Cloud Engineer - FedRAMP

Coalfire Systems, Inc.
United States
19 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$89,000.0 - $149,000.0
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services Microsoft Azure Cloud Computing Security Cloud Engineering Continuous Integration Identity and Access Management JSON Python (Programming Language) Ansible Phishing Security Information and Event Management Software Vulnerability Management
+5 more
Data Logging Cloud Platform System Information Technology CIS Benchmarks Terraform

Job description

Under FedRAMP, compliance is no longer a document-it’s a set of Key Security Indicators (KSIs): measurable security outcomes validated through automation, continuously. Coalfire organizes its delivery engineering into capability-focused teams, each owning a set of KSI domains such as identity and access management, monitoring and logging, change management, or incident recovery. We’re looking for a Cloud Engineer to go deep on a team’s domains-building the standard implementation once, making it deployable anywhere, and landing it in client environment after client environment, getting better every time. If you’re driven by a desire to innovate, excel at operational excellence, and thrive in a collaborative environment, come be part of a team committed to making the world a safer place., * Design and implement the security capabilities that satisfy FedRAMP’s Key Security Indicators (KSIs) within your team’s specialty domains.

  • Build the Security Decision Record (SDR) automation that deploys those capabilities repeatably across many client environments-infrastructure-as-code, pipelines, and configuration baselines, not one-off builds.

  • Develop automated validation and continuous-monitoring evidence for each capability, so the certified state is provable every day.

  • Deploy into client environments as the subject-matter expert for your domain: land the capability, integrate it with the client’s stack, troubleshoot, and harden.

  • Bring lessons from every deployment back to your team, improving the standard implementation for the next client.

  • Mentor junior team members by reviewing their work, sharing best practices, and guiding them through troubleshooting and operational standards.

  • Contribute to documentation, runbooks, and machine-readable compliance artifacts.

  • Support both new FedRAMP environment builds and the modernization of existing ones.

  • Author and peer review detailed design and security documentation, inclusive of vendor best practices.

Requirements

  • BS or above in a related Information Technology field or equivalent combination of education and experience

  • 5+ years in cloud, security, or platform engineering

  • 5+ years supporting cloud architecture, design, implementation, operations, and automation in AWS, Azure, or GCP

  • Experience with Infrastructure-as-Code and orchestration/automation tools such as Terraform and Ansible

  • Automation-first mindset with strong Infrastructure-as-Code (Terraform or equivalent), CI/CD, and scripting (Python, Go, or similar); exposure to policy-as-code

  • Hands-on depth with at least one major cloud platform (AWS, Azure, or GCP) and its native services

  • Working knowledge of NIST 800-53, FedRAMP, or comparable security control frameworks

  • The instinct to solve a problem once, properly, and package the solution so it works everywhere

  • Excellent communication, organizational, and problem-solving skills

  • Effective documentation skills, including technical diagrams and written descriptions

  • Ability to work independently and as part of a team with a professional attitude and demeanor

  • Critical thinking, and the ability to balance security requirements with mission needs

REQUIRED CERTIFICATIONS:

  • Associate-level (or higher) certification in AWS, Azure, or GCP

Bonus Points

  • Direct familiarity with FedRAMP 20x and Key Security Indicators (KSIs)

  • Experience with OSCAL or JSON machine-readable compliance formats

  • Depth in a likely specialty area: identity (SSO, phishing-resistant MFA), SIEM and log pipelines, vulnerability management, or resilience engineering

  • Relevant certifications such as cloud security specialty certifications, CISSP, or GIAC

  • Previous experience supporting clients from within a professional services organization

  • Familiarity with configuration baseline standards such as CIS Benchmarks & DISA STIG

  • Familiarity with frameworks such as FedRAMP, FISMA, HIPAA, HITRUST, or PC

Benefits & conditions

3.63.6 out of 5 stars Remote $89,000 - $149,000 a year - Full-time, Pulled from the full job description

  • Paid parental leave
  • Parental leave, The salary range listed is a reasonable estimate of the compensation range for this role based on national salary averages. The actual salary offer to the successful candidate will be based on job-related education, geographic location, training, licensure and certifications and other factors. You may also be eligible to participate in annual incentive, commission, and/or recognition programs. Why You’ll Want to Join Us At Coalfire, you’ll find the support you need to thrive personally and professionally. In many cases, we provide a flexible work model that empowers you to choose when and where you’ll work most effectively - whether you’re at home or an office. Regardless of location, you’ll experience a company that prioritizes connection and wellbeing and be part of a team where people care about each other and our communities. You’ll have opportunities to join employee resource groups, participate in in-person and virtual events, and more. And you’ll enjoy competitive perks and benefits to support you and your family, like paid parental leave, flexible time off, certification and training reimbursement, digital mental health and wellbeing support membership, and comprehensive insurance options.

About the company

Coalfire is on a mission to make the world a safer place by solving our clients’ hardest cybersecurity challenges. We work at the cutting edge of technology to advise, assess, automate, and ultimately help companies navigate the ever-changing cybersecurity landscape. We are headquartered in Chicago, Illinois with offices across the U.S. and U.K., and we support clients around the world. But that’s not who we are - that’s just what we do. We are thought leaders, consultants, and cybersecurity experts, but above all else, we are a team of passionate problem-solvers who are hungry to learn, grow, and make a difference.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:47 min

Exploring JSON, CBOR, and JOSE for data serialization

Aaron Russell · LIVE

1:42 min

Automating Skupper deployments using Ansible

Alex Soto Alex Soto · WWC 2024

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa · LIVE

6:13 min

Defining cloud proficiency by technical role

Piet Van Dongen · LIVE

2:03 min

Distinguishing type definition constructs from data validation routines

Clemens Vasters Clemens Vasters · WWC 2025

1:55 min

Executing secure deployments with verified compliance and data residency

Alex Laubscher Alex Laubscher · WWC 2025

Videos

See all

Related articles

See all