> Markdown version of [/jobs/ext/145343-cloud-security-engineer](https://www.wearedevelopers.com/jobs/ext/145343-cloud-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cloud Security Engineer - **Company:** Fedpoint LLC - **Location:** Portsmouth, NH, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Microsoft Azure, Cloud Computing Security, Cloud Engineering, Cyber Security, Continuous Integration, Github, Identity and Access Management, Intrusion Detection and Prevention, Log Analysis, Security Software, Security Information and Event Management, Software Vulnerability Management, Amazon Virtual Private Cloud (VPC), Cloudformation, Infrastructure Automation Frameworks, Data Analytics, Terraform, Devsecops - **Published:** May 19, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=75929dc2f62c2821 ## About the Role * 5+ years of experience in cloud security, cybersecurity, or related field * Strong experience working in AWS environments, including hands-on use of tools such as GuardDuty, Security Hub, Inspector, Detective, and IAM * Experience supporting regulatory frameworks such as FedRAMP, FISMA, NIST, HIPAA, ISO, or similar * Background working in 24x7 operational environments * Experience with DevSecOps, CI/CD pipelines, and automated security tooling Technical Skills * Deep expertise in AWS security architecture and services * Strong understanding of IAM, Infrastructure as Code, and cloud-native security controls * Experience with Terraform, GitHub, and CI/CD pipeline security integration * Knowledge of threat modeling and cloud risk assessments * Familiarity with MFA, conditional access, and identity risk policies Certifications (At least one preferred) * AWS Certified Security - Specialty * Certified Cloud Security Professional (CCSP) * CISSP or equivalent cloud/security certification, * Strong analytical and problem-solving skills * Ability to translate complex security risks into actionable solutions * Excellent communication skills with both technical and non-technical stakeholders * High attention to detail and strong organizational skills * Self-starter who thrives both independently and in a collaborative team environment ## Description We are seeking a Cloud Security Engineer who is passionate about building secure, scalable cloud environments and reducing risk through a proactive, data-driven approach. In this role, you will help shape and strengthen cloud security across AWS and Azure environments while supporting compliance with federal and industry regulations. You will collaborate closely with engineering, infrastructure, and business teams to design, implement, and continuously improve cloud security controls, monitoring, and incident response capabilities., * Analyze cloud security risks, technologies, and requirements to ensure adherence to best practices and regulatory standards * Partner with cloud engineering teams to define and implement security baselines and guardrails * Architect and implement security controls for AWS-hosted applications and Azure multi-tenant environments * Design and maintain secure infrastructure using Infrastructure as Code (Terraform, CloudFormation) * Strengthen DevSecOps practices by integrating security into CI/CD pipelines (GitHub Actions) * Lead cloud security monitoring strategy, including metrics, tooling, and reporting * Develop and maintain cloud security incident response playbooks * Collaborate cross-functionally to design and optimize cloud security processes and controls * Support compliance tracking and reporting for external agencies and customers Incident Response * Lead cloud security incident investigations and response efforts * Enhance automated threat detection and response capabilities * Analyze logs and alerts across cloud environments (CloudTrail, VPC flow logs, firewalls, SIEM tools) * Participate in Security Incident Response Team activities and vulnerability management efforts * Serve as an on-call cloud security contact and escalation point * Provide guidance to IT and business teams on incident response and remediation Continuous Improvement * Drive ongoing enhancements to cloud security processes and controls * Incorporate feedback from stakeholders to improve security effectiveness, The Information Security & Risk Management team provides leadership in protecting the organization's information assets and ensuring compliance with federal and state regulations. The team drives enterprise-wide security strategy, risk management, incident response, and continuous improvement to maintain secure and resilient operations. ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)