
Senior Cloud Technical Project Manager
Posted Aug 31

Posted Aug 31
This is a fully remote position, open to applicants in United States.
• Lead the cloud security operations for NSF AWS environments, encompassing triage, investigation, containment, and recovery.
• Manage Splunk Enterprise Security content and operations, including data onboarding, CIM alignment, correlation searches, notable event tuning, risk-based alerting, dashboards, and reporting.
• Oversee Prisma Cloud CSPM outcomes, focusing on posture baselines, policy standards and exceptions, remediation workflows, and tracking risk reduction.
• Engineer and enhance AWS logging and detection coverage.
• Integrate and operationalize CloudTrail, VPC Flow Logs, Route 53 Resolver logs, ALB/ELB logs, AWS Config, CloudWatch, GuardDuty, and Security Hub into Splunk ES and Prisma Cloud.
• Lead detection engineering mapped to the MITRE ATT&CK framework.
• Define and implement AWS incident response playbooks and escalation paths.
• Ensure the capture of evidence, reconstruction of timelines, and execution of post-incident corrective actions.
• Drive ongoing monitoring and compliance alignment with FISMA and NIST 800-53.
• Support audits through the provision of repeatable evidence packages.
• Collaborate with cloud platform, network, and application teams to establish security guardrails.
• Prioritize and monitor the remediation of misconfigurations and security findings.
• Automate security workflows such as enrichment, ticketing, evidence capture, and containment actions.
• Establish operational metrics and reporting cadence, including MTTD, MTTR, detection coverage, backlog, and trends in security posture.
• Manage team performance, technical quality, and delivery commitments.
• Mentor analysts and engineers.
• Participate in after-hours escalation and on-call activities as necessary.
• Perform additional job-related duties as assigned.
• Possess a Public Trust or the ability to obtain one.
• Have 7+ years of experience in cybersecurity, cloud security, or security operations, including over 3 years in technical leadership roles.
• Demonstrate hands-on experience in securing and operating production cloud environments.
• Preferred experience in AWS and/or Azure; GCP experience is acceptable.
• Strong background in SIEM operations, including log onboarding, correlation rules, alert tuning, and investigative workflows.
• Experience with cloud incident response, particularly in evidence handling and root-cause analysis.
• Working knowledge of cloud IAM, networking, encryption, key management, and secure service configurations.
• Familiarity with vulnerability management tools and coordinating remediation efforts across engineering teams.
• Ability to create clear operational documentation and deliver succinct, executive-ready status reports.
• Demonstrate security-first technical leadership with decisive incident command capabilities.
• Exhibit strong prioritization and risk-based decision-making skills.
• Ability to facilitate effective execution across technical and business teams.
• Possess clear communication skills to engage with technical teams and senior stakeholders.
• Maintain a continuous-improvement mindset focused on measurable outcomes.
• Must successfully pass pre-employment qualifications set by Cherokee Federal.
• Medical.
• Dental.
• Vision.
• 401K.
• Additional benefits may be offered.
• Military-friendly employer.
BAE Systems, Inc.
Avicado
Booker DiMaio
DLB Associates
Get handpicked remote jobs straight to your inbox weekly.