> Markdown version of [/jobs/ext/3126865-cyber-security-engineer-senior-cloud-dos-css](https://www.wearedevelopers.com/jobs/ext/3126865-cyber-security-engineer-senior-cloud-dos-css). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Security Engineer - Senior / Cloud DoS CSS - **Company:** OneZero Solutions - **Location:** Suitland-Silver Hill, MD, United States - **Experience:** Expert - **Salary:** $107,900.0 - $195,050.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Amazon Web Services, Systems Engineering, Microsoft Azure, Bash Shell, Cascading Style Sheets (CSS), Cloud Computing, Cloud Computing Security, Cloud Engineering, Collaborative Software, Cyber Security, Continuous Integration, Multi-Factor Authentication, Federal Information Processing Standards (FIPS), Data Flow Control, Identity and Access Management, Python (Programming Language), Key Management, Microsoft Visio, Windows PowerShell, Zero Trust Network Access, Data Streaming, Data Logging, Cloud Platform System, Cloudformation, Kubernetes, Information Technology, Bicep, CIS Benchmarks, Restful APIs, Terraform, Cyber Warfare, Prisma Cloud Platform, Devsecops, Plan of Action and Milestones - **Published:** September 28, 2026 - **Apply:** https://www.careerjet.com/jobad/us07c99fdf6428ddbf057b2a2efc8a7592 ## About the Role through CA change management; participate in CCB/ECM.Demonstrate cloud control implementations during Security Control Review Meetings and provide screenshots, logs, and configuration evidence to the SCA(RMF Step 4).Support infrastructure-as-code and container image security checks in DevSecOps pipelines and ensure results are captured as SSP evidence(RMF Step 3).Coordinate with cloud system operations teams and CSPs to validate remediation and maintain the accredited security posture of cloud systems.Required QualificationsEight (8)+ years of cybersecurity or systems engineering experience, including three (3)+ years securing federal workloads in AWS GovCloud, Azure Government, or equivalent.Hands-on experience with a CNAPP/CSPM platform (Wiz strongly preferred; Prisma Cloud, Defender for Cloud, or equivalent considered).Working knowledge of NIST SP 800-53 Rev. 5 control implementation in cloud environments and FedRAMP inheritance models.Active, final SECRET security clearance; U.S. citizenship.DoD 8140/8570 IAT Level III or IAM Level II baseline certification (e.g., CISSP, CASP+, CCSP, CISM) or ability to obtain within 6 months.Experience producing authorization evidence (diagrams, configuration exports, scan reports) for ISSOs and assessors.Preferred QualificationsCCSP, AWS Certified Security - Specialty, or Azure Security Engineer Associate; Wiz certification.Department of State or other federal civilian cloud authorization experience.Experience with Terraform/CloudFormation security, Kubernetes/container security, and CI/CD pipeline integration.Experience with cryptographic key management services (AWS KMS, Azure Key Vault, HSMs) and FIPS 140-2/140-3 validated modules.Technical SkillsWiz (or comparable CNAPP), AWS/Azure native security services, IAM, logging/monitoring, KMS/Key Vault.Tenable integration for hybrid boundaries; STIG/CIS benchmarks for cloud OS and services.Infrastructure-as-code (Terraform, CloudFormation, Bicep), containers/Kubernetes, CI/CD tooling.NIST SP 800-53 Rev. 5, 800-144/145/210 cloud guidance, FedRAMP, zero-trust architecture (NIST SP 800-207).Scripting (Python, PowerShell, Bash) and REST API automation; Visio diagramming.EducationBachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field, or an additional four (4) years of directly relevant experience in lieu of degree.Remote/Hybrid/On-site and any other relevant work-environment requirementRemote. Duties are performed remotely; the selected candidate must reside within the National Capital Region (NCR). The Government does not furnish equipment; OneZero provides the laptop and collaboration tools. Position requires an OpenNet account, DoS PIV badge, multifactor authentication, and adherence to DoS SBU/CUI handling requirements. Local travel within the National Capital Region; minimal other travel.Position Status:New Position, contingent upon Call Order awardOneZero Solutions LLC is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or protected veteran status.Job Posted by ApplicantPro ## Description integrations, and dashboards.Support agent deployment, vulnerability and compliance scanning, data ingest and sharing, pipeline, and other integration efforts for cloud workloads.Apply Department and CA cloud-security and zero-trust overlays; identify and document controls inherited from CSPs and DT enterprise services in each system's Inherited Controls Matrix and SSP(RMF Step 2).Support cryptographic key management and encryption key lifecycle activities for cloud and hybrid systems.Develop and maintain cloud architecture, network, and data-flow diagrams and evidence for System Boundary & Data Flow Packages and the Evidence Index(RMF Steps 1 and 3).Review cloud vulnerability and compliance scan results within 5 business days of scan completion; drive critical and high findings to closure within Department and BOD timelines; provide closure evidence to ISSOs for POA&M management(RMF Step 6).Perform Security Impact Analysis on cloud infrastructure and configuration changes submitted, Description Cyber Defense Infrastructure Support Engineer Location: Suitland, MD Clearance: Active TS/SCI Join a mission focused team supporting the Navy's cybersecurity env… + 12 days ago ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Back(end) to the Future: Embracing the continuous Evolution of Infrastructure and Code](https://www.wearedevelopers.com/videos/440-back-end-to-the-future-embracing-the-continuous-evolution-of-infrastructure-and-code) - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)