AWS & Application Security Engineer
anchanto
India
Posted Oct 29, 2025
- Other
- Information Tech
Job description
**AWS & Application Security Engineer** **Experience:** 5+ Years **Location:** Pune,India **Job Role Pointers:** - Conduct security assessments, VAPT, and penetration testing of web applications, mobile applications, AWS infrastructure, and networks. - Perform security reviews of AWS accounts, VPCs, EC2 instances, EKS clusters, RDS databases, S3 buckets, Load Balancers, and serverless services. - Implement and manage AWS security services such as GuardDuty, Security Hub, AWS Config, Inspector, CloudTrail, WAF, Shield, and IAM. - Conduct regular cloud security posture assessments and identify misconfigurations against AWS security best practices and CIS benchmarks. - Identify security vulnerabilities, misconfigurations, and compliance gaps, and drive remediation efforts. - Hands-on experience with Ansible Automation for server provisioning, configuration management, security hardening, patch management, and compliance enforcement. - Develop and maintain Ansible playbooks for automating security controls, vulnerability remediation, user access management, and AWS infrastructure deployments. - Perform and support internal/external security audits and compliance assessments. - Prepare security test cases, audit checklists, VAPT reports, and risk assessment reports. - Coordinate with engineering and infrastructure teams to remediate findings within defined timelines. - Implement OWASP security best practices and support secure SDLC initiatives. - Perform Linux server hardening and infrastructure security reviews. - Support firewall, network security, cloud security monitoring, and incident response activities. **Required Skills** - Strong hands-on experience in AWS Security, Application Security, and VAPT. - Hands-on experience with AWS Security Hub, GuardDuty, Inspector, CloudTrail, Config, WAF, Shield, Secrets Manager, and KMS. - Experience securing containerized environments such as Docker and Kubernetes - Expertise with tools such as Burp Suite Pro, Nessus, Qualys, Acunetix, Netsparker, Metasploit, WebInspect, and Nmap. - Experience with OWASP Top 10, secure coding practices, and cloud security controls. - Good understanding of Linux administration, server hardening, and network security. - Experience participating in at least two security audits, with one conducted in the last 12 months. - Excellent analytical, documentation, and communication skills. **Preferred** - Experience in SaaS, e-commerce, or product-based organizations. - Certifications such as AWS Security Specialty, CISM, or ISO 27001 Lead Auditor.