Engagement Architect - Cloud Architecture (FedRAMP)

Coalfire Systems, Inc.
United States
19 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$89,000.0 - $149,000.0
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services Microsoft Azure Cloud Computing Cloud Engineering Digital Architecture Identity and Access Management JSON Data Logging Cloud Platform System Information Technology CIS Benchmarks

Job description

Coalfire builds and operates FedRAMP-compliant cloud environments for software companies entering the federal market. We’re looking for an Engagement Architect to serve as the technical owner of a client engagement-taking a signed contract and carrying it through architecture build, security control implementation, and a verified transition into managed operations. You’ll own active engagements: deep enough to be accountable for every technical outcome, focused enough to do it well. If you’re driven by a desire to innovate, excel at operational excellence, and thrive in a collaborative environment, come be part of a team committed to making the world a safer place., * Own client engagements end-to-end: from contract signature through environment build, control implementation, automated evidence pipelines, and handoff to managed operations.

  • Instantiate Coalfire’s reference architecture for the contracted certification level and cloud platform, adapting it to the client’s application and boundary.
  • Lead implementation of security controls and the automation that continuously validates them-the evidence a modern FedRAMP certification runs on.
  • Coordinate Coalfire’s engineering teams as they deploy their capabilities (identity, monitoring, change management, and more) into your engagement.
  • Drive the build through defined quality gates, with a clean, measurable transition to operations-every in-scope control implemented, validated, and stable.
  • Serve as the client’s primary technical counterpart: run technical working sessions, manage milestones and risks, and keep scope honest.
  • Document architecture decisions and feed lessons from each build back into Coalfire’s standards.

Requirements

  • BS or above in a related Information Technology field or equivalent combination of education and experience

  • 8+ years in cloud engineering or architecture, including 3+ years leading technical delivery for external clients

  • Experience leading FedRAMP builds or authorizations-or equivalent depth in another regulated cloud regime (DoD impact levels, StateRAMP, PCI, HIPAA)

  • Hands-on skill across infrastructure-as-code, identity and access management, logging and monitoring, and cloud networking on at least one major cloud platform (AWS, Azure, or GCP)

  • Strong client-facing communication-able to explain an architecture decision to an engineer, a project sponsor, or an assessor

  • Sound judgment about scope, risk, and when to escalate

  • Excellent organizational and problem-solving skills

  • Effective documentation skills, including technical diagrams and written descriptions

  • Ability to work independently and as part of a team with a professional attitude and demeanor

  • Critical thinking, and the ability to balance security requirements with mission needs

REQUIRED CERTIFICATIONS:

  • Professional-level certification in AWS, Azure, or GCP

Bonus Points:

  • Familiarity with FedRAMP 20x, Key Security Indicators (KSIs), and machine-readable compliance artifacts (OSCAL or JSON)

  • Experience with productized or fixed-price delivery models

  • Relevant certifications such as cloud platform professional/security certifications or CISSP

  • Familiarity with configuration baseline standards such as CIS Benchmarks & DISA STIG

  • Familiarity with frameworks such as FedRAMP, FISMA, HIPAA, HITRUST, or PCI

Benefits & conditions

3.63.6 out of 5 stars Remote $89,000 - $149,000 a year - Full-time, Pulled from the full job description

  • Paid parental leave
  • Parental leave, The salary range listed is a reasonable estimate of the compensation range for this role based on national salary averages. The actual salary offer to the successful candidate will be based on job-related education, geographic location, training, licensure and certifications and other factors. You may also be eligible to participate in annual incentive, commission, and/or recognition programs. Why You’ll Want to Join Us At Coalfire, you’ll find the support you need to thrive personally and professionally. In many cases, we provide a flexible work model that empowers you to choose when and where you’ll work most effectively - whether you’re at home or an office. Regardless of location, you’ll experience a company that prioritizes connection and wellbeing and be part of a team where people care about each other and our communities. You’ll have opportunities to join employee resource groups, participate in in-person and virtual events, and more. And you’ll enjoy competitive perks and benefits to support you and your family, like paid parental leave, flexible time off, certification and training reimbursement, digital mental health and wellbeing support membership, and comprehensive insurance options.

About the company

Coalfire is on a mission to make the world a safer place by solving our clients’ hardest cybersecurity challenges. We work at the cutting edge of technology to advise, assess, automate, and ultimately help companies navigate the ever-changing cybersecurity landscape. We are headquartered in Chicago, Illinois with offices across the U.S. and U.K., and we support clients around the world. But that’s not who we are - that’s just what we do. We are thought leaders, consultants, and cybersecurity experts, but above all else, we are a team of passionate problem-solvers who are hungry to learn, grow, and make a difference.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:55 min

Executing secure deployments with verified compliance and data residency

Alex Laubscher Alex Laubscher · WWC 2025

2:15 min

Auditing container configurations against CIS benchmark security standards

Madhu Akula · LIVE

1:10 min

Exposing sensitive information through partial search logs

Dennis Schulz Dennis Schulz +1 · WWC Europe 2026

3:47 min

Exploring JSON, CBOR, and JOSE for data serialization

Aaron Russell · LIVE

3:39 min

Validating data queries and infrastructure security configurations

Philipp Krenn · WWC 2023

1:56 min

Discovering incidents using logs, metrics, and traces

Nele Uhlemann · WWC 2023

Videos

See all

Related articles

See all