Haystack
← Back to Jobs
Technology
DE

Cloud Security Engineer - Advanced Fusion Center (AFC) SME | Onsite - Bellevue, WA | 6+ Months Contract

Dexperts IncBellevue, WA🇺🇸United StatesPosted 3 Sept 2026

Quick Overview

Seniority
Mid Senior
Work mode
On Site
Location
Bellevue, WA, United States
Posted
19 hours ago
AWSSOC 2AnsibleAzureGoogle CloudKubernetesPenetration TestingPrismaTerraformZero Trust

Job Description

Job Details:

Job Title:             Cloud Security Engineer - Advanced Fusion Center (AFC) SME

Location:             Onsite - Bellevue, WA

Duration:            6+ Months Contract

 

Description:

We're seeking a Cloud Security Engineer to join an Advanced Fusion Center (AFC) Subject Matter Expert (SME) team supporting the ongoing, day-to-day operation and monitoring of a client's cloud security stack. This is a steady-state operations role - SME Services focus on the ongoing day-to-day management, operation, and/or monitoring of technology platforms

1 - working within client-owned infrastructure under client direction. It is not a net-new build/architecture role.

 

Key Responsibilities

Directly from the engagement scope, the Cloud Security Engineer will:

Design and implement hybrid enterprise network architectures with segmentation, zero trust principles, and layered defenses2

Maintain operational cloud security and compliance continuity around hybrid cloud systems, primarily in AWS2

Support Prisma Cloud, Cortex Cloud, and CI/CD pipelines using Terraform2

Apply a deep understanding of cloud native controls (Azure NSGs, AWS SGs, routing, private endpoints, ingress/egress controls)2

Perform scripting, Infrastructure as Code (Ansible), and IT orchestration2 across managed platforms

Implement future-proof configurations with considerations for long-term maintainability and risk reduction2

Partner with business stakeholders to design secure implementation patterns and orchestration2

Assess the posture of current network security assets and remediate2

 

Required Qualifications (Must-Have)

AWS-primary cloud security experience — hands-on operational security and compliance in production AWS (hybrid a plus)

Prisma Cloud and/or Cortex Cloud (Palo Alto CNAPP) hands-on experience — CSPM/CWPP posture management

CI/CD security with Terraform — authoring and maintaining IaC in automated pipelines

Cloud-native network controls — AWS Security Groups, Azure NSGs, routing, private endpoints, ingress/egress design

Infrastructure as Code (Ansible) and IT orchestration platforms

Zero Trust & segmentation design and operational experience

Strong security posture assessment and remediation skills

Plus the SOW's baseline SME skillsets:

Proactively and reactively troubleshooting common issues within their field of expertise; Base experience in cloud, containerization, and other modern design patterns; Modern problem solving and design patterns: basic scripting, cloud, and automation; Critical thinking skills "beyond runbooks" and problem solving; Written and verbal communication and language skills3

 

Preferred Qualifications

Multi-cloud exposure (Azure/Google Cloud Platform alongside AWS)

Compliance framework experience (CIS, NIST, SOC 2, PCI-DSS)

Container/Kubernetes security (EKS/AKS)

Relevant certifications (e.g., AWS Security Specialty, Palo Alto PCCSE, Terraform Associate)

CI/CD security tooling (Checkov, tfsec, Snyk, Aqua/Trivy) — note: Prisma Cloud's IaC scanning is built on Checkov, so this experience transfers well

Schedule: Business Hours (Monday through Friday 8:00 A.M. to 5:00 P.M.)5; not to exceed 40 hours per week6

Access model: Client-provided VDI with MFA7 (primary) plus site-to-site VPN

Screening: Comprehensive background checks8 confirming clearance appropriate to the sensitivity of client data

 

What This Role Is NOT (Scope Boundaries)

This role excludes: architecture design and implementation of net-new platforms in the Client environment; project-based work with specific deliverables and outcomes; security monitoring outside of platform health monitoring; penetration testing, application security, and adversary emulation.

Candidates should be comfortable in a hands-on operate-and-monitor capacity, not a greenfield build role.

Similar jobs