Team Leadership & Architecture Alignment: Lead a team of security engineers to translate architectural blueprints into technical controls, ensuring all cloud workloads align with the AWS Well-Architected Framework (Security Pillar).
Identity & Access Governance: Design, audit, and enforce enterprise-wide least-privilege access using structural guardrails like Service Control Policies (SCPs), Permission Boundaries, and AWS IAM Identity Center.
DevSecOps & Security Automation: Drive "shift-left" security by integrating automated vulnerability scanning into CI/CD pipelines and engineering programmatic, event-driven remediations via AWS Lambda.
Threat Detection & Incident Response: Oversee continuous posture monitoring and attack-path analysis using AWS Security Hub and Amazon GuardDuty, serving as the Tier 3 technical escalation lead for cloud security incidents.