Senior Cloud Infrastructure Consultant (Active TS/SCI)

Cg Infinity, Inc.
Chantilly, United States of America
16 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Senior

Job location

Chantilly, United States of America

Tech stack

Amazon Web Services (AWS)
Audit Trail
Cloud Computing
Cloud Computing Security
Continuous Integration
DNS
Identity and Access Management
IP Routing
Subnetting
Python
Powershell
Security Information and Event Management
Data Logging
Scripting (Bash/Python/Go/Ruby)
Cloud Platform System
Delivery Pipeline
Amazon Web Services (AWS)
Cloudformation
Gitlab-ci
Information Technology
Hashicorp
Route53
Cloudwatch
Terraform
Virtual Private Clouds
Jenkins

Job description

CG Infinity is expanding our AWS Professional Services delivery team to support a high-priority national-security program. As a Senior Cloud Infrastructure Consultant, you will design and stand up secure, multi-account AWS Landing Zones in air-gapped and classified regions that serve as the foundational platform for downstream mission applications. You will partner directly with AWS Professional Services architects and government technical leads, owning architecture decisions across networking, identity, security, and automation., * Design and deploy AWS Landing Zones in air-gapped, classified regions, including AWS Control Tower equivalents and account-vending automation.

  • Architect multi-account AWS organizations with appropriate Organizational Unit (OU) structure, Service Control Policies (SCPs), and tag governance.
  • Build and maintain Infrastructure-as-Code modules in Terraform (and AWS CloudFormation where required) for repeatable, auditable deployments.
  • Configure VPCs, subnets, route tables, Transit Gateways, VPC endpoints, DNS (Route 53 / hybrid resolvers), and private connectivity to on-premises enclaves.
  • Implement IAM policies, permission boundaries, role federation, and break-glass procedures aligned to least-privilege principles.
  • Stand up centralized logging, audit, and monitoring (CloudTrail, Config, GuardDuty, Security Hub, CloudWatch) and integrate with the customer's SIEM.
  • Integrate the cloud platform with enterprise identity (e.g., Identity, Credential, and Access Management (ICAM); Personal Identity Verification (PIV); Common Access Card (CAC)) and compliance tooling.
  • Collaborate with AWS Professional Services, mission application teams, and the customer's Risk Management Framework (RMF) / Authority to Operate (ATO) authorizing officials.
  • Produce architecture diagrams, runbooks, and design decision records suitable for ATO body-of-evidence packages.

Requirements

Do you have experience in Virtual Private Clouds?, Do you have a Bachelor's degree?, * U.S. Citizenship and active Top Secret / SCI clearance.

  • Five (5) or more years of hands-on AWS engineering experience, including building environments from inception (greenfield).
  • Demonstrated experience designing multi-account AWS architectures and AWS Landing Zone patterns.
  • Advanced AWS networking knowledge: VPC design, Transit Gateway, PrivateLink, hybrid DNS, and on-premises connectivity patterns.
  • Proficiency with Infrastructure-as-Code, specifically Terraform and/or AWS CloudFormation, including module design and state management.
  • Experience implementing AWS security controls, IAM at scale, KMS, audit logging, and resource-based policies.
  • Familiarity working in classified or highly regulated environments and producing artifacts suitable for compliance review.
  • Bachelor's degree in Computer Science, Engineering, or a related discipline - or equivalent professional experience.
  • Clear written and verbal communication skills for technical documentation, stakeholder coordination, and customer-facing delivery., * Prior delivery experience in AWS GovCloud (US), AWS Secret Region / AWS Secret-West, or AWS Top Secret-East/West.
  • Working knowledge of DISA STIGs, NIST SP 800-53 / 800-171, and the DoD Cloud Computing Security Requirements Guide (SRG).
  • Direct experience supporting Risk Management Framework (RMF) / Authority to Operate (ATO) packages (SSP, control implementation, POA&M).
  • Experience with CI/CD for infrastructure (GitLab CI, Jenkins, AWS CodePipeline).
  • Scripting in Python or PowerShell for automation and integration tasks.

PREFERRED CERTIFICATIONS

  • AWS Certified Solutions Architect - Professional
  • AWS Certified Advanced Networking - Specialty
  • AWS Certified Security - Specialty
  • HashiCorp Certified: Terraform Associate
  • HashiCorp Certified: Terraform Authoring & Operations Professional

About the company

CG Infinity, Inc. is a software consulting firm that was founded in 1998. We offer solutions that are tailored to the needs of each individual client that we work with instead of offering standard, run-of-the-mill solutions to everyone. We work closely with our clients throughout the entire process and offer solutions for a myriad of challenges. CG Infinity has offices in Plano, TX, Houston, TX, Little Rock, AR, and Albuquerque, NM.

Apply for this position