> Markdown version of [/jobs/ext/1711497-aws-cloud-security-engineer-with-cnapp](https://www.wearedevelopers.com/jobs/ext/1711497-aws-cloud-security-engineer-with-cnapp). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # AWS Cloud Security Engineer with CNAPP - **Company:** General Dynamics Information Technology - **Location:** United States (Remote available) - **Experience:** Experienced - **Salary:** $149,469.0 - $195,500.0 - **Contract:** Permanent contract - **Skills:** Adobe Analytics, Kubernetes Security, Agile Methodology, Amazon Web Services, Software Applications, Cloud Computing, Cloud Computing Security, Cloud Engineering, Cyber Security, Information Systems, Intrusion Detection and Prevention, Network Segmentation, Cloud Services, Zero Trust Network Access, Security Information and Event Management, Software Vulnerability Management, Data Logging, Enterprise Software Applications, HybridCloud, Containerization, CIS Benchmarks, Splunk, New Relic (SaaS), Plan of Action and Milestones, Vulnerability Analysis - **Published:** July 19, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=622f4934b83c7bed ## About the Role Required Education & Experience: Technical Training, Certification(s) or Degree and 10+ years of general experience in information systems required Preferred Education & Experience: Additional education and/or experience are strongly preferred in the following combinations: * HS Diploma & 16+ Years Experience * AA/AS & 14+ Years Experience * BA/BS & 12+ years Experience * MA/MS & 10+ Years Experience * Doctorate Degree/Ph.D. & 9+ Years Experience (may subtract 1 year from required experience with Doctorate Degree), * 7+ years of cybersecurity experience with at least 4+ years focused on AWS cloud security and CNAPP technologies. * Hands-on experience implementing and operating Wiz and AWS-native CNAPP/security services in enterprise cloud environments. * Strong experience with CSPM, CIEM, workload protection, runtime security, vulnerability management, cloud compliance monitoring, and cloud attack-path analysis. * Strong understanding of Zero Trust Architecture (ZTA), FedRAMP High, NIST 800-53, FISMA, CIS Benchmarks, and cloud security best practices. * Experience supporting vulnerability remediation, incident response, compliance assessments, and continuous monitoring activities in regulated cloud environments. * Ability to support after-hours vulnerability scanning, incident response, and critical security remediation activities as required. Preferred Certifications: * AWS Certified Security - Specialty * Certified Kubernetes Security Specialist * AWS Certified Solutions Architect - Professional Security Clearance Level: Ability to pass a background check to obtain and maintain a position of Public Trust with the Administrative Office of the US Courts Must be a US Person (Green Card Holder, US Permanent Resident Alien, Refugee, Asylee, US Citizen), 10 + years of related experience * may vary based on technical training, certification(s), or degree Certification AWS Certified Security - Specialty | Amazon Web Services (AWS) - Amazon Web Services (AWS) Certified Kubernetes Security Specialist (CKS) | Cloud Native Computing Foundation (CNCF) - Cloud Native Computing Foundation (CNCF) AWS Certified Solutions Architect - Professional | Amazon Web Services (AWS) - Amazon Web Services (AWS) Travel Required Less than 10% ## Description The AWS Cloud Security Engineer will work as part of an agile development team to build and support the modernization of enterprise-class software applications utilizing judiciary frameworks. They will provide advanced technical expertise in securing AWS cloud environments through continuous vulnerability management, Cloud-Native Application Protection Platform (CNAPP) operations, threat detection, compliance monitoring, and cloud security engineering. This role supports enterprise cloud modernization initiatives operating within a FedRAMP High and Zero Trust Architecture (ZTA) environment by implementing and maintaining cloud-native security capabilities across AWS infrastructure, containerized workloads, storage platforms, cloud services, and enterprise applications. Security platforms utilized include Wiz, Splunk, New Relic, IriusRisk, and TestifySec., * Implement, configure, and manage CNAPP capabilities across AWS cloud environments supporting FedRAMP High compliance requirements. * Configure and maintain AWS-native security services. * Implement and monitor Cloud Security Posture Management (CSPM), Cloud Infrastructure Entitlement Management (CIEM), workload protection, runtime security, vulnerability management, attack-path analysis, encryption controls, network segmentation, backup/recovery protections, and continuous compliance monitoring capabilities. * Monitor and analyze Wiz vulnerabilities, Splunk alerts, AWS security findings, SIEM events, runtime alerts, and New Relic dashboards to identify threats, validate remediation efforts, and support continuous cloud security operations and incident response activities. * Implement and validate security baselines, policy enforcement mechanisms, encryption standards, workload isolation controls, secrets protection, secure storage configurations, and least-privilege access controls aligned with Zero Trust principles. * Integrate CNAPP tooling with SIEM, logging, monitoring, alerting, automated remediation, and incident response platforms to support centralized cloud security operations. * Support continuous ATO activities by developing and maintaining SSPs, security implementation procedures, SOPs, mitigation plans, technical runbooks, automated remediation playbooks, audit evidence, POA&M documentation, and operational security documentation supporting FedRAMP, NIST 800-53, FISMA, and Judiciary security requirements. ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [30 powerful AWS hacks in just 30 minutes: Boost your developer productivity](https://www.wearedevelopers.com/videos/1624-30-powerful-aws-hacks-in-just-30-minutes-boost-your-developer-productivity) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Build Delightful Mobile Experiences with Kotlin, Realm, and Atlas Device Sync](https://www.wearedevelopers.com/videos/694-build-delightful-mobile-experiences-with-kotlin-realm-and-atlas-device-sync) - [Logs in observability - Correlation](https://www.wearedevelopers.com/videos/1430-logs-in-observability-correlation) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [Why Attend a Developer Event in 2026?](https://www.wearedevelopers.com/magazine/688-why-attend-a-developer-event-in-2026) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [Best Coding Boot Camps in Germany](https://www.wearedevelopers.com/magazine/237-best-coding-boot-camps-in-germany) - [Dev Digest 162: AI careers, MCP, AWS best practices & floppy sweaters](https://www.wearedevelopers.com/magazine/571-dev-digest-162-ai-careers-mcp-aws-best-practices-floppy-sweaters)