AWS Cloud Security Engineer

Posted 37mins ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

AWS Cloud Security Engineer securing Peraton’s FedRAMP-authorized AWS infrastructure. Implementing cloud controls, continuous compliance, and ATO support for national security missions.

Responsibilities:

  • Design and implement security architecture for AWS workloads aligned with FedRAMP Moderate baseline controls
  • Build and maintain AWS security guardrails using IAM, GuardDuty, Security Hub, Config, CloudTrail, KMS, WAF, Macie, and Inspector
  • Implement and manage Infrastructure as Code security controls using Terraform or CloudFormation with policy as code
  • Support System Security Plans, Authorization to Operate activities, and POA&M remediation
  • Perform continuous monitoring, vulnerability scanning, patch management tracking, and monthly/annual assessment support
  • Configure and maintain centralized logging, SIEM integration, and audit trail retention according to FedRAMP/NIST requirements
  • Implement least-privilege IAM policies, service control policies, and cross-account access controls
  • Manage encryption at rest and in transit using KMS, ACM, and TLS enforcement per applicable FIPS requirements
  • Respond to security incidents, perform root cause analysis, and support cloud-specific incident response playbooks
  • Collaborate with DevOps and Platform teams to embed security into CI/CD pipelines through DevSecOps
  • Maintain control implementation statements, architecture diagrams, and audit evidence documentation
  • Support boundary definition and system categorization activities under FIPS 199

Requirements:

  • US citizenship required
  • Ability to obtain and maintain a Top-Secret eligible clearance
  • Minimum 8 years work experience with BS/BA in computer science, Information Systems, or a related field (or equivalent experience)
  • 5+ years of hands-on AWS engineering experience, with 3+ years specifically in cloud security roles
  • Experience working within a FedRAMP Moderate or FedRAMP High, DoD IL4/IL5, or equivalent federal compliance environment
  • Experience supporting or maintaining an SSP and RMF processes
  • Experience with AWS GovCloud (US), AWS Commercial, or equivalent federal AWS environments
  • Hands-on expertise with AWS security services including IAM, GuardDuty, Security Hub, AWS Config, CloudTrail, KMS, WAF, Macie, Inspector, and Systems Manager
  • Understanding of NIST SP 800-53 Rev 5 control families and ability to map implementations to specific controls
  • 3+ years of experience with Infrastructure as Code using Terraform and/or CloudFormation, including security scanning and policy-as-code tools
  • Networking security fundamentals including VPC design, security groups, NACLs, PrivateLink, Transit Gateway, and network segmentation
  • Experience with vulnerability management tools and remediation tracking
  • Experience implementing Zero Trust Architecture in AWS
  • Familiarity with SIEM/log aggregation tools such as Splunk, AWS CloudWatch, and OpenSearch
  • Scripting ability in Python or Bash
  • Understanding of FIPS 140-2/140-3 and TLS 1.2+
  • One of AWS Certified Security – Specialty, AWS Certified Solutions Architect – Professional with a security focus, CISSP, CISM, or Security+ with strong AWS hands-on experience
  • Preferred: Direct experience supporting a Peraton program or similar federal integrator
  • Preferred: Familiarity with server and systems hardening software
  • Preferred: Experience with container security, AWS Control Tower, continuous ATO evidence collection, regulated change management, AWS AI services, hybrid/multi-cloud architecture, Microsoft .NET, DevSecOps pipelines, AI security and governance frameworks, and federal agencies or large GovCon programs

Benefits:

  • Discretionary bonus may be available in addition to base pay
  • Overtime may be available
  • Shift differential may be available