Skip to content
NEXTMOVEFDE careers · United States

Cyber - AWS Forward Deployed Security Engineer (FDE) - Senior Consultant

AI summary of the role

Forward Deployed Security Engineer embedded with client teams to design, build, and operate automated AWS security controls, including for generative AI and container workloads.

What you’ll do

  • Embed with client cloud/platform teams to design, build, deploy, and operate automated security controls across AWS environments.
  • Implement security guardrails for AWS AI/ML services (Bedrock, SageMaker) and EKS/container workloads.
  • Build data protection and DLP using Macie, KMS, and encryption patterns across S3, databases, and analytics.
  • Deploy and maintain AWS-native security services (Security Hub, GuardDuty, Config, IAM Access Analyzer, CloudTrail).

What you’ll bring

  • 5+ years in cloud security, cybersecurity, technology risk, or consulting with a bachelor's in a technical field.
  • 3+ years hands-on AWS security solution design/build/operate (Security Hub, GuardDuty, Config, IAM, KMS, CloudTrail).
  • 2+ years Terraform or CloudFormation for production infrastructure.
  • Experience securing EKS/containers, SageMaker/Bedrock, or data protection with Macie in production.

Technologies

AWS · Amazon Bedrock · Amazon SageMaker · Amazon EKS · Terraform · AWS CloudFormation · Amazon Macie · AWS KMS · AWS Security Hub · Amazon GuardDuty · AWS Config · AWS IAM

Source and classification

Production engineering · Evidence for this classification:

Join Deloitte’s Cloud Cyber Risk practice as a Forward Deployed Security Engineer and help organizations secure their Amazon Web Services (AWS) cloud and AI workloads at scale while working directly with client engineering teams. This is not an assessment-and-handoff role. You will design, build, deploy, and operate secure-by-default AWS environments and automated security controls across generative AI services, container and data platforms, infrastructure-as-code, and secure delivery pipelines. This role is designed for a hands-on engineer who enjoys solving complex cloud security challenges, building working automation, and supporting security outcomes in production environments. Recruiting for this role ends on 12/31/2026. Work you'll do As an Engineering and Product Engineer III on the Cloud Cyber Risk team, you will be responsible for: Embed directly with client cloud and
More from the job description

Join Deloitte’s Cloud Cyber Risk practice as a Forward Deployed Security Engineer and help organizations secure their Amazon Web Services (AWS) cloud and AI workloads at scale while working directly with client engineering teams. This is not an assessment-and-handoff role. You will design, build, deploy, and operate secure-by-default AWS environments and automated security controls across generative AI services, container and data platforms, infrastructure-as-code, and secure delivery pipelines. This role is designed for a hands-on engineer who enjoys solving complex cloud security challenges, building working automation, and supporting security outcomes in production environments. Recruiting for this role ends on 12/31/2026. Work you'll do As an Engineering and Product Engineer III on the Cloud Cyber Risk team, you will be responsible for: Embed directly with client cloud and platform engineering teams to design, build, deploy, and operate automated security controls across AWS environments from initial design through production support. Design and implement security guardrails for AWS generative artificial intelligence (AI) and machine learning services, including Amazon Bedrock, Amazon Bedrock AgentCore, and Amazon SageMaker, as well as containerized and serverless workloads on Amazon Elastic Kubernetes Service (EKS). Build automated data protection and data loss preve [... source excerpt omitted ...] intain AWS-native security services, including AWS Security Hub, Amazon GuardDuty, AWS Config, AWS Identity and Access Management (IAM) Access Analyzer, and AWS CloudTrail, within client monitoring and security operations workflows. Write and maintain production infrastructure-as-code using Terraform and/or AWS CloudFormation, integrate security scanning into continuous integration / continuous deployment (CI/CD) pipelines, and contribute reusable modules, runbooks, and reference implementations for future engagements. A successful candidate would possess these skills: Ability to work independently and collaborate as part of a team Effective written and verbal communication [... source excerpt omitted ...] r Risk team helps organizations pursue growth, innovation, and performance through proactive management of cyber risk. Our Forward Deployed Security Engineers work directly within client teams, combining risk, regulatory, and technology capabilities with hands-on engineering to design, build, and operate scalable, automated AWS cloud security solutions. This team works closely with clients to implement controls in production environments and support security outcomes at scale. Qualifications Required: 5+ years of experience in cloud security, cybersecurity, technology risk, or technology consulting; and a bachelor’s degree in computer science, cybersecurity, information tech

How jobs are selected

Employer postings · Data from · Sources