Security Infrastructure Engineer

PointOne
New York
Workplace: OnsiteFull timeUSD 160,000 - 220,000 annuallyFunction: DevOps, Cloud & InfrastructureExperience: 5+ yearsSkills: ["IAM","VPC","PrivateLink","Security Groups","CDK","Terraform","AWS","Lambda","SQS","RDS","KMS","SCP","Log management","Incident response"]

Senior security-focused engineer responsible for hardening AWS infrastructure, implementing least-privilege access, securing networks, and optimizing cost and resilience. You’ll own infrastructure security, detection and response, and scale/cost tradeoffs across multi-account AWS environments, partnering with engineering to build secure, scalable cloud platforms for an AI timekeeping product used by law firms and government agencies.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
PointOne
PointOne
3 months ago

Security Infrastructure Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 15 hours agoStatus: Live

Job Summary

Senior security-focused engineer responsible for hardening AWS infrastructure, implementing least-privilege access, securing networks, and optimizing cost and resilience. You’ll own infrastructure security, detection and response, and scale/cost tradeoffs across multi-account AWS environments, partnering with engineering to build secure, scalable cloud platforms for an AI timekeeping product used by law firms and government agencies.
Location: New York
Workplace: Onsite
Employment Type: Full time
Job Function: DevOps, Cloud & Infrastructure
Seniority: Sr. Manager level

Key Responsibilities

  • •Infrastructure Security: Design and enforce least-privilege IAM across services; Implement permission boundaries and SCP strategy; Reduce attack surface across networking and service exposure; Improve secrets management and KMS key segmentation; Lead threat modeling across core systems; Design blast-radius containment strategies.
  • •Detection & Response: Strengthen logging, monitoring, and anomaly detection; Ensure logs are immutable and auditable; Build and test incident response playbooks; Review new infrastructure designs for security risks.
  • •Scale & Cost: Optimize AWS architecture for reliability and efficiency; Improve Lambda/SQS concurrency and scaling patterns; Evaluate and improve RDS scaling strategy; Drive principled tradeoffs between isolation, performance, and cost.

Pay and Benefits

Salary: USD 160,000 - 220,000 annually
Equity and Bonus:Equity
Perks:Health InsuranceDentalVisionEquity

Key Requirements

  • •5+ years operating AWS infrastructure in production.
  • •Deep IAM expertise (roles, policies, trust relationships, STS).
  • •Strong AWS networking knowledge (VPC, PrivateLink, Security Groups).
  • •Experience designing multi-account AWS environments.
  • •Hands-on experience responding to real security incidents.
Experience:5+ years
Skills:IAMVPCPrivateLinkSecurity GroupsCDKTerraformAWSLambdaSQSRDSKMSSCPLog managementIncident response
Tech Stack:AWSIAMVPCPrivateLinkSecurity GroupsCDKTerraformLambdaSQSRDSKMSSCP

Company Brief

PointOne
PointOne provides strategic consulting and advisory services focused on business transformation, product strategy, and operational improvement for clients across industries. They help organizations align strategy, technology, and processes to drive growth and efficiency.
Industry: Management Consulting
Website