> Markdown version of [/jobs/ext/3139831-cloud-engineer](https://www.wearedevelopers.com/jobs/ext/3139831-cloud-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cloud Engineer - **Company:** KBR Inc - **Location:** Lexington Park, MD, United States - **Experience:** Experienced - **Salary:** $130,000.0 - $190,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Active Directory, Amazon Web Services, Amazon Elastic Compute Cloud, Amazon S3, Bash Shell, Command-Line Interface, Cloud Computing, Cloud Engineering, Configuration Management, CompTIA Security+, Cyber Security, Information Systems, Computer Networks, Databases, Linux, Disaster Recovery, Domain Name System (DNS), Monitoring of Systems, Identity and Access Management, Internet Information Services (IIS), IP Routing, Subnetting, Python (Programming Language), Linux System Administration, Windows Servers, Network Configuration and Change Management, Public Key Infrastructure, Role-Based Access Control, Amazon Simple Notification Service (SNS), Software Deployment, Software Vulnerability Management, Private Cloud Environment, Scripting, Enterprise Software Applications, Network Access Control, Cloud Platform System, Sysadmin, System Availability, AWS Lambda, AWS ECS, Cloudformation, Containerization, Kubernetes, Infrastructure Automation Frameworks, Patch Management, Cloudwatch, Terraform, Network Server, Devsecops, Docker - **Published:** September 29, 2026 - **Apply:** https://kbr.wd5.myworkdayjobs.com/KBR_Careers/job/Lexington-Park-Maryland/Cloud-Engineer_R2130580 ## About the Role * Bachelor's degree. Relevant additional experience may be considered in accordance with contract requirements. * Minimum of three years of specialized experience administering cloud systems within an AWS GovCloud or AWS Secret Region government environment. * Demonstrated experience managing CloudWatch log groups, metric filters, dashboards, alarms, and alert configurations. * Proficiency with AWS Command Line Interface, AWS Systems Manager, Identity and Access Management, Amazon EC2, and Virtual Private Cloud configurations. * Experience administering Windows Server and Linux operating systems in cloud-hosted environments. * Experience building or administering Linux-based containers and Kubernetes environments. * Demonstrated experience using Terraform for Infrastructure as Code. * Proficiency with Python, Bash, or comparable scripting languages for administrative and infrastructure automation. * Practical knowledge of DISA STIGs, DoD Risk Management Framework requirements, and military disaster recovery planning standards. * Ability to develop and maintain accurate technical procedures, architecture information, monitoring documentation, and system-administration records. * Required Certifications: Candidates must possess the following certifications before onboarding: AWS Certified SysOps Administrator, Associate CompTIA Security+ or another approved IAT Level II baseline certification * Preferred CertificationAWS Certified Solutions Architect, Associate Preferred Qualifications * Experience supporting Navy, Marine Corps, NAVAIR, or other DoD enterprise information systems.Experience administering AWS environments operating at DoD Impact Levels 5 or 6. * Experience supporting PLM or other complex COTS enterprise applications. * Familiarity with IT service management integration and automated incident-notification workflows. * Experience conducting disaster recovery exercises and documenting recovery results. * Experience supporting RMF authorization packages, continuous monitoring, or Assessment and Authorization activities. * Strong written and verbal communication skills, with the ability to coordinate effectively across engineering, cybersecurity, operations, application, and government stakeholder teams. ## Description KBR is seeking a highly qualified Cloud Engineer, AWS Administrator and CloudWatch Specialist to support the Aviation Product Lifecycle Management program. The selected candidate will provide engineering, administration, monitoring, automation, and cybersecurity support for secure Amazon Web Services GovCloud environments supporting Navy and Department of Defense aviation systems. The Cloud Engineer will design, administer, secure, and sustain AWS infrastructure operating at Impact Levels 5 and 6. The position will serve as a technical specialist for Amazon CloudWatch monitoring, Windows and Linux environments, containerized applications, Kubernetes orchestration, disaster recovery, and infrastructure automation. The successful candidate will help ensure that AvPLM systems remain secure, resilient, observable, recoverable, and aligned with applicable Navy and DoD requirements, including established Recovery Time Objectives and Recovery Point Objectives., AWS GovCloud Infrastructure Administration * Administer the lifecycle of AWS GovCloud resources, including Amazon EC2 instances, Linux-hosted containers, Amazon S3 storage buckets, Amazon FSx storage shares, and associated network configurations. * Configure and maintain secure Virtual Private Cloud environments, including subnets, route tables, security groups, Network Access Control Lists, and transit gateways. * Implement and maintain Identity and Access Management policies, roles, and permissions in accordance with least-privilege principles. * Use Infrastructure as Code tools, including Terraform and AWS CloudFormation, to automate infrastructure deployment and configuration. * Develop Python and Bash scripts to automate system deployment, patch management, and recurring administrative activities. * Use AWS Systems Manager to support configuration management, patching, automation, and administration of cloud-hosted systems. Amazon CloudWatch Monitoring and Alerting * Design, implement, and maintain enterprise monitoring solutions using Amazon CloudWatch, CloudWatch Logs, and AWS EventBridge. * Develop and automate deployment of the CloudWatch unified agent across virtual-machine fleets to collect operating-system metrics and system logs. * Create custom CloudWatch dashboards that display key performance indicators, infrastructure health, system availability, and disaster recovery readiness. * Configure CloudWatch log groups, metric filters, alarms, and alerting capabilities. * Establish event-driven remediation and notification workflows by integrating CloudWatch Alarms with AWS Lambda, Amazon Simple Notification Service, and applicable IT service management tools. * Implement monitoring capabilities for the network traffic, servers, databases, and supporting systems that comprise Commercial Off-the-Shelf Product Lifecycle Management applications. * Monitor system performance and identify conditions that may affect availability, reliability, security, or mission operations. Windows Server Administration * Deploy, configure, administer, and sustain Windows Server environments hosted on Amazon EC2. * Support the availability, security, and performance of cloud-hosted Windows systems. * Administer Active Directory, Group Policy Objects, Domain Name System services, and Internet Information Services. * Integrate Windows Server environments with DoD Public Key Infrastructure to support Common Access Card authentication. * Perform operating-system patching, upgrades, vulnerability remediation, and recurring maintenance using AWS Systems Manager, Windows Update Services, or other approved tools. Container and Kubernetes Administration * Design, deploy, configure, and administer Kubernetes clusters using Amazon Elastic Kubernetes Service or self-hosted Kubernetes on Amazon EC2, based on AvPLM and COTS application requirements. * Build, maintain, secure, and optimize Docker and other container images in alignment with DoD DevSecOps practices. * Administer Kubernetes components, including pods, deployments, services, ingress controllers, and Role-Based Access Control. * Manage secure container registries, including Amazon Elastic Container Registry. * Use Helm and other approved package-management tools to support application deployment, configuration, upgrades, and lifecycle management. Disaster Recovery and Contingency Operations * Configure, test, and validate AWS disaster recovery capabilities using AWS Backup, AWS Elastic Disaster Recovery, multi-region replication, and other approved AWS-native services. * Coordinate with system owners, engineering teams, cybersecurity personnel, and other stakeholders to align technical configurations with documented Recovery Time Objectives and Recovery Point Objectives. * Support disaster recovery planning for in-scope AvPLM and mission-program applications. * Plan, coordinate, execute, and document disaster recovery exercises. * Verify system failover integrity, monitoring performance, application availability, and data-recovery processes following exercises or contingency events. * Identify recovery gaps and support corrective actions that improve system resilience and continuity of operations. Cybersecurity and Compliance * Harden cloud infrastructure, Windows systems, Linux systems, containers, and supporting services in accordance with applicable Defense Information Systems Agency Security Technical Implementation Guides. * Support compliance with FedRAMP requirements and applicable NIST Special Publication 800-53 security controls. * Ensure log aggregation, system monitoring, and audit configurations comply with applicable Navy and DoD retention requirements. * Collaborate with Command cybersecurity and information-assurance teams to produce technical documentation supporting Assessment and Authorization activities. * Support system authorization and continuous monitoring activities conducted under the DoD Risk Management Framework. * Assist with vulnerability remediation, security evidence collection, configuration documentation, and technical responses to cybersecurity findings. ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [30 powerful AWS hacks in just 30 minutes: Boost your developer productivity](https://www.wearedevelopers.com/videos/1624-30-powerful-aws-hacks-in-just-30-minutes-boost-your-developer-productivity) - [Celery on AWS ECS - the art of background tasks & continuous deployment](https://www.wearedevelopers.com/videos/561-celery-on-aws-ecs-the-art-of-background-tasks-continuous-deployment) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Docker build without Docker](https://www.wearedevelopers.com/videos/100114-docker-build-without-docker) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [A Guide to Green Tech and Green IT Careers](https://www.wearedevelopers.com/magazine/374-a-guide-to-green-tech-and-green-it-careers) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market)