> Markdown version of [/jobs/ext/2203907-cloud-security-engineer-aws-govcloud](https://www.wearedevelopers.com/jobs/ext/2203907-cloud-security-engineer-aws-govcloud). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cloud Security Engineer, AWS GovCloud - **Company:** The Apex - **Location:** Los Angeles, CA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Amazon Web Services, Microsoft Antivirus, Software System Penetration Testing, Microsoft Azure, Burp Suite, Cloud Computing, Cloud Computing Security, Cloud Engineering, Configuration Management, CompTIA Security+, Cyber Security, Continuous Delivery, Continuous Integration, Data Security, Software Design Patterns, Hardware Design, Identity and Access Management, Internet Security, Information Systems Security Architecture Professional, Python (Programming Language), Network Security, Microsoft Software, Network Segmentation, PCI Data Security Standards, Windows PowerShell, Role-Based Access Control, Zero Trust Network Access, Information Technology Security Auditing, Security Software, Security Information and Event Management, Software Engineering, Data Logging, Scripting, Google Cloud, Cloud Platform System, Multi-Cloud, Cyber Threat Analysis, Cloudformation, Information Technology, Nessus, Data Management, Front End Software Development, CIS Benchmarks, Terraform, Software Version Control, Devsecops, Security Orchestration, Automation & Response, Plan of Action and Milestones, Vulnerability Analysis - **Published:** August 23, 2026 - **Apply:** https://www.careerbuilder.com/job-details/senior-cloud-security-engineer-aws-govcloud-los-angeles-ca--50b3739a-e649-4f94-99f6-7100d7ab742a ## About the Role * Must be a U.S. citizen. * Education: Bachelor's degree in Cybersecurity, Information Assurance, Computer Science, or a related field (or 5+ years equivalent professional experience in cloud security engineering) * Experience: 5-9+ years in cloud security engineering, with hands-on work in AWS GovCloud, Azure, Google GCP, or multi-cloud environments. * Strong analytical, problem-solving, communication, and collaboration skills; ability to work in fast-paced, mission-critical environments. Technical Skills: + Deep knowledge of cloud platforms (AWS GovCloud, Azure Government, etc.), IAM/RBAC, encryption, network security, and cloud-native security services. + Familiarity with SIEM, vulnerability scanners, threat intelligence, and automation tools (e.g., Terraform, Python scripting). + Experience with compliance frameworks (NIST, FedRAMP, RMF) and tools like Azure Sentinel, NESSUS, BURP SUITE, Microsoft Defender, or AWS equivalents. + Deep understanding of network security, encryption, logging/monitoring, and container/Kubernetes security. + Experience with infrastructure-as-code, scripting (Python, PowerShell, etc.), and security automation tools. * Additional Certifications: + CISSP, AWS Certified Security-Specialty, AWS Certified Solutions Architect (Associate or Professional), Microsoft Certified: Security, Compliance & Identity, Security+, CEH, or CSSP related (e.g., CySA+, GCIH)., Access Control, Amazon Web Services (AWS), Analysis Skills, Architectural Analysis, Automation, Benchmarking, Best Practices, Buses, CISSP - Certified Information Systems Security Professional, Cloud Architecture, Cloud Computing, CompTIA Security+, Computer Science, Computer Security, Configuration Management, Continuous Deployment/Delivery, Continuous Integration, Cost Control, Cryptography, Design Patterns Programming Methodologies, Diversity, Environmental Monitoring, Federal Compliance Regulations, Funding, GCIH - GIAC Certified Incident Handler, Government, Hardware Design, Healthcare, High Tech Industry, ISO (International Organization for Standardization), Identity Data Management, Incident Response, Industry Standards, Information/Data Security (InfoSec), Intelligence Community, Internet Security, Just in Time (JIT), Life Insurance, MCP - Microsoft Certified Professional, Maintain Compliance, Manufacturing Design, Microsoft Product Family, Microsoft Windows Azure, Nessus, Network Security, Online Publications, PCI-DSS, Penetration Testing, People Management, Problem Solving Skills, Protective Services, Python Programming/Scripting Language, Risk, Root Cause Analysis, Scripting (Scripting Languages), Security Analysis, Security Architecture, Security Auditing, Security Compliance, Security Information and Event Management (SIEM), Security Protocols, Security Software, Software Engineering, Source Code/Configuration Management (SCM), Startup, Support Documentation, Systems Maintenance, Team Player, Training/Teaching, U.S. National Institute of Standards and Technology (NIST), United States Citizen, United States Department of Defense (DoD), Vulnerability Scanners, Wheel/Front-End Loader, Windows PowerShell ## Description We are seeking a Senior Cloud Security Engineer, AWS GovCloud to design, implement, maintain, and optimize secure cloud environments supporting U.S. government, DoD, and intelligence community missions.This role plays a critical part in protecting classified and sensitive data in AWS, Azure, and hybrid/multi-cloud infrastructures while ensuring full compliance with federal standards such as NIST 800-53, FedRAMP, RMF, and DoD Impact Levels (IL-4/IL-5). The right candidate will bring hands-on experience securing cloud platforms in regulated environments. This role will help the organization meet industry standards such as SOC2, ISO 27001, PCI-DSS, GDPR/CCPA, or other relevant compliance frameworks., * Design and implement secure cloud architectures and configurations across AWS GovCloud, Azure, and/or Google Cloud, applying best practices for least privilege encryption, network segmentation, and data protection. * Implement and maintain cloud security frameworks, ensuring ongoing compliance with NIST 800-53 Rev. 5, FedRAMP, DoD IL-2/4/5, RMF, and Secure Cloud Computing Architecture (SCCA) requirements. * Configure and manage Identity and Access Management (IAM), Role-Based Access Control (RBAC), Just-In-Time (JIT) access, Key Vaults, and Zero Trust Architecture (ZTA) principles across cloud environments. * Engineer, deploy, and optimize cloud-native security tools, including Microsoft Defender for Cloud, Azure Sentinel, AWS GovCloud security services, CSPM/CWPP solutions, and SIEM (Elastic) platforms for threat detection, monitoring, and response. * Conduct vulnerability assessments, penetration testing simulations, security configuration reviews (against STIGs, CIS benchmarks, and NIST controls), and continuous monitoring of cloud resources. * Develop, maintain, and update System Security Plans (SSP), Security Assessment Reports (SAR), Plans of Action & Milestones (POA&M), and risk/compliance reporting for cloud-based operations. * Identify, analyze, and respond to Indicators of Compromise (IoCs), threat intelligence, and security incidents within cloud environments; perform root-cause analysis and implement preventive controls. * Perform periodic security reviews and audits of cloud environments (Azure, AWS, hybrid) to ensure sustained compliance, mitigate evolving threats, and update policies/procedures. * Collaborate with DevSecOps, infrastructure, and development teams to integrate security into CI/CD pipelines, automate security controls, and support secure cloud migrations or modernization initiatives. * Assess current cloud architectures, propose security improvements, review designs through a security lens, and serve as a subject-matter expert on cloud security tools,processes, and best practices. * Coordinate with configuration management teams to ensure hardware/software changes adhere to security protocols, maintain version control, and support documentation of the cyber terrain. * Develop, enforce, and maintain cloud security policies, standards, and automated guardrails to support secure CI/CD pipelines and infrastructure-as-code (IaC) practices (e.g., using Terraform, CloudFormation). * Monitor cloud environments for security incidents, investigate alerts, perform root-cause analysis, and coordinate incident response activities. * Identify emerging threats and recommend proactive improvements to cloud security posture, including automation of security controls and processes. * Provide guidance and training to engineering teams on secure cloud design patterns and best practices. * Ability to be on-site 5 days a week at our office in Playa Vista, CA. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Top Must-Visit Developer Conferences in the US in 2026](https://www.wearedevelopers.com/magazine/679-top-must-visit-developer-conferences-in-the-us-in-2026) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers)