> Markdown version of [/jobs/ext/1452772-cloud-automation-engineer-security-focused-in-arlington](https://www.wearedevelopers.com/jobs/ext/1452772-cloud-automation-engineer-security-focused-in-arlington). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cloud / Automation Engineer (Security-Focused) in Arlington - **Company:** Energy Jobline - **Location:** Arlington, VA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Amazon Web Services, Amazon Elastic Compute Cloud, Amazon S3, Bash Shell, Cloud Computing, Cloud Computing Security, Cloud Engineering, Computer Networks, Continuous Integration, DevOps, Identity and Access Management, Information Systems Security Architecture Professional, Python (Programming Language), Key Management, Network Security, OpenShift, Role-Based Access Control, Ansible, Security Information and Event Management, Datadog, Policy as Code, Scripting, Cloud Platform System, Software Security, Amazon Virtual Private Cloud (VPC), Gitlab, SC Clearance, Containerization, Gitlab-ci, Kubernetes, Infrastructure Automation Frameworks, Hardware Infrastructure, CIS Benchmarks, Cloudwatch, Terraform, Splunk, Security Orchestration, Automation & Response, Jenkins, Vulnerability Analysis - **Published:** July 26, 2026 - **Apply:** https://www.energyjobline.com/job/cloud-automation-engineer-security-focused-arlington-31251134 ## About the Role * Active Secret Clearance * 5+ years of hands-on experience in Cloud Engineering, DevOps, or Cloud Security * Strong experience securing AWS environments (IAM, VPC, EC2/EKS, S3, CloudTrail, GuardDuty) * Hands-on Kubernetes/EKS security experience (RBAC, PSP/PSS, network policies, admission controllers) * Strong CI/CD pipeline security experience (GitLab CI, Jenkins) * Proficiency with Terraform and/or Ansible, including secure IaC patterns * Experience with container security, image scanning, and runtime protection * Strong troubleshooting skills for security failures across cloud, CI/CD, IaC, and Kubernetes * Scripting experience (Python, Bash, or similar), * Experience with OpenShift security controls * Experience with compliance frameworks (FedRAMP, NIST 800-53, CIS Benchmarks) * Experience with policy-as-code (OPA, Sentinel, Checkov) * Experience with SIEM tools (Splunk, ELK, Datadog) * AWS Security or Solutions Architect certification * CKA or similar Kubernetes certification ## Description We are seeking a Cloud/Automation Engineer with deep, hands-on security engineering experience across AWS, Kubernetes/EKS, CI/CD pipelines, and Infrastructure-as-Code. This role is ideal for engineers who can own cloud security end-to-end, not just implement controls. You will design secure architectures, troubleshoot complex security failures, and ensure our cloud and on-prem DevOps platforms meet strict compliance and audit requirements. You will work across cloud and on-prem environments, supporting CI/CD automation, infrastructure provisioning, container platforms, and security automation. This position requires strong technical depth, especially in pipeline security, IAM architecture, Kubernetes/EKS security, and IaC security., Cloud & Platform Security (Primary Focus) * Architect and enforce secure AWS cloud environments, including IAM policy design, permission boundaries, workload hardening, encryption standards, and secure networking. * Own security posture for EKS and OpenShift clusters, including RBAC, Pod Security Standards, network policies, admission controllers, secrets management, and runtime security. * Implement and maintain automated security monitoring using CloudTrail, CloudWatch, GuardDuty, Security Hub, and SIEM integrations. * Troubleshoot complex cloud security issues such as IAM failures, denied resource creation, broken trust relationships, and misconfigured policies. CI/CD Pipeline Security * Build and secure CI/CD pipelines (GitLab, Jenkins) with hardened runners, least-privilege IAM roles, encrypted secrets, artifact signing, SBOM , and vulnerability scanning. * Diagnose and resolve pipeline security failures including secret injection errors, policy violations, and container image security issues. * Ensure pipelines meet compliance requirements (CIS, NIST 800-53, FedRAMP) through automated checks and policy-as-code enforcement. Infrastructure-as-Code Security * Develop secure Terraform and Ansible modules with encrypted state, IAM provisioning, compliance guardrails, and automated drift detection. * Implement policy-as-code frameworks (OPA, Sentinel, Checkov) to enforce security baselines across cloud and on-prem infrastructure. * Troubleshoot IaC security failures and implement durable fixes. Security Automation & Compliance * Build automated workflows for vulnerability scanning, secrets rotation, compliance validation, and configuration drift detection. * Support audit readiness by documenting security controls, remediation steps, and root-cause analyses. * Ensure all cloud and on-prem environments adhere to FedRAMP, NIST 800-53, and enterprise security standards. DevOps & Platform Engineering * Support containerized workload deployments on EKS and OpenShift. * Build and maintain CI/CD pipelines and automation across cloud and on-prem environments. * Participate in cross-team DevOps initiatives, knowledge sharing, and platform improvements. * Troubleshoot deployment failures, monitoring gaps, and security automation issues across all supported platforms. ## Related Videos - [WeAreDevelopers LIVE - Modern DevOps for IoT Devices and More](https://www.wearedevelopers.com/videos/1805-wearedevelopers-live-modern-devops-for-iot-devices-and-more) - [Kubernetes Security Best Practices](https://www.wearedevelopers.com/videos/1411-kubernetes-security-best-practices) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [Securing Secrets in the GitOps era](https://www.wearedevelopers.com/videos/546-securing-secrets-in-the-gitops-era) ## Related Articles - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline)