AWS Cloud Security / IAM Engineer

AGILETEK SOLUTION LLC
Reston, VA, United States
9 days ago
Apply on www.clearancejobs.com
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Working hours
Regular working hours

Tech stack

Amazon Web Services Amazon Elastic Compute Cloud Amazon S3 Systems Engineering Bash Shell Cloud Computing Cloud Computing Security Cloud Engineering Cyber Security Continuous Integration DevOps Multi-Factor Authentication
+30 more
Github Identity and Access Management Python (Programming Language) Key Management Ping (Networking Utility) Windows PowerShell Role-Based Access Control Aws Command Line Interface (CLI) Ansible Zero Trust Network Access Systems Integration Software Vulnerability Management Data Logging Okta Cyberark Boto3 Amazon Virtual Private Cloud (VPC) Cloudformation Containerization Gitlab-ci Kubernetes Infrastructure Automation Frameworks Route53 Opsworks Functional Programming SailPoint Terraform Devsecops Docker Jenkins

Job description

We are seeking an experienced AWS Cloud Security / IAM Engineer to design, implement, automate, and secure cloud infrastructure within a Federal AWS environment.

This is not a traditional enterprise IAM role centered on administering large Okta, SailPoint, Ping, or CyberArk environments. The position is primarily focused on securing the AWS operating platform, with AWS Identity and Access Management (IAM) serving as a critical component of the overall cloud security architecture.

The ideal candidate is a hands-on AWS engineer who has experience building and securing AWS environments, implementing least-privilege access, automating infrastructure and security controls, and integrating security into DevSecOps and CI/CD workflows., Design, implement, and maintain secure AWS cloud infrastructure supporting Federal workloads. Design and manage AWS IAM roles, policies, permissions, and access controls using least-privilege principles. Implement secure authentication and authorization patterns for users, workloads, applications, and AWS services. Support multi-account AWS environments, including cross-account access and centralized security controls. Implement and maintain AWS Organizations, organizational units (OUs), and Service Control Policies (SCPs) where applicable. Design IAM permissions boundaries, role-based access controls, and workload/service roles. Review IAM policies and remediate excessive, unused, or improperly configured permissions. Automate cloud infrastructure and security configuration using Terraform, CloudFormation, Ansible, or similar Infrastructure as Code technologies. Integrate AWS infrastructure and security controls into CI/CD and DevSecOps pipelines. Develop automation using Python, Bash, PowerShell, AWS CLI, or Boto3. Configure, monitor, and remediate findings from AWS-native security services such as Security Hub, GuardDuty, CloudTrail, AWS Config, Inspector, IAM Access Analyzer, KMS, and Secrets Manager. Secure AWS networking and infrastructure components including VPCs, security groups, EC2, S3, Lambda, and related AWS services. Support containerized workloads and Amazon EKS/Kubernetes environments where applicable. Implement security controls consistent with Zero Trust and least-privilege principles. Support cloud security hardening, vulnerability remediation, logging, monitoring, and continuous compliance. Work closely with cloud engineering, DevSecOps, cybersecurity, and application teams to integrate security throughout the cloud environment. Support Federal security requirements and frameworks such as NIST 800-53, RMF, FedRAMP, DISA STIGs, and FISMA, as applicable.

AWS specifically recommends federation/temporary credentials, IAM roles for workloads, MFA, least privilege, IAM Access Analyzer, and multi-account permissions guardrails, making these good IAM competencies to emphasize.

Requirements

8+ years of experience in cloud engineering, cybersecurity engineering, DevSecOps, systems engineering, or related infrastructure roles. Strong hands-on experience with Amazon Web Services (AWS). Demonstrated experience securing production AWS environments. Hands-on experience with AWS IAM, including: IAM roles IAM policies Least-privilege access Cross-account access Role-based access Workload/service identities Experience with AWS infrastructure services such as EC2, VPC, S3, Lambda, Security Groups, Route 53, or similar services. Experience with Infrastructure as Code using Terraform and/or CloudFormation. Experience with CI/CD pipelines and DevSecOps practices. Experience automating infrastructure or security tasks using Python, Bash, PowerShell, AWS CLI, or similar scripting technologies. Understanding of cloud security concepts including Zero Trust, least privilege, encryption, logging, monitoring, and vulnerability management. Experience supporting secure or regulated environments. Preferred Qualifications AWS GovCloud experience. AWS Organizations and Service Control Policies (SCPs). IAM Identity Center. IAM Access Analyzer. AWS Security Hub. Amazon GuardDuty. AWS Config. AWS CloudTrail. Amazon Inspector. AWS KMS. AWS Secrets Manager. Amazon EKS/Kubernetes and Docker. GitLab CI/CD, Jenkins, or GitHub Actions. Ansible. Experience with NIST 800-53, RMF, FedRAMP, DISA STIGs, or similar Federal security frameworks. AWS certifications such as: AWS Certified Security - Specialty AWS Certified Solutions Architect AWS Certified DevOps Engineer Security certifications such as CISSP, Security+, CASP+/SecurityX, or equivalent.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:23 min

Reviewing AWS infrastructure deployment configuration and planning

Devlin Duldulao · LIVE

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

1:12 min

Validating risky service requests safely via dry runs

Modood Alvi · World Congress 2025

2:07 min

Inspecting default bridge architectures and custom Docker networks

Oliver Seitz Oliver Seitz · World Congress 2025

1:24 min

Evaluating formal AWS certifications versus raw practical engineering experience

Jan Giacomelli · LIVE

4:37 min

Architecting single sign-on flows across multiple application domains

Gift Egwuenu · World Congress 2023

Videos

See all

Related articles

See all