Cloud Security Engineer
Quick Overview
Job Description
Hello Everyone,
Hope you are doing good!!!!
My name is Pavan and I work with SPAR Information System., I have a great opportunity for you, please find the job details below, if you are interested in applying please send me your updated resume and best time for you to discuss about this opportunity in details.
Senior Cloud Security Engineer
Location Remote
Duration: Long term contract
The Senior Cloud Security Engineer (Onshore) will lead the implementation, hardening, and operationalization of the cloud security posture for the AWS GovCloud Landing Zone program. Working directly with the client on-site, this role is responsible for deploying enterprise-grade security controls, implementing FIPS-compliant encryption standards, automating governance and compliance frameworks, and supporting FedRAMP/IL2 readiness activities, including mock C3PAO assessments and audit preparation.
The engineer will deploy and manage AWS-native security services across a multi-account AWS GovCloud environment, including AWS Security Hub, GuardDuty, Macie, AWS Config, and AWS Audit Manager. The role requires establishing centralized security monitoring, threat detection, and compliance visibility across all cloud accounts while ensuring alignment with federal security requirements and organizational security policies.
A key responsibility will be implementing and maintaining encryption and key management controls, including AES-256 encryption for data at rest, TLS 1.2+ FIPS-compliant encryption for data in transit, AWS KMS utilizing FIPS 140-2 Hardware Security Modules (HSMs), and AWS Secrets Manager with automated credential rotation. The engineer will ensure all security controls meet government and regulatory compliance requirements.
The role also involves designing and enforcing AWS governance frameworks through Service Control Policies (SCPs), including region restrictions, FIPS enforcement policies, service deny lists, tagging standards, and organizational guardrails. The engineer will implement IAM security best practices such as permission boundaries, cross-account access controls, least-privilege models, and federated-only access using enterprise identity providers.
Strong experience with compliance automation is required. The candidate will configure AWS Config conformance packs aligned with NIST SP 800-53, FedRAMP, FISMA, and DoD IL2 control requirements, enabling continuous compliance monitoring and automated remediation. Additionally, the engineer will deploy AWS Audit Manager to streamline evidence collection, manage compliance artifacts, and support audit readiness initiatives.
From a security operations perspective, the candidate will establish centralized logging and monitoring capabilities using AWS CloudTrail, AWS Security Lake, VPC Flow Logs, and SIEM platforms such as Splunk integrated through Cribl. This includes ensuring log integrity through Object Lock retention policies, log aggregation, threat detection, and security analytics capabilities across the AWS environment.
The engineer will also support application-level security for Customer Facing Business (CFB) applications deployed on the Cloud Kubernetes Platform (CKP). Responsibilities include implementing platform and application hardening controls, identifying security gaps, remediating vulnerabilities, and supporting security assessments performed by internal teams and external auditors.
A significant aspect of the role involves supporting FedRAMP authorization efforts by preparing compliance evidence, remediating security findings, participating in mock C3PAO assessments, assisting with eMASS documentation requirements, and coordinating with assessors throughout the authorization process. Experience with risk management, governance documentation, and regulatory compliance frameworks will be critical for success.
The ideal candidate will possess at least 8 years of cloud security experience, including 4+ years of hands-on AWS security engineering experience. Strong expertise in AWS Security Hub, GuardDuty, Macie, AWS Config, AWS KMS, Secrets Manager, IAM governance, SCP implementation, centralized logging, SIEM integration, and compliance automation is required. Experience supporting FedRAMP, FISMA, NIST SP 800-53, DoD IL2, AWS GovCloud environments, and formal assessment activities is highly preferred.
Preferred qualifications include AWS Certified Security Specialty certification, hands-on experience with Splunk and Cribl, familiarity with C3PAO or 3PAO assessment processes, knowledge of eMASS and NIST SP 800-37 Risk Management Framework (RMF), exposure to software supply-chain security controls such as SBOM and container image signing, and experience implementing Zero Trust security architectures within AWS GovCloud environments.
Mandatory Skills: AWS GovCloud, AWS Security Hub, GuardDuty, Macie, AWS Config, AWS KMS, Secrets Manager, Service Control Policies (SCPs), IAM Governance, Permission Boundaries, CloudTrail, Security Lake, VPC Flow Logs, Splunk, Cribl, AWS Audit Manager, FedRAMP, FISMA, NIST SP 800-53, FIPS 140-2 Encryption, Compliance Automation, and Security Hardening.
Thanks & Regards,
Pavan Raikhelkar
LEAD TALENT ACQUISITION SPECIALIST
Direct Number:-
Fax :
Email:
Website:
(An E-verify Company)
NOTE: We respect your online privacy. This is not an unsolicited mail. Under bill 1618 title III passed by the 105th us congress this mail cannot be considered Spam as long as we include contact information and a method to be removed from our mailing list. If you are not interested in receiving our e-mails, please reply with a "REMOVE" in the subject line. We apologize for any inconvenience caused by this mail.
Skills
Similar jobs
Google Cloud Platform Data Engineer
Galaxy i Technologies, Inc. · Phoenix, United States
16 minutes agoCloud Architect
Dew Softech Inc · Trenton, United States
16 minutes agoCloud Engineer Specialist :: Only Locals to VA/MD/DC area
Reliable Software Resources · McLean, United States
16 minutes agoAWS Cloud Architect AI & Cloud Governance - Remote - Long Term Contract (Client in Trenton, NJ) - B4180B
Technovision, Inc. · United States
17 minutes agoGuidewire Policy Center Cloud Architect
Savi Technologies · United States
37 minutes agoCloud Architect - AI Model (Remote)
GSK Solutions Inc. · United States
2 hours ago€90/hr