AWS Cloud Security Engineer
ON.energyAbout the role
<div class="content-intro"><p>ON.energy<span class="Apple-converted-space"> </span>is setting the standard for large load interconnection. ON’s patented AI UPS™ is a medium-voltage UPS that serves as a firewall, protecting the data center from the grid, and the grid from the data center. With multiple gigawatts currently under construction, we are enabling grid-safe data centers. </p></div><h3><strong>Key Responsibilities </strong></h3> <ul> <li>The multi-account security foundation. AWS Organizations structure, SCPs, guardrails, a security tooling account, centralized logging, and secure baselines — delivered as infrastructure as code, not console clicks.</li> <li>Security standards and review gates. You can mandate controls and block deploys that introduce unacceptable risk, through review gates on identity and network changes, a documented exception path, and a defined escalation route.</li> <li>AWS identity and access. IAM Identity Center as the single front door, federated with Entra ID in partnership with IT, who own Entra as the source of truth. Role and group model mapping job functions to permissions; joiner/mover/leaver; privileged and break-glass access; workload identity; recurring access reviews. Hands-on at first, progressively automated so it stops being manual work.</li> <li>Cloud-to-site connectivity and segmentation — the defining part of this role. Every plant, BESS site, and remote asset that reaches our cloud does so over a path you design and defend: site-to-cloud VPN and private connectivity, hard segmentation between IT and OT zones, DMZ and broker patterns for site telemetry, certificate and device identity for field gateways, remote vendor access to sites, and strict control over what may initiate traffic in each direction. You own the cloud side of that boundary and share the path itself with the OT security owner.</li> <li>Threat detection, monitoring, and mitigation. You are expected to know how attacks actually run — credential and token abuse, cross-account privilege escalation, exposed control and management interfaces, lateral movement from a compromised site network into cloud, supply-chain and dependency compromise, ransomware staging — and to build the monitoring that catches them. GuardDuty, Security Hub, Detective, Inspector, Config, and CloudTrail tuned for real signal-to-noise, detections mapped to MITRE ATT&CK and ATT&CK for ICS, runbooks the wider team can execute, and the mitigations driven to done.</li> <li>Vulnerability management. Scanning coverage across workloads, images, and dependencies; risk-based triage and prioritization; remediation SLAs and exception handling; posture reporting. You identify and prioritize; the AWS engineers remediate in the workloads they own.</li> </ul> <p>
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s