About this role.
Experian is seeking a DevOps Senior Engineer to join their global data and technology company. The role involves managing AWS security, including VPC firewalls, IAM, and security groups, as well as automating security configurations and managing infrastructure guardrails. The engineer will collaborate with security, DevOps, and engineering teams to ensure tight security for eCommerce platforms and lead projects from start to finish. Requires 5+ years of cloud security experience in AWS, scripting proficiency (Python), and an AWS Certified Security credential. Experian offers an inclusive culture and has been recognized as a top workplace globally.
Role DNA
A quick view of the complexity, pace, ownership and collaboration implied by the job description.
Job Complexity
4/5Pace & Pressure
4/5Autonomy Level
4/5Communication Load
4/5Salary analysis
Estimated compensation compared with the broader US market for similar roles.
Core skills
Skills and capabilities most closely associated with this opportunity.
Cover letter sample
Dear Hiring Manager,
I am excited to apply for the DevOps Senior Engineer position at Experian. With over 5 years of hands-on experience in AWS cloud security, I have developed deep expertise in managing IAM, security groups, and VPC firewalls to protect critical infrastructure. My background includes leading projects that automate security configurations and implement CI/CD pipelines, aligning perfectly with the responsibilities outlined.
I am particularly drawn to Experian's commitment to innovation and data-driven solutions, and I am eager to contribute to securing your eCommerce platforms. My proficiency in Python and AWS certifications, including AWS Certified Security Specialty, equip me to excel in this role. I look forward to the opportunity to bring my skills in collaboration and technical leadership to your team.
Sincerely,
[Your Name]
Sample interview questions
I would start by organizing accounts into organizational units (OUs) and apply SCPs at the root level to restrict actions like disabling CloudTrail or modifying VPC flow logs. Then, I'd create more granular SCPs for each OU based on business needs, ensuring guardrails prevent security misconfigurations while allowing flexibility.
I would use Infrastructure as Code (IaC) tools like Terraform to define security groups, store them in a Git repository, and apply changes via CI/CD pipelines. For dynamic rules, I'd integrate with a system like HashiCorp Vault for secrets and automate approvals for changes.
I implement a process using tools like Inspector or third-party scanners to identify vulnerabilities, then prioritize based on severity and exploitability. Remediation involves automated patching via AWS Systems Manager Patch Manager or custom scripts for container images.
I would use AWS CodePipeline with separate stages for build, test, and deploy. Security checks are integrated in the build stage using tools like Snyk or Checkov for IaC scanning. The pipeline then deploys to a green environment, validates via automated tests, and switches traffic after approval.
I start by creating AWS IAM policies based on job functions, using conditions to restrict access to specific resources. I use IAM Access Analyzer to monitor unused permissions and automate periodic reviews. Additionally, I implement role-based access with AWS SSO and enforce MFA.
Company Description
Experian is a global data and technology company, powering opportunities for people and businesses around the world. We help to redefine lending practices, uncover and prevent fraud, simplify healthcare, create marketing solutions, and gain deeper insights into the automotive market, all using our unique combination of data, analytics and software. We also assist millions of people to accomplish their financial goals and help them save time and money.
We operate across a range of markets, from financial services to healthcare, automotive, agribusiness, insurance, and many more industry segments.
We invest in people and new advanced technologies to unlock the power of data. As a FTSE 100 Index company listed on the London Stock Exchange (EXPN), we have a team of 22,500 people across 32 countries. Our corporate headquarters are in Dublin, Ireland. Learn more at experianplc.com.
Job Description
- Manage internal endpoints and VPC Firewalls to enhance security boundaries.
- Add and configure Security Groups in AWS for different applications and environments.
- Manage Role-Based Access Control (RBAC) and Identity Access Management (IAM) within the AWS cloud.
- Create, audit, and maintain policies and entitlements to ensure secure access to AWS services.
- Use AWS and third-party deployment tools for automation of security configurations.
- Set up Infrastructure Guardrails using AWS Service Control Policies (SCPs).
- Manage AMI Factory for automated image creation and validation.
- Implement and manage serverless policies and deployments in AWS.
- Operate and manage network traffic flow, NACLs, transit gateways, Peers, direct connect, and Security groups.
- Assess infrastructure and application vulnerabilities and take remediation actions.
- Operate and manage AWS IAM permissions based on defined roles and responsibilities.
- Ensure tight security for an eCommerce platform including data encryption, security groups, environment scanning, etc.
- Build the the pipeline supporting Continuous Delivery, and SDLC Security tools, including support for canary and blue green releases.
- Manage Linux-based operating systems and associated vulnerability management processes.
- Collaborate with information security, DevOps, and engineering teams to identify Platform needs and issues concerning security.
- Collaborate with main third-party security partners to ensure that security controls follow defined policies and mitigate risks.
- Perform advanced security technical troubleshooting for cloud and e-commerce environments.
- Lead projects from start to finish and be the go-to technical person for that initiative.
- Administer Linux OS vulnerability management to ensure systems are patched and secure.
- Manage container vulnerability, applying patches and updates.
- Ensure system monitoring and logging using AWS and third-party tools.
Qualifications
- Bachelor’s degree in computer science, Information Systems, or equivalent experience.
- AWS Certified Security – Specialty or similar AWS certifications.
- 5+ years of experience in cloud security in AWS.
- Experience with cloud networking architectures, cloud operations, security, automation, Systems management, and orchestration.
- Proficiency with scripting languages such as Python.
Additional Information
Our uniqueness is that we celebrate yours. Experian’s people first, inclusive and purpose driven culture is multi award-winning; World’s Best Workplaces™ 2025 (Fortune Global Top 25), Great Place To Work™ in 26 countries to name a few. Check out Experian Life on social or explore our Careers Site to understand why. Experian is also proud to be an Equal Opportunity and Affirmative Action employer. If you have a disability or special need that requires accommodation, please let us know at the earliest opportunity.
Experian is proud to be an Equal Opportunity Employer for all groups protected under applicable federal, state and local law, including protected veterans and individuals with disabilities. If you have a disability or special need that requires accommodation, please let us know at the earliest opportunity.
This is a remote role in Costa Rica. No relocation available.
#LI-ML2 #LI-Remote
Annual salary information is not provided for this position. Explore salary ranges for similar roles in our Salary Directory ›
This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.







