
AWS Cloud Security Engineer
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in United States.
• Design and execute security architecture for AWS workloads in accordance with FedRAMP Moderate baseline controls
• Develop and sustain security guardrails utilizing AWS-native services
• Implement and oversee Infrastructure as Code security measures with policy as code
• Assist in the preparation of System Security Plans, ATO activities, and POA&M remediation efforts
• Conduct continuous monitoring, vulnerability scanning, patch management tracking, and provide monthly/annual assessment support
• Configure and uphold centralized logging, SIEM integration, and audit trail retention following FedRAMP/NIST standards
• Enforce least-privilege IAM policies, service control policies, and cross-account access controls
• Manage encryption for data at rest and in transit in compliance with FIPS 140-2/140-3 standards where applicable
• Address security incidents, conduct root cause analysis, and support cloud-specific incident response protocols
• Work collaboratively with DevOps/Platform teams to integrate security into CI/CD pipelines
• Maintain documentation for control implementation statements, architecture diagrams, and audit evidence
• Provide support for boundary definition and system categorization tasks as necessary
• Must be a US citizen
• Capability to obtain and retain a Top-Secret eligible clearance
• Minimum of 8 years of work experience with a BS/BA in computer science, or 10 years of work experience with an AA/AS degree in Information Systems or a related field (or equivalent experience)
• Over 5 years of hands-on AWS engineering experience, with at least 3 years specifically in cloud security roles
• Proven experience working within a FedRAMP Moderate or FedRAMP High, DoD IL4/IL5, or comparable federal compliance environment
• Experience in supporting or maintaining an SSP and RMF processes
• Experience with AWS GovCloud (US), AWS Commercial, or equivalent federal AWS environments
• Strong practical expertise with AWS security services: IAM, GuardDuty, Security Hub, AWS Config, CloudTrail, KMS, WAF, Macie, Inspector, and Systems Manager
• Comprehensive understanding of NIST SP 800-53 Rev 5 control families (AC, AU, CM, IA, SC, SI, etc.) and the ability to map implementations to specific controls
• Over 3 years of experience with Infrastructure as Code (Terraform and/or CloudFormation), including security scanning and policy-as-code tools
• Fundamentals of networking security: VPC design, security groups, NACLs, PrivateLink, Transit Gateway, and network segmentation for compliance boundaries
• Experience with vulnerability management tools (AWS Inspector or similar) and remediation tracking
• Experience in implementing Zero Trust Architecture (ZTA) within AWS
• Familiarity with SIEM/log aggregation tools (Splunk, AWS CloudWatch, OpenSearch, or similar) for security event monitoring
• Scripting skills in Python or Bash for automating compliance checks and remediation
• Knowledge of encryption standards relevant to federal systems (FIPS 140-2/140-3, TLS 1.2+)
• One of the following certifications: AWS Certified Security – Specialty, AWS Certified Solutions Architect – Professional (with a security focus), CISSP, CISM, or Security+ (with strong AWS hands-on experience)
• Preferred: Direct experience supporting a Peraton program or a similar federal integrator
• Preferred: Familiarity with server and systems hardening software
• Preferred: Experience with container security (ECS/EKS), including image scanning (ECR scanning) and runtime protection
• Preferred: Experience with AWS Control Tower and multi-account landing zone security governance
• Preferred: Experience in automating compliance evidence collection for continuous ATO (cATO)
• Preferred: Previous experience with change management processes in a regulated/audited environment
• Preferred: Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related field
• Preferred: Active security clearance
• Preferred: Experience with AWS AI services (Amazon Bedrock)
• Preferred: Experience with hybrid/multi-cloud architecture, including Azure
• Preferred: Experience with Microsoft .NET
• Preferred: Experience in supporting ATO/continuous monitoring processes
• Preferred: Familiarity with DevSecOps pipelines
• Preferred: Familiarity with AI security and governance frameworks, national security/defense/critical infrastructure missions, and supporting federal agencies or large GovCon programs
• Potential eligibility for overtime
• Potential eligibility for shift differential
• Potential eligibility for a discretionary bonus
NVIDIA
Soteria - Security Solutions & Advisory
BMO U.S.
Abnormal Security
Get handpicked remote jobs straight to your inbox weekly.