Haystack
← Back to Jobs
Technology
DE

Onsite in Bellevue, WA/Cloud Security Engineer — Advanced Fusion Center (AFC) SME/12+ Months Contract Role

Dexperts IncBellevue, WA🇺🇸United StatesPosted 3 Sept 2026

Quick Overview

Seniority
Mid Senior
Work mode
On Site
Location
Bellevue, WA, United States
Posted
20 hours ago
AWSSOC 2AnsibleAzureGoogle CloudKubernetesPrismaTerraformZero Trust

Job Description

Hello,                                                                                                 

 

This is Akash Singh from Dexperts INC. I hope you’re doing great. I have an urgent requirement with one of our clients for a Cloud Security Engineer. Position. Please go through the below requirement and revert to me with your updated resume.

 

Job Details:

Job Title: Cloud Security Engineer — Advanced Fusion Center (AFC) SME

Location: Onsite in Bellevue, WA

Duration: 12+ Months 

 

About the Role

We're seeking a Cloud Security Engineer to join an Advanced Fusion Center (AFC) Subject Matter Expert (SME) team supporting the ongoing, day-to-day operation and monitoring of a client's cloud security stack. This is a steady-state operations role — SME Services focus on the ongoing day-to-day management, operation, and/or monitoring of technology platforms

Working within client-owned infrastructure under client direction. It is not a net-new build/architecture role.

 

Key Responsibilities:

Directly from the engagement scope, the Cloud Security Engineer will:

·        Design and implement hybrid enterprise network architectures with segmentation, zero trust principles, and layered defenses2

·        Maintain operational cloud security and compliance continuity around hybrid cloud systems, primarily in AWS2

·        Support Prisma Cloud, Cortex Cloud, and CI/CD pipelines using Terraform2

·        Apply a deep understanding of cloud native controls (Azure NSGs, AWS SGs, routing, private endpoints, ingress/egress controls)2

·        Perform scripting, Infrastructure as Code (Ansible), and IT orchestration2 across managed platforms

·        Implement future-proof configurations with considerations for long-term maintainability and risk reduction2

·        Partner with business stakeholders to design secure implementation patterns and orchestration2

·        Assess the posture of current network security assets and remediate2

Required Qualifications (Must-Have)

·        AWS-primary cloud security experience — hands-on operational security and compliance in production AWS (hybrid a plus)

·        Prisma Cloud and/or Cortex Cloud (Palo Alto CNAPP) hands-on experience — CSPM/CWPP posture management

·        CI/CD security with Terraform — authoring and maintaining IaC in automated pipelines

·        Cloud-native network controls — AWS Security Groups, Azure NSGs, routing, private endpoints, ingress/egress design

·        Infrastructure as Code (Ansible) and IT orchestration platforms

·        Zero Trust & segmentation design and operational experience

·        Strong security posture assessment and remediation skills

Plus the SOW's baseline SME skillsets:

·        Proactively and reactively troubleshooting common issues within their field of expertise; Base experience in cloud, containerization, and other modern design patterns; Modern problem solving and design patterns: basic scripting, cloud, and automation; Critical thinking skills "beyond runbooks" and problem solving; Written and verbal communication and language skills3

Preferred Qualifications

·        Multi-cloud exposure (Azure/Google Cloud Platform alongside AWS)

·        Compliance framework experience (CIS, NIST, SOC 2, PCI-DSS)

·        Container/Kubernetes security (EKS/AKS)

·        Relevant certifications (e.g., AWS Security Specialty, Palo Alto PCCSE, Terraform Associate)

·        CI/CD security tooling (Checkov, tfsec, Snyk, Aqua/Trivy) — note: Prisma Cloud's IaC scanning is built on Checkov, so this experience transfers well

Similar jobs