Cloud Infrastructure Engineer - AWS (Active TS/SCI Clearance)

Strategic Business Systems, Inc.
Chantilly, VA, United States
1 day ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours

Tech stack

Amazon Web Services Audit Trail Cloud Computing Cloud Computing Security Continuous Integration Domain Name System (DNS) Identity and Access Management IP Routing Subnetting Python (Programming Language) Windows PowerShell Security Information and Event Management
+12 more
Data Logging Scripting Cloud Platform System Amazon Virtual Private Cloud (VPC) Cloudformation Gitlab-ci Information Technology Route53 Cloudwatch Terraform Jenkins Plan of Action and Milestones

Job description

SBS is expanding its AWS Professional Services delivery team to support a high-prioritynational-securityprogram. As a Senior Cloud Infrastructure Engineer, you will design and stand up secure, multi-account AWS Landing Zones in air-gapped and classified regions that serve as the foundational platform for downstream mission applications. You will partner directly with AWS Professional Services architects and government technical leads, owning architecture decisions across networking, identity, security, and automation., * Design and deploy AWS Landing Zones in air-gapped, classified regions, including AWS Control Tower equivalents and account-vending automation.

  • Architect multi-account AWS organizations withappropriate OrganizationalUnit (OU) structure, Service Control Policies (SCPs), and tag governance.

  • Build andmaintainInfrastructure-as-Code modules in Terraform (and AWS CloudFormation whererequired) for repeatable, auditable deployments.

  • Configure VPCs, subnets, route tables, Transit Gateways, VPC endpoints, DNS (Route 53 / hybrid resolvers), and private connectivity to on-premises enclaves.

  • Implement IAM policies, permission boundaries, role federation, and break-glass procedures aligned to least-privilege principles.

  • Stand up centralized logging, audit, and monitoring (CloudTrail, Config,GuardDuty, Security Hub, CloudWatch) and integrate with the customer’s SIEM.

  • Integrate the cloud platform with enterprise identity (e.g., Identity, Credential, and Access Management (ICAM); Personal Identity Verification (PIV); Common Access Card (CAC)) and compliance tooling.

  • Collaborate with AWS Professional Services, mission application teams, and the customer’s Risk Management Framework (RMF) / Authority to Operate (ATO) authorizing officials.

  • Produce architecture diagrams, runbooks, and design decision records suitable for ATO body-of-evidence packages.

Requirements

  • U.S. Citizenship and active Top Secret / SCI clearance.

  • Five (5) or more years of hands-on AWS engineering experience, including building environments frominception(greenfield).

  • Demonstrated experience designing multi-account AWS architectures and AWS Landing Zone patterns.

  • Advanced AWS networking knowledge: VPC design, Transit Gateway,PrivateLink, hybrid DNS, and on-premises connectivity patterns.

  • Proficiencywith Infrastructure-as-Code, specifically Terraform and/or AWS CloudFormation, including module design and state management.

  • Experience implementing AWS security controls, IAM at scale, KMS, audit logging, and resource-based policies.

  • Familiarity working in classified or highly regulated environments and producing artifacts suitable for compliance review.

  • Bachelor’s degree in Computer Science, Engineering, or a related discipline or equivalent professional experience.

  • Clear written and verbal communication skills for technical documentation, stakeholder coordination, and customer-facing delivery.

PREFERRED QUALIFICATIONS

  • Prior delivery experience in AWS GovCloud (US), AWS Secret Region / AWS Secret-West, or AWS Top Secret-East/West.

  • Working knowledge of DISA STIGs, NIST SP 800-53 / 800-171, and the DoD Cloud Computing Security Requirements Guide (SRG).

  • Direct experience supporting Risk Management Framework (RMF) / Authority to Operate (ATO) packages (SSP, control implementation, POA&M).

  • Experience with CI/CD for infrastructure (GitLab CI, Jenkins, AWSCodePipeline).

  • Scripting in Python or PowerShell for automation and integration tasks., * AWS Certified Solutions Architect Professional

  • AWS Certified Advanced Networking Specialty

  • AWS Certified Security Specialty

  • HashiCorpCertified: Terraform Associate

  • HashiCorpCertified: Terraform Authoring & Operations Professional

Benefits & conditions

Strategic Business Systems, Inc. (SBS) delivers AWS-aligned mission-critical cloud, cybersecurity, software engineering, and data modernization solutions to the U.S. Department of Defense, the Intelligence Community, and federal civilian agencies.

We hire engineers, architects, and consultants who want to do hands-on work on high-impact national-security programs while collaborating directly with AWS Professional Services. Our culture is technical, lean, and clearance-friendly: we invest in certifications,retaintalent through long-duration prime engagements, and provide a comprehensive benefits package., SBS offers competitive compensation and a comprehensive total-rewards package, including:

  • Comprehensive medical, dental, and vision coverage; HSA-eligible plan options available

  • 401(k) retirement plan with company match (vesting schedule per Plan Document)

  • Paid Time Off, federal holidays, and floating holiday for personal observance

  • Annual professional development support for AWS certifications, training, and conferences

  • Employee referral program where applicable and documented by program policy

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.disabledperson.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:23 min

Reviewing AWS infrastructure deployment configuration and planning

Devlin Duldulao · LIVE

1:34 min

Essential commands for running and testing Terraform configurations

Hennie Francis · LIVE

1:02 min

Applying an ETL methodology to infrastructure configuration management

Axel Barbier · World Congress 2023

1:24 min

Evaluating formal AWS certifications versus raw practical engineering experience

Jan Giacomelli · LIVE

2:32 min

Overview of Terraform and Terraform Cloud features

Devlin Duldulao · LIVE

57 sec

Extracting API schemas automatically during continuous integration builds

Axel Barbier · World Congress 2023

Videos

See all

Related articles

See all