BusPatrol is transforming student transportation safety through AI-enabled, cloud-connected platforms and real-time operational systems. We are seeking a Senior Cybersecurity Engineer to make those platforms secure by default, resilient, and easier for engineering teams to operate safely. This is a hands-on engineering role focused on securing the platform layer: AWS identity and access, multi-account guardrails, network security, secrets and encryption, infrastructure-as-code, CI/CD security controls, vulnerability management, and security telemetry. You will partner with DevOps, application engineering, architecture, MLOps, IT, and Cyber Security to turn security requirements into reusable controls and paved-road patterns.
🏢 About BusPatrol
BusPatrol is transforming student transportation safety through AI-enabled, cloud-connected platforms and real-time operational systems.
🎯 The Role
This is a hands-on engineering role focused on securing the platform layer: AWS identity and access, multi-account guardrails, network security, secrets and encryption, infrastructure-as-code, CI/CD security controls, vulnerability management, and security telemetry. You will partner with DevOps, application engineering, architecture, MLOps, IT, and Cyber Security to turn security requirements into reusable controls and paved-road patterns.
✅ Key Responsibilities
Design, implement, and continuously improve security controls across BusPatrol’s AWS multi-account environments.
Establish least-privilege identity patterns using AWS IAM, IAM Identity Center, Entra ID, permission sets, groups, cross-account roles, service roles, and time-bound elevated access where appropriate.
Build and maintain secure, reusable Terraform modules and AWS CDK constructs for platform services, security controls, logging, encryption, networking, and account/environment guardrails.
Help evolve AWS Organizations, Control Tower, service control policies, account boundaries, and shared-services patterns to reduce blast radius and improve governance.
Secure cloud networking through practical controls for VPCs, routing, security groups, network ACLs, WAF, private connectivity, site-to-site VPNs, Direct Connect, and related network segmentation strategies.
Implement and operate secrets-management and encryption patterns using AWS KMS, Secrets Manager, Parameter Store, TLS, and automated credential rotation.
Integrate security checks into GitHub Actions and other delivery workflows, including infrastructure validation, dependency and vulnerability scanning, container/image security, SBOMs, signing, and policy enforcement.
Develop policy-as-code and preventive guardrails using appropriate tools such as AWS Config, SCPs, CloudFormation Guard, OPA, Conftest, Checkov, tfsec, or equivalent technologies.
Partner with engineering teams to define secure golden paths, platform templates, and documented patterns that make the safest implementation the easiest implementation.
Operate and improve cloud security telemetry and findings across services such as GuardDuty, Security Hub, CloudTrail, AWS Config, CloudWatch, and Datadog.
Triage, prioritize, and remediate platform security findings from CNAPP, CSPM, vulnerability-management, penetration-testing, and internal assessment tools, including Wiz or comparable platforms.
Support incident response, containment, root-cause analysis, and post-incident improvement for cloud, infrastructure, identity, and platform security events.
Produce concise architecture decisions, threat-informed control designs, runbooks, evidence, and operational documentation that engineering teams can use.
Collaborate with Cyber Security and GRC on SOC 2, ISO 27001, CIS, NIST, customer assurance, and audit-readiness activities without turning compliance into a manual exercise.
Mentor engineers through design reviews, infrastructure pull requests, office hours, and practical security enablement.
Contribute to secure AI-enabled engineering and platform workflows by protecting sensitive data, non-human identities, secrets, tool permissions, logging, and production change controls.
📌 Required Qualifications
8–10+ years of professional experience in cloud security, platform security, DevSecOps, infrastructure security, or a related engineering discipline.
Deep hands-on experience securing production AWS environments, preferably across multiple accounts and environments.
Strong knowledge of AWS IAM, IAM Identity Center, KMS, Secrets Manager, Parameter Store, CloudTrail, GuardDuty, Security Hub, AWS Config, Organizations, SCPs, and VPC security.
Demonstrated ability to implement infrastructure security through Terraform, AWS CDK, CloudFormation, or comparable infrastructure-as-code tooling.
Experience designing and enforcing least-privilege access, role-based access, group-based permissions, cross-account access, and privileged-access controls.
Practical understanding of cloud network security, including segmentation, routing, security groups, WAF, private connectivity, site-to-site VPNs, and Direct Connect concepts.
Experience with vulnerability management, security findings, risk prioritization, remediation tracking, and verification of control effectiveness.
Working knowledge of policy-as-code, preventive and detective controls, security automation, and compliance evidence collection.
Strong Linux, networking, scripting, Git, and troubleshooting skills.
Experience responding to or supporting security incidents in production environments.
Ability to communicate clearly with engineers, architects, security professionals, auditors, and technical leadership.
Strong written documentation habits and a pragmatic, automation-first mindset.
⭐ Desirable Experience
Experience with AWS Control Tower, landing zones, account vending, shared services, or large-scale AWS governance.
Experience with Wiz, Qualys, Prisma Cloud, Lacework, or comparable CNAPP/CSPM and vulnerability-management platforms.
Please let BusPatrol know that you found this role at devopsprojectshq.com as a way to support us, so we can keep providing you with awesome DevOps jobs.
Never miss a job
Join 2,000+ DevOps developers getting weekly alerts for remote and US/EU roles, Kubernetes, AWS, Terraform, filtered for your stack.
🔒 Need an IP to whitelist?
Get a dedicated static EU outbound IP for Banks, payments, EHRs, APIs, AI.