Cloud Security Engineer
Role details
Job location
Tech stack
Job description
We are looking for a Cloud Security Engineer to enhance our cloud security posture across various platforms, including Azure and enterprise SaaS solutions. This role requires expertise in implementing security controls, evaluating risks, and ensuring compliance with data protection regulations. The ideal candidate will have a strong understanding of secure cloud architectures and a passion for staying current with emerging trends in cloud security. You will collaborate with cross-functional teams to promote secure development practices and contribute to the continuous improvement of our security capabilities, ensuring the protection of our cloud environments and data assets., Hybrid weekly work schedule in Lynchburg, Virginia
Your Day to Day as a Cloud Security Engineer:
-
Implement and audit cloud security controls to protect workloads across Azure and other IaaS/PaaS environments.
-
Evaluate and secure SaaS and application platforms including Microsoft 365, enterprise SaaS solutions, containerized workloads, and DevOps pipelines.
-
Support data protection and governance initiatives through configuration and operational use of Microsoft Purview (eDiscovery, Insider Risk, DLP).
-
Conduct security reviews and risk assessments for cloud services, applications, and third-party integrations prior to deployment.
-
Collaborate with architecture and development teams to embed secure-by-design practices into cloud architectures and processes.
-
Monitor and assess cloud security posture using native and enterprise tools to identify misconfigurations, vulnerabilities, and improvement opportunities.
-
Support supply chain and third-party risk management by evaluating vendor security practices and integration risks.
-
Contribute to continuous improvement efforts by identifying process gaps, recommending enhancements, and helping mature cloud and on-premises security capabilities.
-
Develop and maintain technical documentation for cyber security configurations, standards, and operational procedures.
-
Stay current with emerging cloud security trends, technologies, and best practices relevant to enterprise environments.
Requirements
-
Bachelor's degree in Cybersecurity, IT, or related field. Equivalent experience may be considered.
-
At least 5 years of relevant experience.
-
Hands-on experience securing cloud environments across Azure, AWS, or GCP, including identity, networking, storage, and workload protections.
-
Experience with application and SaaS security including Microsoft 365, enterprise SaaS platforms, and containerized applications.
-
Proficiency with Windows and Linux environments and their security hardening practices.
-
Familiarity with data protection and governance tools such as Microsoft Purview (DLP, Insider Risk, eDiscovery).
-
Understanding of DevOps and CI/CD security practices including code scanning, pipeline security, and secrets management.
-
Knowledge of cloud security frameworks such as CIS Benchmarks, NIST CSF, or equivalent industry standards.
-
Demonstrate a strong commitment to confidentiality in handling sensitive information.
-
Strong communication and documentation skills with the ability to translate technical concepts for diverse audiences.
-
Ability to work collaboratively across teams and contribute to a positive, security-focused culture.
-
U.S. citizenship.
-
Ability to obtain and maintain a Department of Energy (DOE) security clearance.
Preferred Additional Qualifications:
-
Experience supporting third-party and supply chain risk assessments for cloud and SaaS vendors.
-
One or more of the following certifications: AWS-SCS, AZ-500, GCP-PCSE, CISSP, CCSP, GCLD, Cloud+, or equivalent.
Benefits & conditions
-
Competitive salary and benefits package, including health, dental, and retirement plans.
-
Flexible work schedules and paid time off to promote a healthy work-life balance.
-
Professional development opportunities, including mentorship programs and sponsorship for continuing education.
-
An inclusive atmosphere that celebrates new perspectives and supports collaboration between different generations.
-
The chance to be part of a mission-driven organization making a positive impact on the future of energy.
-
Opportunities for continuous learning and training to grow throughout your career!
#LI-DA1
Pay: $[[cust_salaryMin]] - $[[cust_salaryMax]]
The base salary range for this position in [[stateProvince]] at the start of employment is expected to be between $[[cust_salaryMin]] and $[[cust_salaryMax]] per year. However, the base salary offered is based on local job market factors, and may vary further depending on factors specific to the selected job candidate, such as job-related knowledge, skills, experience, and other objective business considerations. Subject to these considerations, the total compensation package for this position may also include other elements, such as an annual cash incentive in addition to a full range of medical, retirement, and/or other benefits. Details of participation in these benefit plans will be provided at such time the selected job candidate receives an offer of employment. If hired, the selected job candidate will be employed 'at-will,' unless employed at a location and in a position subject to a collective bargaining agreement. The company further reserves the right to modify base salary (as well as any other discretionary payment, compensation or benefit program) at any time, including for reasons related to individual performance, company or individual department/team performance, and other market factors.
As a federal government contractor, BWX Technologies, Inc. and any subsidiaries, affiliates and related entities ("BWXT" or the "Company") complies with all federal, state, and local laws and customer requirements regarding health and safety protocols. As such, all BWXT new hires will be required to adhere to applicable Company health and safety requirements within the workplace as a condition of employment.