SRE- Security and Identify Engineer (548)
JSG (Johnson Service Group, Inc.) · New York, NY · Yesterday
Information TechnologyContract
Responsibilities
- Integrate the Project Omni API layer with AWS IAM Identity Center and the existing enterprise identity-federation and credential-vending model.
- Design and implement policy and entitlement controls to enforce data boundaries across SRE, Application teams, and Business Units.
- Implement and automate cross-account routing to aggregate logs, metrics, and traces across multiple AWS Organizations.
- Build, test, and deploy features end-to-end from the AWS infrastructure layer, including CloudWatch, Omni, and IAM, through the API layer serving the UI.
- Develop high-performance APIs in Python, Java, or Go to query CloudWatch, CloudTrail, and flow logs.
- Implement efficient caching strategies and asynchronous data-fetching capabilities.
- Automate infrastructure and resource deployment using Terraform or AWS CDK.
- Use AWS CloudFormation StackSets to deploy source links across approximately 15,000 AWS accounts.
- Produce clear architecture, integration, design, and operational documentation.
- Enable internal teams to operate and extend the Omni identity and routing model.
- Work as an embedded SME alongside SRE, observability, security, and engineering stakeholders.
Qualifications
- Advanced expertise with AWS IAM Identity Center (IdC), SAML/OIDC federation, and integration with established enterprise identity-federation and credential-vending models.
- Strong experience with AWS identity and access management, including attribute-based access control (ABAC) and fine-grained authorization using AWS Verified Permissions, Open Policy Agent (OPA), or similar policy engines.
- Advanced experience with AWS Organizations, CloudFormation StackSets, organization-level APIs and policies, including large-scale multi-account environments.
- Advanced Amazon CloudWatch and cross-account observability/OAM experience, including Metrics, Logs, Alarms, Contributor Insights, CloudTrail, and flow logs.
- Advanced Infrastructure as Code experience using Terraform or AWS CDK, including automated deployment through CI/CD pipelines.
- Proficiency in Python, Java, or Go with experience building high-performance REST/API services, asynchronous data fetching, and efficient caching strategies.
- Experience delivering solutions within a large, regulated enterprise environment and operating under formal change-control and audit requirements.
- Strong written documentation and stakeholder communication skills, with the ability to work directly with engineering, security, SRE, and observability teams.