will collaborate with various departments to implement effective compliance policies and procedures, monitor compliance activities, and provide training to staff. What you’ll be up to: - Regulatory Advisory: Act as the internal subject matter expert on the Gambling Act 2005, specifically focusing on the distinctions between regulated lotteries and exempt prize competitions/free draws. - Platform Auditing: Review new software features (e.g., entry mechanics, payment gateways, winner selection algorithms) to ensure they meet legal requirements for fairness and transparency. - Client Consultation: Onboard new clients by auditing their business models, Terms & Conditions, and "Free Entry" routes to mitigate the risk of regulatory intervention. - Marketing Oversight: Review advertising copy and social media campaigns to ensure compliance with ASA (Advertising Standards Authority) guidelines, preventing misleading claims and ensuring age-gating is robust. - Data Protection & AML: Manage the agency’s GDPR compliance and oversee Anti-Money Laundering (AML) / Know Your Customer (KYC) protocols within our software to prevent fraud. - Policy Management: Develop, implement, and maintain internal compliance manuals and risk assessment frameworks. - Representing Zap externally and occasional travel to Industry relevant events. Qualifications - Proven experience in a compliance role, preferably within the prize draw, payments, or software industry. - Strong knowledge of relevant laws, regulations, and industry standards. - Excellent analytical and problem-solving skills. - Strong attention to detail and organisational skills. - Ability to communicate effectively with all levels of the organisation. - Experience with compliance management tools and software is a plus. - Professional certification in compliance or related fields is advantageous. Benefits - Salary is competitive, negotiable and depending on experience. - Company Bonus 10% of salary once company goals are met or at the company’s discretion which has been paid the past 5 years in a row. - Service Bonus of £1,000 per annum paid into your monthly salary up to 5 years / £5,000. - Flexible hours system allowing for a balance between work and personal time. - Fully remote team, eliminating the need for commutes. - A minimum of 39 holidays a year. - An extra day off for your birthday. - Twice a year all-team meeting, which ends in all-team social. - Best Place to Work Certified company. - Provision of remote working tools and equipment. - Full private BUPA Healthcare & Dental coverage. - Access to VIVUP - staff benefits & wellbeing platform. - Pension-providing employer.
Regulatory Data Technical Advisor
BryceTechBryceTech, also known as simply Bryce, is a firm that specializes in providing solutions for sectors such as security, defense, space, and public health. The company emphasizes a c
• Serve as technical SME for CDISC SEND and SENDIG-AR (2019) • Develop validation criteria, business rules, and quality control procedures for DCC ingestion of SEND datasets • Support design and implementation of DCC data architecture and metadata governance frameworks • Establish data acceptance and rejection criteria aligned with regulatory expectations • Contribute to DCC end user interface testing and acceptance criteria • Assist in developing end user training and implementation plans • Ensure alignment with Animal Rule regulatory requirements (21 CFR 314.600 and 601.90) • Assist other contractors by translating regulatory requirements into operational data standards specifications • Perform quality control of dataset packages • Integrate knowledge of nonclinical study conduct to assure correct dataset output • Knowledgably interact with study personnel as needed to prepare, review and troubleshoot issues for dataset packages • Communicate findings to team members and management • Obtain proficiency with DNCD quality control workflows to include regulatory dataset [e.g. SEND] review, study report QC, and other reviews, as required • Adhere to and/or assist in establishment/refinement of DNCD SOPs and business practice documents related to QC efforts • Learn data audit practices with possibility to assist in remote and/or on-site data audits of BARDA contracted research • Provide technical expertise to individual advanced research and development (ARD) and/or nonclinical project coordination teams (PCTs) • Act as the primary data management contact for BARDA ARD/nonclinical PCTs supporting contracts issued to CHEM, RADNUC, and BIOLOGICAL network contract research laboratories (CROs) • Coordinate with PCTs to determine intended use for data derived from contract(s) and establish data management plans intended to ensure data are fit for purpose • Coordinate with PCTs to ensure data management plans are included within contract management plans and quality assurance project plans established by CRO contractors • Develop strong PCT relationships that are driven by consistent study data analytic and management services in terms of quality and timeliness • Advise CRO contractors on data delivery and format requirements • Receive and review raw data from CRO contractors for completeness and quality according to established quality control standards • Coordinate with BARDA statisticians for appropriate methods and practices related to analytical support to PCTs
Compliance Specialist
Kitsch, LLCKitsch, LLC is a manufacturing company that designs and creates a wide variety of hair and beauty accessories. The company, as an employer, is known for its fast-paced, customer-fo
• Monitor and maintain compliance with all Amazon US product listing policies. • Own the relationship with Amazon compliance teams and manage any listing suppression. • Ensure all product detail pages, A+ content, and advertising copy meet Amazon guidelines and FTC requirements. • Track changes to Amazon Terms of Service. • Lead compliance for all international Amazon marketplaces (UK, EU, CA, JP, AU, MX). • Manage country-specific labeling and packaging requirements. • Develop and maintain a master labeling matrix by SKU and marketplace.

