> Markdown version of [/jobs/ext/264500-cloud-security-lead-sme](https://www.wearedevelopers.com/jobs/ext/264500-cloud-security-lead-sme). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cloud Security Lead SME - **Company:** Everforth Ecs - **Location:** Fairfax, VA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Microsoft Azure, Cloud Computing, Cloud Computing Security, CompTIA Security+, Identity and Access Management, Intrusion Detection and Prevention, NIPRNet, Cloud Services, Zero Trust Network Access, Microsoft SharePoint, Devsecops - **Published:** May 13, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=9fac5cbca48a7ea9 ## About the Role Do you have experience in Stakeholder management?, * Current Secret security clearance. * 12 or more years of progressively responsible experience in cybersecurity, cloud security, or a closely related field, with demonstrated expert-level proficiency securing mission-critical cloud environments in support of DoW or federal government programs. * DoW 8140/8570 IAM Level I baseline certification, satisfied by one of the following active credentials: CompTIA Security+ CE, ISC² CAP, ISC² SSCP, or GIAC GSLC. * Demonstrated experience implementing and assessing Zero Trust security capabilities in alignment with the DoW Zero Trust Reference Architecture and NIST SP 800-207, including Attribute-Based Access Control, Privileged Access Management, Identity and Access Management federation, and continuous monitoring across multi-enclave cloud environments. * Hands-on experience executing Risk Management Framework activities, including preparation and management of cybersecurity Body-of-Evidence artifacts, eMASS administration, and support for Authority to Operate processes across multiple security enclaves. * Strong problem-solving and decision-making capabilities, with a proven ability to weigh the relative costs and benefits of potential actions and identify the most appropriate solution. * Highly developed interpersonal and oral/written communication skills, with the ability to effectively and professionally interact with a diverse set of stakeholders (from peers to end-users to executive management). ## Description The War Data Platform (WDP) is a key initiative within the U.S. Department of War's (DoW) AI-First strategy introduced in early 2026. The WDP focuses on operational warfighting data and aims to accelerate the deployment of artificial intelligence (AI) on the battlefield. The WDP extends to Unclassified, Secret, and Top Secret environments, and supports collaboration between Combatant Commands, Joint Staff directorates, Senior Executive Service leaders, and operational analysts. * The Cloud Security Lead SME is a senior subject matter expert responsible for the enterprise cloud security posture of the WDP across NIPRNet, SIPRNet, and JWICS environments, serving as the authoritative voice on Zero Trust compliance, Risk Management Framework execution, and cloud security architecture across all WDP-supported Cloud Service Provider environments. This role works in close coordination with cybersecurity leadership, platform engineers, and Authorizing Officials to sustain and continuously improve the authorization posture of mission-critical cloud infrastructure supporting the DoW's AI-First mission. * Provides enterprise cloud security oversight supporting Department of War mission systems operating within AWS GovCloud, Azure Government, and approved DoW cloud environments. * Monitors cloud-native security posture using Cloud Security Posture Management platforms integrated with native provider tooling to identify misconfigurations, policy drift, and compliance gaps. * Configures and enforces cloud security controls aligned to the DoW Cloud Computing Security Requirements Guide, Zero Trust Architecture, and Risk Management Framework objectives. * Reviews Infrastructure-as-Code artifacts to validate secure baseline configurations prior to deployment, integrating security checks into DevSecOps pipelines and automated compliance workflows. * Analyzes cloud audit logs, configuration events, and security alerts to support continuous monitoring, threat detection, and incident response coordination. * Collaborates with cloud engineers, platform teams, and cybersecurity leadership to remediate findings impacting authorization posture and mission availability. * Maintains traceable evidence supporting security assessments, authorization packages, and ongoing compliance reporting through eMASS, SharePoint, and centralized dashboards. * Produces cloud security posture reports, risk summaries, and remediation plans for Authorizing Officials and senior cybersecurity leadership. * Supports cloud migration initiatives by embedding security requirements into design reviews, architecture decisions, and operational handoff processes. * Delivers measurable improvements in cloud compliance posture, configuration consistency, risk visibility, and operational resilience while reinforcing program values of security-by-design, accountability, mission assurance, and disciplined cloud operations. * Performs other duties as assigned. ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Leverage Cloud Computing Benefits with Serverless Multi-Cloud ML ](https://www.wearedevelopers.com/videos/78-leverage-cloud-computing-benefits-with-serverless-multi-cloud-ml) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [What Makes WeAreDevelopers World Congress Different From Every Other Tech Event?](https://www.wearedevelopers.com/magazine/701-what-makes-wearedevelopers-world-congress-different-from-every-other-tech-event)