Please mention DailyRemote when applying
Match your resume skills with our AI powered skill match!
Type: Contract, per-project.
Location: Remote - within LATAM time zones (GMT-3 to GMT-5) - Remote with meetings across U.S. time zones
Availability: Contractor (40 hours per week)
We are looking for a Cloud Security Remediation Engineer to work through a substantial backlog of security findings across our infrastructure and application fleet, covering dependency vulnerabilities, operating system currency, configuration issues, and endpoint coverage.
This role focuses on practical security remediation, vulnerability triage, infrastructure automation, and reducing security risk at scale while maintaining a high standard of care for production environments.
Triage security findings at scale by grouping them by root cause, assessing their actual exploitability in context, and identifying fixes that can address multiple findings efficiently.
Perform security remediation activities, including patching, end-of-life operating system migrations, configuration fixes, and closing endpoint coverage gaps.
Validate security remediations in development and test environments before deploying changes to production.
Automate repetitive remediation and security tasks using infrastructure and scripting tools.
Work with AWS security services to investigate and remediate security findings.
Document what was remediated, what was accepted as a risk or false positive, and the reasoning behind each decision.
2–5 years of experience in Cloud Security, Security Engineering, DevSecOps, Infrastructure, Platform Engineering, or a similar role.
Hands-on experience with AWS, particularly IAM and security services such as:
Security Hub.
GuardDuty.
Inspector.
Or credible equivalents from another cloud provider.
Practical security remediation experience in production environments, including closing security findings rather than only scanning and reporting them.
Experience with Terraform, including making changes in an existing codebase through pull requests.
Experience with Python for automation and tooling.
Linux fundamentals, including patching and operating system upgrade paths.
Clear written English.
Experience with CVE triage, including assessing whether vulnerabilities are genuinely exploitable and documenting the evidence supporting that assessment.
Experience with dependency vulnerability management at scale, including Dependabot or similar tools.
Experience with container image scanning and maintaining secure, up-to-date base images.
Experience with compliance and audit initiatives.
Experience automating security remediation workflows across large infrastructure environments.
Stop the endless job search. Our AI finds and applies to the best jobs for you.
Discover remote opportunities in Software Development
Answer easy questions
200,000+ jobs across 15+ categories
Get your best job matches
Only hand-screened, legit jobs
Find a remote job faster
No ads, scams, or junk
“ I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!