Intelligence Match
Match: ??%
Unlock Your Personalized Match
Sign in to see your exact score breakdown and personalized insights.
Team Tagline
About the role
The organization is seeking a Senior Security Engineer to design, implement and continuously improve the technical security controls that protect its AWS cloud estate, Kubernetes (EKS) platform, software delivery pipelines and data stores. The role provides expert detection, response and assurance capability to keep digital services resilient, auditable and compliant with CBN, PCI DSS, ISO 27001 and NDPR requirements.
This is a full-time position based in Lagos, Nigeria, requiring 6–8 years of cybersecurity or security engineering experience, including at least 4 years securing production AWS workloads and 2 years securing Kubernetes (preferably Amazon EKS) and CI/CD pipelines. A bachelor's degree in Computer Science, Information Security, Engineering or a related discipline is required, and professional certifications such as AWS Certified Security – Specialty, CKS, CISSP, CISM, CCSP, OSCP or GIAC are strongly preferred.
Required Skills
Preferred Skills
Similar Skills not Listed
Responsibilities
- Design, implement and maintain preventive and detective security controls across all AWS accounts, including AWS Organizations service control policies, AWS Config rules and conformance packs, AWS WAF and AWS Shield.
- Enforce least privilege through IAM roles, permission boundaries, IAM Identity Center and IAM Access Analyzer; drive the elimination of long-lived access keys in favour of federated and role-based access.
- Own AWS Secrets Manager end to end — secret lifecycle, automatic rotation, resource and cross-account policies — and lead the removal of hard-coded credentials from application code, manifests and pipelines.
- Configure and maintain organization-wide AWS CloudTrail (including data and management events), CloudWatch log groups, metric filters, alarms and retention aligned to regulatory record-keeping requirements.
- Implement AWS Config baselines with automated drift detection and remediation against CIS AWS Foundations and PCI DSS benchmarks.
- Manage AWS WAF rule sets, rate limiting, bot control and geo restrictions for internet-facing applications behind CloudFront and ALB, and tune rules to minimise false positives without weakening protection.
- Operate Amazon GuardDuty, AWS Security Hub, Amazon Inspector and Amazon Detective as a single triage workflow — from finding, to enrichment and root-cause investigation, to verified closure.
- Define and review secure landing zone and VPC network patterns (segmentation, private subnets, VPC endpoints, security groups, managed prefix lists) and assess new architectures against them.
- Harden EKS clusters: private API endpoints, control plane audit logging to CloudWatch, node group hardening, and timely patching of cluster versions and node AMIs.
- Design, implement and periodically review Kubernetes RBAC, namespace isolation, service accounts and IAM Roles for Service Accounts (IRSA) / EKS Pod Identity.
- Enforce Pod Security Standards, admission control policy (OPA Gatekeeper or Kyverno) and Kubernetes network policies to restrict east-west traffic.
- Secure the container supply chain — approved base images, ECR and Amazon Inspector image scanning, image signing and admission-time signature verification.
- Deploy and tune runtime threat detection for containers (GuardDuty EKS Runtime Monitoring, Datadog Cloud Security Management) and investigate detections through to resolution.
- Secure secret delivery into workloads using the External Secrets Operator or Secrets Store CSI driver backed by AWS Secrets Manager, removing plaintext secrets from manifests and Helm values.
- Build and maintain detection coverage in Datadog Cloud SIEM — log pipelines, detection rules, signal correlation, suppression tuning and security dashboards.
- Operate Datadog Cloud Security Management (misconfiguration, identity and workload risk) and Application Security Management (runtime protection and vulnerability detection) alongside native AWS security services.
- Configure Datadog Sensitive Data Scanner to detect and redact PII and cardholder data in logs and telemetry.
- Ensure complete, tamper-evident log coverage across AWS, EKS, applications and databases, with defined retention, archiving and log integrity controls.
- Lead technical security incident response — triage, containment, eradication, recovery and post-incident review — and maintain runbooks, escalation paths and tabletop exercises.
- Define, track and report security metrics and posture trends to management and risk committees.
- Enforce encryption at rest and in transit across RDS, Aurora, DocumentDB, DynamoDB, S3, EBS and EFS using AWS KMS, with defined key policies, rotation and separation of duties.
- Implement IAM database authentication and Secrets Manager-driven credential rotation; remove shared, static and over-privileged database accounts in favour of least-privilege roles.
- Enable, centralise and monitor database audit logging (RDS and Aurora audit logs, DocumentDB auditing, SQL Server audit, CloudTrail data events) within the central log platform.
- Apply data classification, masking or tokenisation and access controls for sensitive and regulated data, and support data loss prevention requirements.
- Eliminate public database exposure — private subnets, restrictive security groups, no public accessibility — and validate backup and snapshot encryption, snapshot sharing controls and restore testing.
- Review database migrations, schema changes and access grants for security impact before approval.
- Translate CBN cybersecurity framework, PCI DSS, ISO 27001, NIST CSF and NDPR requirements into enforceable technical controls and repeatable evidence.
- Maintain security standards, secure configuration baselines and control documentation, and support internal and external audits with automated evidence collection.
- Conduct security assessments, vulnerability management cycles and configuration reviews; coordinate penetration testing and track remediation to closure.
- Perform security reviews of third-party vendors, SaaS integrations and exposed APIs.
- Contribute to risk register maintenance, security exception management and management reporting.
- Act as senior security advisor to infrastructure, platform, DevOps and application teams during architecture, design and change reviews.
- Mentor junior security and platform engineers, and raise the standard of security code and configuration review across engineering.
- Automate recurring security operations using Python, Bash, Terraform and AWS-native tooling to reduce manual effort and human error.
- Deliver targeted, role-relevant security training for engineering teams covering secure coding, secrets handling and incident escalation.
Job Application Safety Disclaimer
Your security and privacy are our top priorities. Please be aware that InStreamIQ will never ask you to pay any fees for job applications, placements, or training as a condition of employment.
Furthermore, legitimate employers will not ask for sensitive personal identification such as your Bank Verification Number (BVN), National Identification Number (NIN), or Passport details during the initial application phase. Do not share financial information or make any payments to individuals or organizations claiming to represent an employer. If you encounter any suspicious requests, please report the listing immediately via our support channels.