Cloud Security Engineer
Role details
Job location
Tech stack
Job description
We are seeking a Cloud Security Engineer to join a dynamic security team. This role is integral to a modern, agile software development environment. The engineer will serve as an information security specialist, responsible for reviewing software and infrastructure changes, following the risk management framework process for system accreditation, and contributing to the development of new cyber monitoring and response plans., * Review audit logs and create mitigation and corrective action plans.
- Utilize forensic tools for attack reconstruction and to determine how to correct vulnerabilities.
- Work with development teams to create, maintain, and monitor data connections, security certificates, and firewall connection requests.
- Implement and improve the DevSecOps process within a Linux and cloud-based development environment.
- Architect security infrastructure as needed to protect against cyber attacks.
- Participate in the design and implementation of information systems to ensure compliance with security features.
- Conduct security planning, assessment, risk analysis, and risk management for system and networking operations.
- Evaluate scan results and work with developers and administrators to mitigate findings.
- Generate certification and accreditation (C&A) documentation and artifacts for import into the designated tool.
- Coordinate with Security Control Assessors (SCAs) during the engineering design phase.
Requirements
Education/Certifications: Bachelor's degree in information systems, systems engineering, electrical engineering, information technology, or a related field. Active IAT III certification (CompTIA Security+, etc.)
Experience: 3+ years of relevant experience, or 5+ years of experience without a related degree. Must have an understanding of engineering in development and operational environments.
Clearance: Candidates must be able to obtain and/or maintain a Department of Defense Top Secret/SCI with CI Poly as a condition and continuation of employment (clearance sponsorship not offered at this time)
Technical Skills:
- Experience with IAT II certification requirements.
- Proficiency in navigating Linux systems and understanding accreditation processes.
- Experience writing security controls and documenting processes.
- Knowledge of tools such as Trellix (formerly McAfee), RMF frameworks, and ServiceNow.
- Understanding of IA principles and DOD/IC system security control requirements.
- Familiarity with IT security technologies such as firewalls, encryption, and proxies.
Preferred Qualifications
- Previous military experience is considered beneficial for this role.