Senior AWS Cloud Security Consultant at Vertical Relevance
Manhattan, NY
—
Aug 15, 2026
Manhattan, NY
Sep 24, 2026
What this job asks for AI summary
A consulting role focused on designing and enforcing enterprise cloud security controls on AWS within highly regulated industries, particularly financial services. The work centers on preventing data exfiltration through policy-as-code, data perimeter architecture, and API-level threat modeling, using tools such as OPA/Rego, AWS Organizations SCPs/RCPs, and IAM guardrails. Suits an experienced cloud security architect comfortable operating in compliance-heavy environments.
Senior level · 8+ years · Remote
Quick apply — this platform usually takes a CV and a few fields.
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
What the occupation pays Median $132,021 (middle half $99,961–$167,095).
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Aug 18, 2026. It is a model, not a headcount.
Why we read it this way (7)
No work location or metro area is specified in the posting; remote status is inferred from the absence of any location requirement and the consulting/distributed nature of the firm, but is not explicitly confirmed.
The posting's 'Key Responsibilities' section doubles as the required qualifications list — the 8+ years experience figure and all hard technical requirements (OPA/Rego, AWS IAM, AWS Organizations SCPs/RCPs, data perimeter architecture) are drawn from that section.
SOC classification is Medium confidence: the role blends cloud security architecture (15-1212) with substantial policy-engineering and infrastructure work that could also fit 15-1299 (Computer Occupations, All Other). The primary day-to-day focus on security analysis, threat modeling, and governance controls tips the classification toward 15-1212.
Kivera.io and Cloudflare One are listed together under Preferred Qualifications as interchangeable policy enforcement platforms; they are captured as a single skill with an alternative.
The 'Technical Environment' section lists the team's stack (OPA, Kivera.io, Cloudflare One, Terraform, GitHub Actions, CloudWatch, CloudTrail, VPC Flow Logs, Amazon EKS) without gating language; those tools not already captured as required are marked preferred.
No compensation, employment type, or degree requirement is stated in the posting.
Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): Data perimeter architecture.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.