Cloud Engineer
Posted 1ds ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Cloud Engineer supporting AWS WordPress infrastructure, Kubernetes CI/CD, and security for U.S. federal government agencies. Maintaining cloud environments, automation, monitoring, and compliance controls.
Responsibilities:
- Support a WordPress site on AWS running a Kubernetes CI/CD pipeline
- Implement, support, and maintain all environments across web assets, including lower environments
- Achieve enterprise uptime, monitoring, and business continuity goals
- Manage a high-volume WordPress production environment on AWS, including traffic spikes
- Establish monitoring and operational procedures to ensure business continuity
- Maintain, support, and troubleshoot developer, testing, and pre-production environments using Kubernetes/EKS and other AWS utilities
- Collaborate with the AWS Architect, Product Owner, Scrum Master, engineers, and security engineers to define and build service offerings and future-release roadmaps
- Participate in coordinating and implementing AWS Cloud solutions
- Implement proofs of concept and pilots
- Develop operational plans and documentation for AWS solutions
- Build and implement cloud infrastructure as the first field of production support calls
- Engineer and design solutions on AWS and other cloud platforms
- Run risk logs and collaborate with the ISSO and System Owner to manage risk
- Provide responses to Common Vulnerability Reports
- Document system boundaries and implement technology-relevant controls with supporting evidence
- Recommend approaches for security regulations, controls, and policy compliance
- Install, configure, and test cloud services, third-party services, and software
- Determine how to leverage cloud-provider services and address gaps with other tools, software, or third-party services
- Assess system security controls, validate implementation, and identify weaknesses
- Perform continuous monitoring using security solutions and tools
- Conduct security impact assessments for proposed environmental changes
- Identify innovative ways to automate security management, monitoring, and related processes to reduce risk and costs
Requirements:
- Must be able to obtain a Public Trust
- Kubernetes and understanding traffic patterns for a high-traffic website running a Content Management System preferred
- Knowledge of Amazon web infrastructure and services including Route53, CloudFormation, OpenSearch, Kinesis Firehose, Config, EKS, WAF, CloudFront, EC2 & EBS, RDS, ALB, Certificate Manager, S3, Secrets Manager, Virtual Private Cloud, Lambda, Inspector, Key Management Service, ElasticCache, SES, CloudShell, ECR, CloudWatch, SNS, GuardDuty, and CloudTrail
- Experience managing and deploying pipeline solutions and containerized applications using tools such as Argo Workflows, ArgoCD, GitHub Actions, GitLab CI, Azure DevOps, Jenkins, and Bitbucket Pipelines
- Experience building and supporting Infrastructure as Code using tools such as AWS CDK, ACK, CloudFormation, Terraform, Pulumi, Ansible, Salt, and Chef
- Proven knowledge of PowerShell and ability to build and understand logical scripts
- Deep understanding of IaaS, PaaS, and serverless services and how to combine them into complex solutions
- Ability to research, analyze, design, propose, and support solutions aligned with business and technology strategies
- Ability to design data, system, and component architectures and communicate them in simple language to executive leadership
- Experience with Agile methodologies, especially TDD and Scrum; Kanban is a plus
- Experience with LEMP and LAMP stacks, WordPress installation and configuration, MySQL performance and scaling, ElasticPress, Elasticsearch, ELK stack, Git, and Bitbucket
- Knowledge of DevOps lifecycle and process improvement strategies
- Knowledge of Change and Configuration Management best practices
- BS in computer science, information systems, cybersecurity, or related IT or security field
- 5 years of professional experience in IT/network engineering, cloud, security engineering, system administration, or security operations
- 7 years of experience in a security-related role with FISMA, FedRAMP, and NIST SP 800-53
- Ability to communicate contributions involving application controls, technical leads, security findings, Common Vulnerability Reports, Security Impact Assessments, and Authorization-To-Operate support
- Strong analytical skills and solid verbal and written communication skills
- Experience with Okta and/or Keycloak application integrations
- Experience with networking for web applications on AWS, Route53, and Certificate Manager
- Experience managing OpenSearch or Elasticsearch, including instance provisioning, dashboard design for public-traffic WAF data via Kinesis Firehose, and WordPress web search capability
- AWS, CISSP, CISM, CISA, CEH, CCSK, CCSP, or related security certifications are nice to have
- Experience with vulnerability management, incident detection, event/audit collection and analysis, and network and web application firewalls
- Relevant bachelor's degree or similar experience
- Experience with Section 508 compliance and user experience
- Experience with federal government system Certification and Accreditation for FISMA compliance with NIST 800-37
- Experience with Security Test and Evaluation of federal government systems
- FITSP Certification or equivalent
- Knowledge of FISMA, OMB Circular A-130, and NIST
- Must be able to work remotely and support occasional infrequent production troubleshooting outside 9-to-5 hours
Benefits:
- Medical, dental, and vision insurance
- 401(k) retirement plan
- Paid time off
- Paid parental leave
- Life and disability insurance
- Flexible spending accounts
- Commuter benefits
- Tuition reimbursement
- Remote work
















