> Markdown version of [/jobs/ext/2188705-cloud-security-engineer](https://www.wearedevelopers.com/jobs/ext/2188705-cloud-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cloud Security Engineer - **Company:** Koniag Services, Inc. - **Location:** Washington, DC, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Application Firewall, Audit Trail, Microsoft Azure, Cloud Computing Security, Cyber Security, Information Systems, System Configuration, Identity and Access Management, Intrusion Detection and Prevention, OAuth, Cloud Services, Security Assertion Markup Language (SAML), Security Software, Security Information and Event Management, Single Sign-On, Data Streaming, Tripwire, Software Vulnerability Management, Google Cloud, Cloud Platform System, Multi-Cloud, Cloudformation, Azure Security Center, Infrastructure Automation Frameworks, Information Technology, Opsworks, CIS Benchmarks, Terraform, Splunk, Serverless Computing, Qualys, Servicenow - **Published:** August 22, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9110622/cloud-security-engineer ## About the Role * Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or a related IT or security field from an accredited college or university. * 5+ years of professional experience in IT/network engineering, security engineering, system administration, or security operations. * Demonstrated experience with FISMA, FedRAMP, and NIST SP 800-53 security frameworks and control families. * Active Secret security clearance or higher., * Exceptional analytical skills with strong verbal and written communication abilities in English, with the capacity to communicate effectively with both technical and non-technical stakeholders. * Demonstrated ability to work independently as a self-starter while also functioning effectively as a collaborative team member. * Hands-on experience engineering and implementing security solutions across two or more major cloud platforms, including AWS, Microsoft Azure, and/or GCP. * Proficiency in configuring and operating cloud-native security services such as AWS Config, AWS Security Hub, Azure Defender/Security Center, Azure Policy, and/or GCP Security Command Center. * Experience implementing and managing security tools including vulnerability management platforms (e.g., Qualys), host-based intrusion detection (e.g., Tripwire), and SIEM platforms (e.g., Splunk). * Experience with OS hardening techniques and implementation of security baselines across cloud-hosted systems. * Familiarity with preparing and maintaining Assessment and Authorization (A&A) documentation including System Security Plans (SSPs) and security controls worksheets. * Experience performing continuous monitoring and security impact assessments within cloud environments. * Knowledge of identity and access management (IAM) principles and implementation across cloud platforms. * Ability to identify opportunities to automate security processes and monitoring to reduce risk and operational overhead. * Strong initiative and ability to present ideas and solutions to overcome technical and organizational security challenges., * Active security certifications such as CISSP, CISM, CISA, CEH, CCSK, CCSP, AWS Certified Security Specialty, Microsoft Certified: Azure Security Engineer Associate, or Google Professional Cloud Security Engineer. * Experience working in a federal government IT environment, specifically within FedRAMP-authorized or FISMA-compliant cloud environments. * Experience deploying and operating tools across multiple security domains including vulnerability management, incident detection and response, event/audit log collection and analysis, and network and web application firewalls. * Familiarity with ServiceNow and its integration within security operations and GRC workflows. * Knowledge of single sign-on (SSO) concepts using SAML and OAuth2 within cloud environments. * Experience with Infrastructure as Code (IaC) tools such as Terraform, CloudFormation, or ARM templates to support secure cloud deployments. * Master's degree in Information Systems, Cybersecurity, or a related field. ## Description The Cloud Security Engineer will be responsible for the security aspects of cloud system design, security tool and service analysis and selection, and subsequent implementation across AWS, Microsoft Azure, and Google Cloud Platform (GCP). This individual will configure tools and services to meet the business requirements, policy mandates, and security risk tolerance of our government customers. The Cloud Security Engineer will also document how required security controls are satisfied through cloud service and tool implementations to support Assessment and Authorization (A&A) activities. Principal responsibilities will include but are not limited to: * Engineer and design security solutions across cloud platforms including AWS, Microsoft Azure, and GCP that manage risk and meet relevant security regulations, controls, and policies. * Implement security designs by installing, configuring, and testing cloud-native services, associated third-party services, and security software across multi-cloud environments. * Determine how to effectively leverage native security services from cloud providers and identify gaps that must be addressed through additional tools, software, or third-party services. * Implement and manage security tools and services including OS hardening, cloud-native security features (e.g., AWS Config, Azure Security Center, GCP Security Command Center), vulnerability management tools such as Qualys, intrusion detection tools such as Tripwire, and SIEM solutions such as Splunk. * Develop and maintain processes and procedures for the operation and use of implemented security tools and services. * Prepare Assessment and Authorization (A&A) documentation including System Security Plans (SSPs), security control worksheets, and other supporting artifacts. * Participate in the assessment of system security controls to validate proper implementation and identify weaknesses or gaps in compliance posture. * Perform continuous monitoring of cloud environments using implemented solutions and tools to detect and respond to security events. * Conduct security impact assessments of proposed changes to cloud environments to identify adverse shifts in security risk posture or compliance standing. * Identify new and innovative ways to leverage existing toolsets to automate security management, monitoring, and related processes in order to reduce risk and operational costs. * Collaborate with cross-functional technical teams, system owners, and business analysts to reconcile security requirements with operational needs. * Contribute to technical documentation including architecture diagrams, security design documents, and detailed data flows. ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Advanced Cypress: custom assertions and tasks](https://www.wearedevelopers.com/videos/790-advanced-cypress-custom-assertions-and-tasks) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)