At a Glance
- Tasks: Protect data and secure cloud environments while tackling real-world cyber threats.
- Company: Join Zerothcode, a forward-thinking tech company focused on modern software solutions.
- Benefits: Enjoy competitive pay, flexible work options, and opportunities for professional growth.
- Why this job: Make a difference in cybersecurity and work with cutting-edge AWS technologies.
- Qualifications: Experience in security operations and a solid understanding of AWS security tools.
- Other info: Dynamic team environment with a focus on innovation and continuous improvement.
The predicted salary is between 36000 - 60000 £ per year.
Responsibilities
- Design and enforce least-privilege IAM (roles, SCPs, SSO), key rotation and secrets hygiene (Secrets Manager/SSM).
- Enable & tune CloudTrail, Config, Security Hub, GuardDuty; own remediation SLAs with engineering.
- Protect data: KMS with tight key policies, S3 block-public-access, EBS/EFS encryption, TLS everywhere.
- Container security (EKS/ECS): IRSA, image scanning/signing (ECR/Trivy), Pod Security Standards, network policies.
- Patch & baseline EC2/OS with SSM Patch Manager/Inspector; golden AMIs/launch templates.
Secure SDLC & product security
- Build CI/CD gates: SAST (Semgrep), DAST (OWASP ZAP), dependency & container scans (Snyk/Trivy).
- Secure Terraform with tfsec/checkov, drift detection, mandatory reviews.
- Threat-model core CRM flows: authentication/session, email-to-ticket, uploads, time-to-invoice, Stripe/PayPal webhooks, role-based access, audit logging and rate limits.
- Set and document secure defaults (CSP, file type/size limits, webhook signing, CSRF/session policies).
Detection & response
- Centralise logs (CloudWatch/OpenSearch/SIEM) and write detections for IAM abuse, exfil and anomalous API calls.
- Build runbooks/playbooks; drive tabletops and continuous improvement; participate in the on-call rota.
Governance & compliance
- Maintain policies/standards (access control, vulnerability mgmt, backups, key mgmt, vendor risk).
- Support GDPR (data mapping, retention, DPIAs) and contribute to ISO 27001/SOC 2 readiness.
- Degree or equivalent experience in a technical field.
- Experience in a Security Operations/blue-team role (investigations, incident response and/or penetration testing) in a mid-to-large environment.
- Solid understanding of security threats and practical experience detecting & defending against cyber attacks.
- Hands-on with AWS (IAM, KMS, CloudTrail, Config, Security Hub, GuardDuty, VPC, ALB, WAF/Shield, S3).
- Ability to develop or automate with at least one language: Python, Go, TypeScript or Java (security scripts, tooling, detections).
- Comfortable reviewing code/config for security issues (app + IaC/Terraform).
Preferred qualifications
- Familiarity with MITRE ATT&CK, host/network telemetry (process lists, application logs, VPC Flow/NetFlow).
- Experience with streaming/analytics stacks (e.g., Kinesis/Kafka, OpenSearch/Splunk/ELK).
- Container security (EKS/ECS), image pipelines and policy enforcement.
- Exposure to PHP/Laravel stacks (our app), secure file uploads, email piping, and Stripe/PayPal webhook security (PCI SAQ-A boundaries).
- Certifications (e.g., AWS Security Specialty, GCIA/GCIH, CISSP) are a plus.
We regularly recruit at many positions. See related jobs here
Zerothcode builds and ships modern software products and delivers client solutions across…
We design and ship modern software across web and mobile—covering SaaS products…
Zerothcode CRM is a self-hosted, modern CRM for agencies, SMEs and service…
Subscribe to our newsletter for the latest updates.
Analytics
#J-18808-Ljbffr
Cyber Security Analyst, AWS Security employer: Zerothcode Pvt Ltd
Contact Detail:
Zerothcode Pvt Ltd Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Cyber Security Analyst, AWS Security
✨Tip Number 1
Network like a pro! Attend industry meetups, webinars, or even local tech events. It's all about making connections and getting your name out there—who knows, you might bump into someone from Zerothcode!
✨Tip Number 2
Show off your skills! Create a portfolio or GitHub repo showcasing your projects, especially those related to AWS security. This gives potential employers a taste of what you can do and sets you apart from the crowd.
✨Tip Number 3
Prepare for interviews by brushing up on common security scenarios and AWS tools. Practice explaining your thought process on how you'd tackle real-world problems—this will impress interviewers and show you're ready for the role.
✨Tip Number 4
Don't forget to apply through our website! It’s the best way to ensure your application gets seen. Plus, we’re always on the lookout for passionate individuals who want to make a difference in cyber security.
We think you need these skills to ace Cyber Security Analyst, AWS Security
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the Cyber Security Analyst role. Highlight your experience with AWS security tools and any relevant projects you've worked on. We want to see how your skills match up with what we're looking for!
Show Off Your Skills: In your cover letter, don’t just list your qualifications—show us how you’ve applied them in real-world scenarios. Talk about specific instances where you’ve tackled security challenges or improved processes. We love a good story!
Be Clear and Concise: When writing your application, keep it clear and to the point. Use bullet points for easy reading and make sure to proofread for any typos. We appreciate a well-organised application that gets straight to the heart of your experience.
Apply Through Our Website: We encourage you to apply through our website for the best chance of getting noticed. It’s super easy and ensures your application goes directly to us. Plus, you’ll get to see all the other cool positions we have available!
How to prepare for a job interview at Zerothcode Pvt Ltd
✨Know Your AWS Security Inside Out
Make sure you brush up on your knowledge of AWS security services like IAM, KMS, and CloudTrail. Be ready to discuss how you've implemented least-privilege access and managed secrets hygiene in past roles. This will show that you’re not just familiar with the tools but have practical experience using them.
✨Demonstrate Your Incident Response Skills
Prepare to share specific examples of how you've handled security incidents or vulnerabilities in the past. Discuss your approach to threat modelling and how you’ve built runbooks or playbooks for incident response. This will highlight your hands-on experience and problem-solving skills.
✨Showcase Your Coding Abilities
Since the role requires automation skills, be ready to talk about your experience with programming languages like Python or Go. Bring examples of scripts or tools you've developed for security purposes, and if possible, demonstrate your ability to review code for security issues.
✨Familiarise Yourself with Compliance Standards
Understand the basics of GDPR and ISO 27001/SOC 2 compliance, as these are crucial for the role. Be prepared to discuss how you’ve contributed to maintaining policies and standards in previous positions. This will show that you can navigate the governance side of security effectively.