AWS Cloud Security Engineer

Posted 1 day ago

This is a fully remote position, open to applicants in United States.

📋 Description

• Design and execute security architecture for AWS workloads in accordance with FedRAMP Moderate baseline controls

• Develop and sustain security guardrails utilizing AWS-native services

• Implement and oversee Infrastructure as Code security measures with policy as code

• Assist in the preparation of System Security Plans, ATO activities, and POA&M remediation efforts

• Conduct continuous monitoring, vulnerability scanning, patch management tracking, and provide monthly/annual assessment support

• Configure and uphold centralized logging, SIEM integration, and audit trail retention following FedRAMP/NIST standards

• Enforce least-privilege IAM policies, service control policies, and cross-account access controls

• Manage encryption for data at rest and in transit in compliance with FIPS 140-2/140-3 standards where applicable

• Address security incidents, conduct root cause analysis, and support cloud-specific incident response protocols

• Work collaboratively with DevOps/Platform teams to integrate security into CI/CD pipelines

• Maintain documentation for control implementation statements, architecture diagrams, and audit evidence

• Provide support for boundary definition and system categorization tasks as necessary


⛳️ Requirements

• Must be a US citizen

• Capability to obtain and retain a Top-Secret eligible clearance

• Minimum of 8 years of work experience with a BS/BA in computer science, or 10 years of work experience with an AA/AS degree in Information Systems or a related field (or equivalent experience)

• Over 5 years of hands-on AWS engineering experience, with at least 3 years specifically in cloud security roles

• Proven experience working within a FedRAMP Moderate or FedRAMP High, DoD IL4/IL5, or comparable federal compliance environment

• Experience in supporting or maintaining an SSP and RMF processes

• Experience with AWS GovCloud (US), AWS Commercial, or equivalent federal AWS environments

• Strong practical expertise with AWS security services: IAM, GuardDuty, Security Hub, AWS Config, CloudTrail, KMS, WAF, Macie, Inspector, and Systems Manager

• Comprehensive understanding of NIST SP 800-53 Rev 5 control families (AC, AU, CM, IA, SC, SI, etc.) and the ability to map implementations to specific controls

• Over 3 years of experience with Infrastructure as Code (Terraform and/or CloudFormation), including security scanning and policy-as-code tools

• Fundamentals of networking security: VPC design, security groups, NACLs, PrivateLink, Transit Gateway, and network segmentation for compliance boundaries

• Experience with vulnerability management tools (AWS Inspector or similar) and remediation tracking

• Experience in implementing Zero Trust Architecture (ZTA) within AWS

• Familiarity with SIEM/log aggregation tools (Splunk, AWS CloudWatch, OpenSearch, or similar) for security event monitoring

• Scripting skills in Python or Bash for automating compliance checks and remediation

• Knowledge of encryption standards relevant to federal systems (FIPS 140-2/140-3, TLS 1.2+)

• One of the following certifications: AWS Certified Security – Specialty, AWS Certified Solutions Architect – Professional (with a security focus), CISSP, CISM, or Security+ (with strong AWS hands-on experience)

• Preferred: Direct experience supporting a Peraton program or a similar federal integrator

• Preferred: Familiarity with server and systems hardening software

• Preferred: Experience with container security (ECS/EKS), including image scanning (ECR scanning) and runtime protection

• Preferred: Experience with AWS Control Tower and multi-account landing zone security governance

• Preferred: Experience in automating compliance evidence collection for continuous ATO (cATO)

• Preferred: Previous experience with change management processes in a regulated/audited environment

• Preferred: Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related field

• Preferred: Active security clearance

• Preferred: Experience with AWS AI services (Amazon Bedrock)

• Preferred: Experience with hybrid/multi-cloud architecture, including Azure

• Preferred: Experience with Microsoft .NET

• Preferred: Experience in supporting ATO/continuous monitoring processes

• Preferred: Familiarity with DevSecOps pipelines

• Preferred: Familiarity with AI security and governance frameworks, national security/defense/critical infrastructure missions, and supporting federal agencies or large GovCon programs


🏝️ Benefits

• Potential eligibility for overtime

• Potential eligibility for shift differential

• Potential eligibility for a discretionary bonus

People also viewed

NVIDIA23 hours ago

Senior Manager, Cybersecurity

US flagCalifornia OnlyFull-timeCybersecurity / Security Engineer$240k – $379.5k/year
ApplyView job
Soteria - Security Solutions & Advisory23 hours ago

Senior Security Advisor – Lead Control Assessor

US flagSouth Carolina OnlyFull-timeCybersecurity / Security Engineer$110k – $150k/year
ApplyView job
BMO U.S.23 hours ago

Associate, Cards Security

CA flagCanada OnlyFull-timeCybersecurity / Security EngineerC$35.5k – C$50.5k/year
ApplyView job
Abnormal Security23 hours ago

Director of Security Engineering

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$214.2k – $308k/year
ApplyView job
World Wildlife Fund23 hours ago

Cybersecurity Specialist

EC flagEcuador OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Leidos1 day ago

Cyber Security Subject Matter Expert

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$131.3k – $237.4k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers