AWS (Mumbai)

AWS (Mumbai)

24 Sep
|
Olevea Nxt
|
Mumbai

24 Sep

Olevea Nxt

Mumbai

– AWS Cloud & Network Security Engineer

Job Title: AWS Cloud & Network Security Engineer

Department: Cloud / Infrastructure & Security

Experience: 5+ years

Location: Mumbai

Employment Type: Full-time

About the Role

We are looking for an experienced AWS Cloud & Network Security Engineer to support the migration and transformation of AWS workloads into a secure, standardized landing-zone environment.

The role will focus on AWS network security, firewall implementation, routing, traffic inspection, secure administrative access, identity and access controls, and cloud security operations. The candidate will work closely with infrastructure, security, cloud, and application teams to implement and operationalize the required AWS security architecture.

Key Responsibilities

- Design, implement, and maintain secure AWS network architecture aligned with Zero Trust / Secure-First principles.
- Configure and manage AWS Network Firewall as a centralized inspection and security control point.
- Configure stateless and stateful firewall rules, domain-list filtering, IPS rules, and AWS Managed Rule Groups.
- Implement and maintain VPC and AWS Transit Gateway routing to ensure appropriate traffic flows through centralized inspection points.
- Configure inbound and outbound traffic flows through AWS WAF, Application Load Balancer/Network Load Balancer, AWS Network Firewall, and approved NAT/egress paths.
- Implement network segmentation and ensure workload traffic is appropriately inspected and controlled.
- Configure AWS WAF for supported web applications and APIs.
- Implement secure administrative access using AWS Systems Manager Session Manager, IAM roles, and federated identities.
- Ensure workload EC2 instances are not unnecessarily exposed through public IP addresses.
- Configure and manage Security Groups and Network ACLs.
- Implement and maintain centralized logging through AWS CloudTrail, Amazon CloudWatch, VPC Flow Logs, and firewall logs.
- Support AWS security controls including IAM, IAM Identity Center, PAM, ZTNA, SIEM, SOAR, GuardDuty, Security Hub, EDR/XDR, CNAPP, CASB, and DLP as applicable to the environment.




- Support the deployment and hardening of network security and intrusion-prevention controls.
- Work on AWS migration activities, security-control integration, and operationalization of AWS landing zones.
- Troubleshoot network, routing, firewall, connectivity, and security-related issues.
- Maintain documentation for network architecture, routing, firewall rules, security controls, and operational procedures.
- Support testing, UAT, implementation, rollback, and post-implementation validation activities.
- Collaborate with cloud, security, infrastructure, application, and business teams to ensure successful implementation.

Required Technical Skills

AWS:

- AWS VPC
- AWS Transit Gateway
- AWS Network Firewall
- AWS WAF
- AWS IAM
- AWS IAM Identity Center
- AWS Systems Manager / Session Manager
- AWS CloudTrail
- Amazon CloudWatch
- AWS Security Hub
- Amazon GuardDuty
- AWS NAT Gateway
- Application Load Balancer / Network Load Balancer

Networking & Security:

- VPC routing and route tables
- Network segmentation
- Security Groups and Network ACLs
- Firewall policy and rule configuration
- Stateful and stateless firewall controls
- IPS/IDS
- Network traffic inspection
- Domain filtering
- Secure administrative access
- Zero Trust security principles
- Network security architecture
- Centralized logging and monitoring

Positive to Have
- Experience with PAM and IAM Identity Center
- Experience with ZTNA
- Knowledge of SIEM and SOAR
- Experience with CNAPP, CASB, and DLP
- Knowledge of Suricata-compatible IPS rules
- Experience with enterprise cloud migration projects
- Experience working with AWS Organizations and landing zones
- Knowledge of ServiceNow / CMDB integration
- Experience with AWS Shield and DDoS protection
- Experience with third-party / next-generation firewalls
- Knowledge of F5 load balancers
- Experience with cloud security governance and compliance





Qualifications
- Bachelor's degree in Computer Science, Information Technology, Networking, Cybersecurity, or a related field.
- 5+ years of relevant experience in AWS cloud infrastructure, network engineering, cloud security, or a related field.
- Strong hands-on experience with AWS networking and security services.
- Experience working on enterprise AWS migration, security implementation, or landing-zone projects.

Key Responsibilities During Implementation The engineer will be expected to support:
- Inbound Traffic Security – routing internet traffic through approved load-balancing, WAF, and firewall controls.
- Outbound Traffic Security – inspecting workload outbound traffic and enforcing approved connectivity policies.
- VPC & Transit Gateway Routing – implementing routing through centralized inspection architecture.
- Secure Administrative Access – using Session Manager and IAM-based access rather than exposing management ports.
- Centralized AWS Network Firewall – deployment, configuration, routing, and operationalization.
- Security Controls – firewall rules, IPS, domain filtering, logging, monitoring, and security integrations.
- Migration & Transformation – supporting migration waves, governance, security integration, compliance alignment, and operational handover.

Project Context The project involves standardizing AWS workloads within a BTIS-GIT native landing zone, with approximately 70 AWS accounts, using a secure-first architecture where applicable inbound, outbound, east-west, and administrative traffic is inspected, controlled, logged, and monitored. Phase I – Secure First: Target completion 30 November 2026

Phase II – Transformation & Operationalization: Target completion 30 November 2027

Candidate Profile

We are looking for someone with strong hands-on experience in AWS networking and cloud security, particularly someone who can work on firewall implementation, routing, traffic inspection, security controls, troubleshooting, and enterprise cloud migration—not just someone with theoretical knowledge of AWS security.

Work Location: In person

📌 AWS (Mumbai)
🏢 Olevea Nxt
📍 Mumbai

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: aws (mumbai) / mumbai