Cloud Engineer

Posted 1ds ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Cloud Engineer supporting AWS WordPress infrastructure, Kubernetes CI/CD, and security for U.S. federal government agencies. Maintaining cloud environments, automation, monitoring, and compliance controls.

Responsibilities:

  • Support a WordPress site on AWS running a Kubernetes CI/CD pipeline
  • Implement, support, and maintain all environments across web assets, including lower environments
  • Achieve enterprise uptime, monitoring, and business continuity goals
  • Manage a high-volume WordPress production environment on AWS, including traffic spikes
  • Establish monitoring and operational procedures to ensure business continuity
  • Maintain, support, and troubleshoot developer, testing, and pre-production environments using Kubernetes/EKS and other AWS utilities
  • Collaborate with the AWS Architect, Product Owner, Scrum Master, engineers, and security engineers to define and build service offerings and future-release roadmaps
  • Participate in coordinating and implementing AWS Cloud solutions
  • Implement proofs of concept and pilots
  • Develop operational plans and documentation for AWS solutions
  • Build and implement cloud infrastructure as the first field of production support calls
  • Engineer and design solutions on AWS and other cloud platforms
  • Run risk logs and collaborate with the ISSO and System Owner to manage risk
  • Provide responses to Common Vulnerability Reports
  • Document system boundaries and implement technology-relevant controls with supporting evidence
  • Recommend approaches for security regulations, controls, and policy compliance
  • Install, configure, and test cloud services, third-party services, and software
  • Determine how to leverage cloud-provider services and address gaps with other tools, software, or third-party services
  • Assess system security controls, validate implementation, and identify weaknesses
  • Perform continuous monitoring using security solutions and tools
  • Conduct security impact assessments for proposed environmental changes
  • Identify innovative ways to automate security management, monitoring, and related processes to reduce risk and costs

Requirements:

  • Must be able to obtain a Public Trust
  • Kubernetes and understanding traffic patterns for a high-traffic website running a Content Management System preferred
  • Knowledge of Amazon web infrastructure and services including Route53, CloudFormation, OpenSearch, Kinesis Firehose, Config, EKS, WAF, CloudFront, EC2 & EBS, RDS, ALB, Certificate Manager, S3, Secrets Manager, Virtual Private Cloud, Lambda, Inspector, Key Management Service, ElasticCache, SES, CloudShell, ECR, CloudWatch, SNS, GuardDuty, and CloudTrail
  • Experience managing and deploying pipeline solutions and containerized applications using tools such as Argo Workflows, ArgoCD, GitHub Actions, GitLab CI, Azure DevOps, Jenkins, and Bitbucket Pipelines
  • Experience building and supporting Infrastructure as Code using tools such as AWS CDK, ACK, CloudFormation, Terraform, Pulumi, Ansible, Salt, and Chef
  • Proven knowledge of PowerShell and ability to build and understand logical scripts
  • Deep understanding of IaaS, PaaS, and serverless services and how to combine them into complex solutions
  • Ability to research, analyze, design, propose, and support solutions aligned with business and technology strategies
  • Ability to design data, system, and component architectures and communicate them in simple language to executive leadership
  • Experience with Agile methodologies, especially TDD and Scrum; Kanban is a plus
  • Experience with LEMP and LAMP stacks, WordPress installation and configuration, MySQL performance and scaling, ElasticPress, Elasticsearch, ELK stack, Git, and Bitbucket
  • Knowledge of DevOps lifecycle and process improvement strategies
  • Knowledge of Change and Configuration Management best practices
  • BS in computer science, information systems, cybersecurity, or related IT or security field
  • 5 years of professional experience in IT/network engineering, cloud, security engineering, system administration, or security operations
  • 7 years of experience in a security-related role with FISMA, FedRAMP, and NIST SP 800-53
  • Ability to communicate contributions involving application controls, technical leads, security findings, Common Vulnerability Reports, Security Impact Assessments, and Authorization-To-Operate support
  • Strong analytical skills and solid verbal and written communication skills
  • Experience with Okta and/or Keycloak application integrations
  • Experience with networking for web applications on AWS, Route53, and Certificate Manager
  • Experience managing OpenSearch or Elasticsearch, including instance provisioning, dashboard design for public-traffic WAF data via Kinesis Firehose, and WordPress web search capability
  • AWS, CISSP, CISM, CISA, CEH, CCSK, CCSP, or related security certifications are nice to have
  • Experience with vulnerability management, incident detection, event/audit collection and analysis, and network and web application firewalls
  • Relevant bachelor's degree or similar experience
  • Experience with Section 508 compliance and user experience
  • Experience with federal government system Certification and Accreditation for FISMA compliance with NIST 800-37
  • Experience with Security Test and Evaluation of federal government systems
  • FITSP Certification or equivalent
  • Knowledge of FISMA, OMB Circular A-130, and NIST
  • Must be able to work remotely and support occasional infrequent production troubleshooting outside 9-to-5 hours

Benefits:

  • Medical, dental, and vision insurance
  • 401(k) retirement plan
  • Paid time off
  • Paid parental leave
  • Life and disability insurance
  • Flexible spending accounts
  • Commuter benefits
  • Tuition reimbursement
  • Remote work