> Markdown version of [/jobs/ext/1478214-cloud-security-compliance-engineer](https://www.wearedevelopers.com/jobs/ext/1478214-cloud-security-compliance-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cloud Security & Compliance Engineer - **Company:** DecisionPoint Corporation - **Location:** Reston, VA, United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Cloud Computing Security, CompTIA Security+, Cyber Security, Identity and Access Management, Log Analysis, Cloud Services, Zero Trust Network Access, Security Information and Event Management, Software Vulnerability Management, Policy as Code, Data Logging, SARS Software Products, Cloud Platform System, Information Technology, Devsecops, Plan of Action and Milestones, Vulnerability Analysis - **Published:** July 29, 2026 - **Apply:** https://diversityjobs.com/main/sendform/8/8/28176/1/17736586?backUrl=%2Fcareer%2F17736586%2FCloud-Security-Compliance-Engineer-Virginia-Reston ## About the Role Bachelor's degree in Computer Science, Information Technology, Systems Administration, or a related field. Experience (Required) * Minimum 5 years of experience in cloud security, cybersecurity compliance, or system security engineering. * Experience performing RMF support activities including SSP updates, POA&M management, and continuous monitoring. * Experience validating compliance against STIGs, IL5 configurations, and federal security controls. * Experience troubleshooting cloud security issues in AWS or secure federal environments. Technical Knowledge (Required) * Familiarity with AWS GovCloud IL5 security controls, logging, monitoring, and IAM best practices. * Knowledge of RMF processes, STIG requirements, and federal cybersecurity frameworks. * Understanding of encryption, auditing, IAM, and boundary defense in cloud environments. * Familiarity with vulnerability scanning, remediation workflows, and compliance validation. Technical Knowledge (Preferred) * Experience with automation for compliance validation or policy-as-code. * Experience with SIEM platforms, SOAR tools, or security analytics. * Familiarity with container hardening and cloud-native security architectures. Certifications Required: * CompTIA Security+ or AWS Cloud Practitioner Preferred: * ITIL v4 Foundation * AWS Security Specialty * CISSP, CCSP, or other advanced cybersecurity certifications Skills * Strong analytical and problem-solving abilities for cloud security and compliance issues. * Excellent communication skills for coordination with cybersecurity and engineering teams. * High attention to detail in documentation and RMF artifact maintenance. * Ability to manage multiple tasks and deadlines in a mission-focused environment. * Strong understanding of secure cloud operations and IL5 compliance. ## Description DecisionPoint seeks a Cloud Security & Compliance Engineer to support cybersecurity compliance, RMF alignment, and IL5 cloud security operations for AWS GovCloud environments supporting a large federal and DoD-aligned mission environment. This role performs impact analysis, updates RMF documentation, maintains STIG compliance, validates security configurations, and ensures IL5 cybersecurity continuity throughout migration and modernization activities. The Cloud Security & Compliance Engineer works closely with cloud architects, ISSM/ISSO teams, cybersecurity analysts, DevSecOps engineers, and system administrators to maintain a secure, compliant, and continuously monitored cloud ecosystem. This position is fully remote., The Cloud Security & Compliance Engineer will: Perform RMF impact analysis for system changes affecting cloud security posture. * Update and maintain RMF documentation including SSPs, POA&Ms, SARs, and control evidence. * Ensure STIG compliance for cloud services, operating systems, containers, and supporting components. * Validate encryption configurations, IAM changes, auditing controls, and logging requirements. * Support continuous monitoring, vulnerability management, and remediation tracking. * Assist with IL5 migration security validation, ensuring no degradation of compliance during transitions. * Review configuration baselines, IaC templates, and cloud security policies for alignment with RMF and Zero Trust. * Conduct log analysis and correlate findings with SIEM outputs for compliance and incident follow-up. * Support COOP/DR planning from a security controls perspective, ensuring continuity of protections. * Assist ISSM and ISSO teams during audits, assessments, and ATO-related activities. * Document security findings, remediation steps, and compliance reports for leadership review. * Participate in Change Control Board (CCB) meetings to evaluate security impacts of proposed updates. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Progressive Delivery in Kubernetes](https://www.wearedevelopers.com/videos/949-progressive-delivery-in-kubernetes) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Logs in observability - Correlation](https://www.wearedevelopers.com/videos/1430-logs-in-observability-correlation) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 162: AI careers, MCP, AWS best practices & floppy sweaters](https://www.wearedevelopers.com/magazine/571-dev-digest-162-ai-careers-mcp-aws-best-practices-floppy-sweaters) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers)