AWS Cloud Security Engineer
Posted 37mins ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
AWS Cloud Security Engineer securing Peraton’s FedRAMP-authorized AWS infrastructure. Implementing cloud controls, continuous compliance, and ATO support for national security missions.
Responsibilities:
- Design and implement security architecture for AWS workloads aligned with FedRAMP Moderate baseline controls
- Build and maintain AWS security guardrails using IAM, GuardDuty, Security Hub, Config, CloudTrail, KMS, WAF, Macie, and Inspector
- Implement and manage Infrastructure as Code security controls using Terraform or CloudFormation with policy as code
- Support System Security Plans, Authorization to Operate activities, and POA&M remediation
- Perform continuous monitoring, vulnerability scanning, patch management tracking, and monthly/annual assessment support
- Configure and maintain centralized logging, SIEM integration, and audit trail retention according to FedRAMP/NIST requirements
- Implement least-privilege IAM policies, service control policies, and cross-account access controls
- Manage encryption at rest and in transit using KMS, ACM, and TLS enforcement per applicable FIPS requirements
- Respond to security incidents, perform root cause analysis, and support cloud-specific incident response playbooks
- Collaborate with DevOps and Platform teams to embed security into CI/CD pipelines through DevSecOps
- Maintain control implementation statements, architecture diagrams, and audit evidence documentation
- Support boundary definition and system categorization activities under FIPS 199
Requirements:
- US citizenship required
- Ability to obtain and maintain a Top-Secret eligible clearance
- Minimum 8 years work experience with BS/BA in computer science, Information Systems, or a related field (or equivalent experience)
- 5+ years of hands-on AWS engineering experience, with 3+ years specifically in cloud security roles
- Experience working within a FedRAMP Moderate or FedRAMP High, DoD IL4/IL5, or equivalent federal compliance environment
- Experience supporting or maintaining an SSP and RMF processes
- Experience with AWS GovCloud (US), AWS Commercial, or equivalent federal AWS environments
- Hands-on expertise with AWS security services including IAM, GuardDuty, Security Hub, AWS Config, CloudTrail, KMS, WAF, Macie, Inspector, and Systems Manager
- Understanding of NIST SP 800-53 Rev 5 control families and ability to map implementations to specific controls
- 3+ years of experience with Infrastructure as Code using Terraform and/or CloudFormation, including security scanning and policy-as-code tools
- Networking security fundamentals including VPC design, security groups, NACLs, PrivateLink, Transit Gateway, and network segmentation
- Experience with vulnerability management tools and remediation tracking
- Experience implementing Zero Trust Architecture in AWS
- Familiarity with SIEM/log aggregation tools such as Splunk, AWS CloudWatch, and OpenSearch
- Scripting ability in Python or Bash
- Understanding of FIPS 140-2/140-3 and TLS 1.2+
- One of AWS Certified Security – Specialty, AWS Certified Solutions Architect – Professional with a security focus, CISSP, CISM, or Security+ with strong AWS hands-on experience
- Preferred: Direct experience supporting a Peraton program or similar federal integrator
- Preferred: Familiarity with server and systems hardening software
- Preferred: Experience with container security, AWS Control Tower, continuous ATO evidence collection, regulated change management, AWS AI services, hybrid/multi-cloud architecture, Microsoft .NET, DevSecOps pipelines, AI security and governance frameworks, and federal agencies or large GovCon programs
Benefits:
- Discretionary bonus may be available in addition to base pay
- Overtime may be available
- Shift differential may be available
















