AWS Cloud Security Engineer
Quick Overview
Job Description
Role Summary
A senior-level AWS Cloud Security Engineer is responsible for designing, implementing, and maintaining security controls within AWS cloud environments supporting federal compliance standards such as FedRAMP Moderate. The role involves hands-on technical expertise in cloud security architecture, continuous monitoring, and compliance activities essential for securing sensitive government cloud workloads. The position requires collaboration across teams to ensure security best practices are embedded into cloud operations and architecture.
Responsibilities
- Design and implement AWS security architectures aligned with FedRAMP Moderate baseline controls.
- Configure and manage AWS-native security services including IAM, GuardDuty, Security Hub, Config, CloudTrail, KMS, WAF, Macie, and Inspector.
- Develop and maintain Infrastructure as Code security controls using Terraform or CloudFormation, incorporating policy as code principles.
- Support System Security Plan (SSP) development, Authorization to Operate (ATO) processes, and Plan of Actions & Milestones (POA&M) remediation efforts.
- Conduct continuous monitoring, vulnerability assessments, and patch management tracking to ensure ongoing compliance.
- Configure centralized logging, Security Information and Event Management (SIEM) integrations, and audit trail retention per federal requirements.
- Implement least-privilege IAM policies, service control policies (SCPs), and secure cross-account access controls.
- Manage encryption at rest and in transit, ensuring FIPS 140-2/140-3 compliance using KMS, ACM, and TLS protocols.
- Respond to security incidents, perform root cause analysis, and support cloud-specific incident response procedures.
- Collaborate with DevOps and Platform teams to embed security into CI/CD pipelines and automation workflows.
- Maintain documentation on control implementations, architecture diagrams, and audit evidence to support compliance audits.
- Assist with boundary definition and system categorization activities in accordance with FIPS 199 standards.
Qualifications
- This position requires eligibility for a U.S. Government security clearance. In accordance with federal law, U.S. citizenship is required. (ability to obtain and maintain a Public Trust or Secret clearance).
- Minimum of 5 years of hands-on AWS engineering experience, with at least 3 years focused on cloud security roles.
- Proven experience within federal compliance environments such as FedRAMP Moderate or High, DoD IL4/IL5, or equivalent frameworks.
- Experience supporting or maintaining System Security Plans (SSPs) and managing Risk Management Framework (RMF) processes.
- Familiarity with AWS GovCloud (US), AWS Commercial, or equivalent federal AWS environments.
- Extensive practical knowledge of AWS security services: IAM, GuardDuty, Security Hub, Config, CloudTrail, KMS, WAF, Macie, Inspector, and Systems Manager.
- Strong understanding of NIST SP 800-53 Revision 5 control families and mapping implementations to controls.
- Experience with Infrastructure as Code tools such as Terraform and CloudFormation, including security scanning and policy as code.
- Knowledge of networking security fundamentals including VPC design, security groups, NACLs, PrivateLink, and Transit Gateway.
- Experience with vulnerability management tools like AWS Inspector and remediation processes.
- Skilled in implementing Zero Trust Architecture (ZTA) principles within AWS.
- Ability to utilize SIEM and log aggregation tools such as Splunk, CloudWatch, or OpenSearch for security monitoring.
- Proficient in scripting languages, including Python and Bash, for automation and compliance tasks.
- Understanding of encryption standards relevant to federal systems, such as FIPS 140-2/140-3 and TLS 1.2+.
Publishing Pay Range: $74.00 - $78.00 hourly
This is a fully remote role and can be performed from any approved location within the United States.
Skills
Similar jobs
Windows Cloud Engineer - Mid-level
Boeing Company · Annapolis, United States
11 minutes ago$104k - $126k/yrNetwork Engineer – NE 1 TS/SCI Poly required with Security Clearance
Emtak LLC · Annapolis Junction, United States
56 minutes agoAzure Cloud Engineer with Security Clearance
NewGen Technologies · Lorton, United States
1 hour agoLead Security Cloud and AI Engineer
Perdue Farms, Inc. · Salisbury, United States
1 hour ago$128k - $192k/yrOracle Cloud PLM / PDH Delivery Architect
Argano · United States
1 hour agoOracle Cloud SCM Principal Architect
Capgemini America, Inc. · United States
1 hour ago$103.9k - $282k/yr