Cloud Security Architect and Engineer, Federal Systems

Greenbrier Government Solutions Inc.
United States
about 1 month ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$131,053.0 - $157,827.0
Working hours
Regular working hours
Job source

Tech stack

Application Programming Interfaces (APIs) Systems Engineering Cloud Computing Cloud Computing Security Cloud Engineering Cyber Security Information Systems Identity and Access Management Key Management Network Segmentation Role-Based Access Control Cloud Services
+8 more
Policy as Code Data Logging Cloud Platform System Containerization Information Technology CIS Benchmarks Devsecops Plan of Action and Milestones

Job description

  • Evaluate cloud and SaaS architectures for identity federation, authentication flows, conditional access, least privilege, workload identities, and service principals.

  • Assess data residency, encryption, key management, API exposure, integration pathways, logging, observability, audit, and shared-responsibility allocations.

  • Develop secure cloud patterns and engineering recommendations that account for mission needs, VA standards, operational constraints, and inherited controls.

  • Integrate FedRAMP and Risk Management Framework requirements into systems and applications from design through deployment.

  • Identify authorization-boundary, common-control, SSP, SAR, POA&M, continuous-monitoring, and ATO impacts before implementation begins.

  • Review infrastructure-as-code, cloud configurations, network segmentation, secrets management, and service-to-service communications.

  • Work with DevSecOps, compliance, application, network, and platform teams to turn architecture findings into owned remediation actions.

  • Document decisions, diagrams, assumptions, risks, dependencies, and validation evidence in a form the customer can reuse., * Cloud designs reach implementation with clear security requirements, owners, and evidence needs.

  • Control inheritance and shared responsibility are settled early, not discovered during authorization.

  • Architecture findings lead to practical fixes that engineering and operations teams can sustain.

Work arrangement and conditions

  • Full-time role; contingent upon contract award and customer approval.

  • U.S.-based remote work from a Greenbrier-approved work location. Routine onsite work is not expected.

  • Availability during VA core hours, 8:00 a.m. to 5:00 p.m. Eastern Time on normal federal workdays.

  • Occasional travel or onsite support for kickoff and other Government-directed events, with Washington, DC anticipated as the primary location.

  • Ability to obtain and maintain the Tier 4/High Risk background suitability determination and VA access required for the role.

How we work

  • Communicate clearly and work comfortably across technical teams, program leaders, and senior government stakeholders.

  • Protect sensitive information and produce work that is complete, traceable, reviewable, and ready for customer use.

Requirements

  • At least 10 years of information security experience, including at least 5 years of cybersecurity and cloud security work at a large Government agency comparable in size or scope to GSA, IRS, DoD, or VA.

  • Experience integrating FedRAMP and Risk Management Framework requirements and authorization needs into systems and applications.

  • Experience with IT and cloud security architecture design, security engineering, development, systems engineering, and implementation.

  • Experience with cloud solutions in federal or commercial environments.

  • Hands-on knowledge of federal assessment and authorization and Authority to Operate activities.

  • Working command of NIST guidance, FISMA, FedRAMP, CIS Controls, HIPAA, and related regulatory requirements.

  • Bachelor’s degree in business administration, business management, cybersecurity, computer science, information systems, information assurance, information security, information resource management, or a related field.

  • One or more of the following: IAT III, IAM III, or IASAE III qualification/certification.

Preferred qualifications

  • Architecture or engineering experience with more than one major cloud platform.

  • Experience with cloud-native identity, container platforms, infrastructure-as-code, policy-as-code, and automated configuration assessment.

  • Federal health IT, VA, or high-value-asset experience.

Benefits & conditions

  • 401(k)
  • 401(k) matching
  • Dental insurance
  • Employee assistance program
  • Flexible schedule
  • Health insurance
  • Life insurance
  • Paid time off
  • Parental leave
  • Professional development assistance
  • Referral program
  • Retirement plan
  • Vision insurance

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:55 min

Executing secure deployments with verified compliance and data residency

Alex Laubscher Alex Laubscher · World Congress 2025

2:15 min

Auditing container configurations against CIS benchmark security standards

Madhu Akula · LIVE

1:10 min

Exposing sensitive information through partial search logs

Dennis Schulz Dennis Schulz +1 · World Congress 2026 Europe

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

3:39 min

Validating data queries and infrastructure security configurations

Philipp Krenn · World Congress 2023

1:56 min

Discovering incidents using logs, metrics, and traces

Nele Uhlemann · World Congress 2023

Videos

See all

Related articles

See all