Skip to main content

AWS Security Engineer

BAE Systems Digital Intelligence is home to 4,500 digital, cyber and intelligence experts. We work collaboratively across 10 countries to collect, connect and understand complex data, so that governments, nation states, armed forces and commercial businesses can unlock digital advantage in the most demanding environments.

We are looking for a talented and enthusiastic individual with excellent technical and client-facing skills, to act an AWS security engineer, who can design, deploy 3rd party security applications as code, integrate with native AWS tools and maintain and configure those tools. 3rd party integration will included tools such as Splunk, JIRA ITSM, Cribl Stream.  The individual will need to be able to maintain and configure GuardDuty, Cloud Watch, Cloud Trail, VPC, AWS Config, Security Hub, Detective, Security Lake, Inspector and Audit Manager as a minimum.  They will also be responsible for working with wider engineering and development teams to design and deploy security monitoring solutions in AWS and integrating across multi-cloud and on-premise networks. The role will range from designing and deploying new solutions, assessing existing deployments to make improvements and onboarding new data sources.  This role is situated within our National Security  & Government Business, based in Canberra, with substantial time on client site.  The role will require a government security clearance at NV2 minimum, but candidates will be expected to undergo PV.

The company supports individuals career development and has a wide range of opportunities to develop further into cloud implementation, solution architecture and broader security consulting, depending up the aspirations and skills of the successful candidate

Find out more about our award winning Cyber Security solutions: http://www.baesystems.com/en/cybersecurity/solutions/by-business-objective/detect-and-monitor-for-cyber-attacks

 

Responsibilities

 

  • The role is a AWS developer who ca deploy infrastructure and applications as code, configure them and integrate with native AWS security tools.
  • Design and deploy AWS security services, apply security controls and check compliance against a range of security standards.
  • Develop, test and deploy security tools as code onto AWS via AWS pipelines on EC2 instances and integrate applications with:
    • identity management solution.
  • Security applications such as splunk, JIRA ITSM, and CTI tools.
  • Design, implement and manage log collection and onboarding activities onto AWS for SOC security tools s(SIEM) from cloud and on-premise environments
  • Oversee deployment / implementation activities ensuring that entry criteria are met, all planned activities are completed and that rollback plans are initiated where required.
  • Identify use cases, plan development, deployment, testing and release into production.
  • Liaise with product and platform teems to ensure that AWS security tools are configured managed, maintained and integrated with SOC security tools.
  • Review and approve all required documentation as part of a release or change including design, deployment, configuration and administration guides.
  • Integrate solutions with vulnerability and asset and configuration management and other tools to enrich efficacy of the solution.

 

Requirements

 

Technical  

  • Strong knowledge and experience in AWS configuration including EC2, S3, ELB, Kinesis, EKB, Docker and Kubernetes.
  • Strong knowledge and experience in AWS deployment and deployed as code via pipelines for infrastructure and security applications.
  • Use and best practices around AWS core tooling including Config, Investigator, IDAM etc
  • Strong relationship with regional AWS staff helpful
  • Experience in Azure helpful
  • Strong knowledge of how AWS security functions work as security controls as well as detection tools to protect large cloud estates; Produce content and playbooks on AWS and Splunk to detect security breaches and recognise the importance of threat led Use Cases.
  • Knowledge of SIEM/SOAR tools (Splunk and Sentinel at a minimum) and other appropriate tooling e.g. SOAR, Threat Intelligence, traffic analysis tools etc. to identify signs of an intrusion, and advise where new/improved tooling could enhance the SOC operation
  • Deep knowledge and experience of operational ICT service delivery management.
  • Working with a range of security tooling/technology
  • Strong understanding of security architecture, in particular networking
  • Detailed understanding of threat intelligence and threat actors, TTPs and operationalising threat intelligence.
  • Understand TCP/IP component layers to identify normal and abnormal traffic
  • Experience of Splunk (with ES) &/or Sentinel
  • Experience developing SIEM/SOAR content desirable

 

Non-technical

  • Client side consulting, including stakeholder engagement and the ability to communicate insights and concepts to others (including briefing skills and report writing)
  • Coaching mindset – help and mentor team
  • Security process development
  • Able to understand and adapt to different cultures and hierarchical structures.
  • Self-starter and capable of independent working
  • Team player and adept at working in multi-disciplinary and diverse teams
  • Communication
    • Ability to write concisely and clearly in simple language.
    • Ability to speak clearly and accurately in English.
  • Interpersonal
    • Ability to build and maintain relationships with the various stakeholders
    • Ability to talk competently and maintain high standards of behaviour with the client
    • Ability to work in a multi-cultural environment.
    • Ability to maintain confidentiality and deal with matters of national security.
    • Ability to maintain high standards and provide challenging feedback even when it will be perceived negatively.
    • It is imperative that the individual can complete their tasks with minimal direction.
  • Collaboration
      • Ability to work collaboratively
      • Self-awareness and understanding of your own strengths and weaknesses.
  • Adaptability
      • Good time and schedule management
      • Adaptability to react to rapid changes.
  • Motivation
  • Able to motivate groups and individuals all at various levels of knowledge and experience
  • Self-starter with the ability to maintain self-motivation
  • Able to manage and recognise signs of stress
  • Attitude
  • A Positive attitude, positive outlook and an active team leader/member
  • Utilising a common sense approach and maintaining a level head when faced with unusual requests
  • The individual needs to be able to maintain discretion and be highly trustworthy

 

Life at BAE Systems Digital Intelligence 

We are embracing Hybrid Working. This means you and your colleagues may be working in different locations, such as from home, another BAE Systems office or client site, some or all of the time, and work might be going on at different times of the day.

By embracing technology, we can interact, collaborate and create together, even when we’re working remotely from one another. Hybrid Working allows for increased flexibility in when and where we work, helping us to balance our work and personal life more effectively, and enhance well-being.

Diversity and inclusion are integral to the success of BAE Systems Digital Intelligence. We are proud to have an organisational culture where employees with varying perspectives, skills, life experiences and backgrounds – the best and brightest minds – can work together to achieve excellence and realise individual and organisational potential. 

Division overview: Capabilities

At BAE Systems Digital Intelligence, we pride ourselves in being a leader in the cyber defence industry, and Capabilities is the engine that keeps the business moving forward. It is the largest area of Digital Intelligence, containing our Engineering, Consulting and Project Management teams that design and implement the defence solutions and digital transformation projects that make us a globally recognised brand in both the public and private sector.

As a member of the Capabilities team, you will be creating and managing the solutions that earn us our place in an ever changing digital world. We all have a role to play in defending our clients, and this is yours. 

AWS Security Engineer

BAE Systems
Canberra ACT
Full-Time

Published on 22/01/2025

Share this job now