> Markdown version of [/jobs/ext/2508220-security-compliance-engineer-region-services-corporate-infrastructure](https://www.wearedevelopers.com/jobs/ext/2508220-security-compliance-engineer-region-services-corporate-infrastructure). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Compliance Engineer, Region Services Corporate Infrastructure - **Company:** Amazon.com, Inc. - **Location:** Herndon, VA, United States - **Experience:** Experienced - **Salary:** $116,900.0 - $167,400.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Active Directory, Amazon Web Services, Cloud Computing, Configuration Management, Cyber Security, Dynamic Host Configuration Protocol, Linux, Domain Name System (DNS), Microsoft Exchange Server, Hypertext Transfer Protocols (HTTP), Internet Protocol, Microsoft Security Essentials, Windows Servers, Networking Basics, Windows PowerShell, Ansible, Skype for Business, Remote Infrastructure Management, Runbook, TCP/IP, Transport Layer Security, Nessus, Puppet, Vulnerability Analysis - **Published:** August 11, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=610c82654b633f32 ## About the Role * Associate's degree or above, or Cloud+ or GICSP (Global Industrial Cyber Security Professional) or GSEC (GIAC Security Essentials) or SSCP (Systems Security Certified Practitioner) * Knowledge of configuration management systems, such as Puppet, Chef, Ansible, or related systems * 3+ years of systems administration (Linux or Windows) experience * Current, active US Government Security Clearance of TS/SCI with Polygraph, * 3+ years of work with networking fundamentals or Internet protocols such as TCP/IP, UDP, SSL, DNS, HTTP/S, or equivalent experience ## Description Region Services Corporate Infrastructure (RSCI) delivers foundational Windows infrastructure services across Amazon Dedicated Cloud (ADC) environments supporting U.S. Government customers. Our team owns Active Directory, File Services, DHCP, DNS, Enterprise Configuration Manager (ECM), Group Policy, and desktop services that AWS service teams depend on. We are looking for a Security Compliance Engineer who can monitor, assess, and drive security compliance across our Remote Management and Administration (RMNA) networks. You will operate vulnerability scanning infrastructure, analyze results, drive service teams to remediation, and ensure our environments maintain compliance with DISA STIGs and the Risk Management Framework (RMF). You will develop and maintain dashboards that give leadership and external security stakeholders clear visibility into our compliance posture, and produce scan data that feeds directly into customer authorization systems. This is a hands-on role. You will run and analyze Tenable/Nessus scans, track vulnerabilities to closure, develop automation to streamline compliance workflows, build and maintain security dashboards, support our comply-to-connect solution, and contribute to security accreditation packages for services within RSCI. You need to understand Windows infrastructure deeply enough to assess whether a finding is a real risk or a false positive and to drive the right remediation with service owners. This position requires that the candidate selected must currently possess and maintain an active TS/SCI security clearance with polygraph. The position further requires the candidate to opt into a commensurate clearance for each government agency for which they perform AWS work., * Operate and maintain Tenable Security Center and Nessus scanning infrastructure across multiple isolated ADC environments * Conduct vulnerability scans, analyze results, and drive service teams to patch compliance within SLA thresholds (Critical/High: 30 days, Moderate: 90 days, Low: 180 days) * Develop, operate, and maintain the comply-to-connect solution for RMNA networks * Assess environments against DISA STIGs for Windows 11, Windows Server, Microsoft Exchange, and Skype for Business; identify and track compliance gaps * Build and maintain security compliance dashboards providing real-time visibility into host health, patch status, and SLA compliance * Produce scan data and compliance artifacts for ingestion by AWS security teams and external customer authorization systems * Conduct threat assessments against RMNA infrastructure including Ansible automation workflows * Contribute to and maintain security accreditation packages (RMF A&A documentation) for RMNA * Develop Ansible playbooks and PowerShell automation to streamline compliance scanning, reporting, and remediation tracking * Partner with A&A to review and validate scan data prior to customer delivery * Create and maintain runbooks, compliance procedures, and standard operating procedures * Participate in on-call rotation for security and compliance events * Participate in weekly operations meetings reviewing Tenable dashboards and SLA compliance with service managers ## Related Videos - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Turning Container security up to 11 with Capabilities](https://www.wearedevelopers.com/videos/718-turning-container-security-up-to-11-with-capabilities) - [Hacking MSSQL on Cloud. All of them. How I became sysadmin on Azure, AWS, GCP and Alibaba.](https://www.wearedevelopers.com/videos/100339-hacking-mssql-on-cloud-all-of-them-how-i-became-sysadmin-on-azure-aws-gcp-and-alibaba) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)