About the job
Encora is seeking an AWS Cloud Security Engineer in Singapore to help strengthen and protect our cloud infrastructure. This position focuses on implementing and maintaining AWS security controls, supporting compliance, and safeguarding sensitive data across our environments.
What you will do
- Develop and enforce AWS security policies, including IAM hardening, Service Control Policies (SCPs), GuardDuty, Security Hub, CloudTrail, Config, KMS, VPC security, S3 security controls, and multi-account governance.
- Design and implement secure AWS landing zones and multi-account architectures, ideally using Control Tower.
- Manage Cloud Security Posture Management (CSPM), monitor compliance continuously, and automate remediation.
- Lead incident response efforts for AWS environments, addressing issues such as compromised IAM keys, misconfigurations, exposed services, and zero-day vulnerabilities.
- Ensure Infrastructure-as-Code security with Terraform or CloudFormation, and integrate security controls into CI/CD pipelines.
- Integrate AWS security logs into SIEM systems (preferably Elastic) and troubleshoot log pipelines as needed.
- Improve container security with EKS security measures, image scanning, and IAM roles for service accounts.
Skills and experience
- Strong understanding of networking concepts, including VPC, NACL, Security Groups, Transit Gateway, and Linux fundamentals.
- Experience with AWS Security certifications, with preference for AWS Security Specialty.
- Ability to work independently, show initiative, and collaborate effectively with stakeholders.

