Jerad Engebreth

Experience

Senior Security Engineer

Amazon Web Services — Global Professional Services — Seattle, WA

Apr 2026 — Present

  • Lead independent security audits of AWS systems and services to evaluate control effectiveness across organizational boundaries
  • Conduct penetration testing, threat modeling, and code review to identify and drive remediation of security risks
  • Assess AI/ML security controls including model access, training data integrity, and output controls

Senior Cloud Security Consultant

Amazon Web Services — Professional Services — Seattle, WA

Apr 2021 — Apr 2026

Associate Cloud Consultant (2021) → Cloud Consultant (2022) → Senior (2024)

  • Lead customer engagements delivering secure cloud architectures and ATO guidance across DoD and government environments
  • Direct CI/CD pipeline security across enterprise customer engagements, implementing automated vulnerability scanning, container image scanning, and compliance checks within GitLab CI pipelines
  • Develop and deploy IaC using AWS CDK and Terraform — reusable security-hardened templates for VPCs, IAM, encryption, and logging
  • Conduct threat modeling and secure architecture reviews for cloud-native applications
  • Design IAM policies, network segmentation, and encryption aligned with zero-trust principles for multi-account environments
  • Implement container security — image scanning, vulnerability remediation, hardened base images, secrets management
  • Build automated security tooling in Python for compliance reporting and findings aggregation
  • Mentor engineers and customer teams on secure design patterns and DevOps security
  • Collaborate cross-functionally with engineering, operations, and compliance teams to embed security into the SDLC
  • Open source contributor to AWS Labs amazon-bedrock-agentcore-samples — authored a CDK IaC template for a full-stack AI agent with AgentCore Runtime, RAG, and comprehensive security controls
  • Architected and built Partner Hub, an internal full-stack application for managing partner relationships and hiring pipelines — React on ECS Fargate, API Gateway + Lambda, DynamoDB, Cognito with Amazon Federate SSO, deployed via CDK
  • Integrated a real-time AI assistant via WebSocket API Gateway, powered by Bedrock AgentCore Runtime with a Strands SDK agent querying 9 DynamoDB tool functions for natural language partner data search

SAP Security Administrator

Spry Methods — Chantilly, VA

Feb 2020 — Mar 2021

  • Administered enterprise security controls and GRC compliance tooling for production SAP environments

Senior IT Security Consultant

New River Systems Corporation — Belmont, VA

Feb 2017 — Jan 2020

  • Led multimillion-dollar GRC implementations across government and international clients, managing end-to-end security for cloud and on-premise enterprise applications

Skills

Cloud Security

AWS Security Architecture, IAM, Network Segmentation, Encryption, Zero-Trust

DevOps & CI/CD

GitHub Actions, GitLab CI, CodePipeline, Vulnerability Scanning, Pipeline Security

Infrastructure as Code

Terraform, AWS CDK, Policy-as-Code, Security-Hardened Templates

Containers

Docker, Kubernetes, Image Scanning, Container Hardening

Security Engineering

Threat Modeling, ATO, NIST/RMF, Secrets Management, Secure Code Review

Programming

Python, TypeScript, Bash, YAML

AI/ML Security

LLM Security, AI Infrastructure, Data Pipeline Protections

Certifications

  • ISC² CISSP, CCSP
  • AWS ML Engineer Associate, AI Practitioner
  • Microsoft Azure Fundamentals
  • CompTIA Security+

Education

Virginia Tech

Blacksburg, VA

B.S. Biological Systems Engineering — May 2016