23 Sep
|
Highbrow Technology
|
Palakkad
23 Sep
Highbrow Technology
Palakkad
ABOUT THE ROLE
We are hiring a senior, hands-on engineer for a fixed 5 to 6 week, full-time, remote contract to deliver two pieces of infrastructure on AWS: a hardened security baseline across our account, and a sealed development workplace where source code never leaves the cloud.
This is a delivery role, not an advisory one. A week-by-week plan already exists. You will personally build and configure everything below, deliver it in Terraform, document it, and hand it over.
WHAT YOU WILL BUILD
Workstream A: AWS security baseline
- Enable and tune CloudTrail, GuardDuty, AWS Config, Security Hub, Amazon Inspector and IAM Access Analyzer.
- Enforce MFA and an IAM password policy; review IAM users and roles for least privilege.
- Tighten security groups across the estate and move all administrative access to SSM Session Manager, so no SSH or RDP is reachable from the internet.
- Lock down S3 and database access; enable encryption at rest for EBS and RDS.
- Set up centralised patching with SSM Patch Manager and backups with AWS Backup.
- Configure security alerting with CloudWatch alarms and SNS.
Workstream B: Sealed Development Environment
- Build an isolated dev VPC with default-deny egress using AWS Network Firewall.
- Deploy Amazon WorkSpaces virtual desktops with DLP controls: clipboard, local drive, USB and printing redirection disabled.
- Configure GitHub so repository access (web, git, API) is only possible from inside the dev environment: SSO, IP allow list, hardened org policies.
This part is well documented; prior GitHub Enterprise admin experience is not required.
- Set up AWS CodeArtifact as a package pull-through cache and self-hosted GitHub Actions runners inside the enclave.
- Run a data-loss-prevention test matrix to prove code cannot leave; pilot with a small group, then roll out to all developers.
Cross-cutting
- Everything as infrastructure as code in Terraform.
- Runbooks, an architecture diagram and admin documentation; a clean handover.
REQUIRED (all four)
1. AWS security services, hands-on. 5+ years in cloud infrastructure, DevOps or cloud security with deep AWS experience. You have personally enabled and tuned CloudTrail, GuardDuty, Config, Security Hub, Inspector and IAM Access Analyzer, and worked with IAM, KMS and SSM in production.
2. AWS networking. VPC design, security groups, NAT, VPC endpoints, and egress control with AWS Network Firewall or an equivalent.
3. VDI or cloud development environments. You have built or administered Amazon WorkSpaces, AppStream 2.0, Azure Virtual Desktop, Windows 365, Citrix, VMware Horizon or Omnissa, Coder, or equivalent, including the DLP side: clipboard, drive, USB and print redirection controls. This is the skill we most need to see evidence of.
4.
Terraform. You deliver infrastructure as code by default.
You can work independently against a fixed plan and deadline and communicate progress clearly.
NICE TO HAVE
- GitHub organisation administration: SSO/SAML, IP allow lists, org policy hardening.
- Experience in environments with SOC 2, ISO 27001 or HIPAA requirements.
- Identity provider integration: Google Workspace, Okta or Entra ID.
- Experience designing zero-egress or no-source-code-on-endpoint developer environments.
- Endpoint security or EDR deployment.
- AWS Security Specialty, Solutions Architect or Advanced Networking certifications.
ENGAGEMENT TERMS
- Full-time for the engagement. This is not a part-time or evenings role.
- 5 to 6 weeks. The sixth week is a buffer for rollout and handover.
- Remote, with overlap with our core working hours.
- Fixed fee.
WHAT DONE LOOKS LIKE
1. The security services above are live and tuned, with Security Hub reporting at an agreed target score.
2. The Sealed Development Environment is live for all developers and the DLP test matrix passes: code provably cannot leave the enclave.
3. All work is in Terraform and documented, with a clean handover to our team.
HOW TO APPLY
Along with your profile, add two or three sentences describing a virtual desktop or sealed development environment you have built or administered, and which redirection or DLP controls you configured. Applications without this are unlikely to be shortlisted.
📌 Cloud Security & DevSecOps Engineer (AWS) - 6 Week Contract (Palakkad)
🏢 Highbrow Technology
📍 Palakkad