Skip to content
EN

Esther Nanzi

Senior Security Engineer

San Antonio, TX

๐ŸŸขAping In

Senior Security Engineer with 11+ years securing AWS/Azure enterprise environments, building scalable IAM programs, and leading vulnerability management in retail, healthcare, and financial services. Blends hands-on engineering (Terraform, Python, Vault, Splunk, Wiz, Prisma Cloud) with governance and risk alignment (NIST 800-53, SOC 2, PCI DSS, SOX/FFIEC, HIPAA, GDPR/CCPA).

Work Preferences

Salary

GBP 100,000 โ€“ 130,000

Skills

AWS (IAM, EKS, Lambda, VPC, CloudTrail, WAF, KMS)9/10
NIST 800-53 / RMF9/10
Okta (Federation/SSO, Conditional Access)9/10
Wiz9/10
Prisma Cloud9/10
Terraform (9/10)PCI DSS (8/10)Python (8/10)Zero Trust Architecture (8/10)Azure (Entra ID, Key Vault, Sentinel) (8/10)GDPR / CCPA (8/10)HashiCorp Vault (8/10)HIPAA (8/10)Microsoft Sentinel (8/10)SOC 2 (8/10)Splunk (ES) (8/10)AI Security (OWASP LLM, MITRE ATLAS) (8/10)Rapid7 / Lacework (7/10)CloudFormation / Ansible (7/10)Bash (7/10)

Work Experience

Senior Security Engineer

lululemon

May 2022 โ€” Sept 2025

Directed enterprise AWS remediation across dozens of accounts; built AI Security Checklist aligned to OWASP LLM/MITRE ATLAS; managed Synack bug bounty engagements; authored Terraform for secure egress patterns; designed posture dashboards with Wiz/Prisma Cloud; implemented Island.io secure browser with Okta DLP; consolidated detections into Splunk/Microsoft Sentinel; published 8+ internal AWS guides and mentored engineers.

Cloud Security Engineer

GoHealth

Jan 2020 โ€” Apr 2022

Enforced HIPAA/SOC 2 controls in AWS; integrated Prisma Cloud and Wiz into CI/CD; designed RBAC mapping between AWS IAM and Azure Entra ID with JIT via PIM/Okta; built Jira-driven CVE workflows; tuned Splunk correlation rules; partnered on PCI DSS scoping; developed reusable Terraform modules; performed third-party vendor assessments.

Senior IAM & Cloud Security Engineer

Ally Financial

Jan 2019 โ€” Dec 2019

Rolled out Okta federation/SSO with adaptive MFA; deployed Azure Entra ID PIM for JIT admin access; implemented HashiCorp Vault SSH/LDAP secrets engines; automated de-provisioning and key rotation with Python/Bash; fed GuardDuty/CloudWatch into Splunk ES; aligned PCI DSS encryption and tokenization; contributed to enterprise Zero Trust patterns.

Security Engineer, Cloud & IAM

Merkle

Jan 2017 โ€” Dec 2018

Stood up secure multi-account AWS landing zone with CIS Foundations controls; built Terraform-first IAM with ServiceNow approvals; integrated Lacework and Rapid7 for posture/vulnerability scanning; implemented Acunetix DAST in CI; authored GDPR/CCPA security addenda; conducted architecture reviews for client workloads.