Cloud Security Engineer

AnaVation, LLC
San Antonio, TX, United States
16 days ago
Apply on startup.jobs
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
10 years minimum
Working hours
Regular working hours
Job source

Tech stack

Java (Programming Language) Artificial Intelligence Amazon Web Services Microsoft Azure C++ (Programming Language) Cloud Computing Cloud Computing Security Cloud Engineering Cyber Security Databases Linux Subnetting
+27 more
Python (Programming Language) Network Segmentation Peering Ansible Zero Trust Network Access Security Information and Event Management Software Engineering Software Factory Software Vulnerability Management Data Logging Enterprise Software Applications Okta Istio Amazon Virtual Private Cloud (VPC) Gitlab Git Gitlab-ci Kubernetes Information Technology CIS Benchmarks Software Coding Terraform Devsecops Docker Security Orchestration, Automation & Response Golang Microservices

Job description

Position Responsibilities: This position sets the engineering direction for the Government’s zero trust and cloud security modernization, translating roadmap objectives into deployed, measurable capability., * Lead zero trust engineering and interoperability initiatives, future-proofing implementations as tools and requirements evolve.

  • Design, implement, and maintain AWS cloud architecture using Terraform (including custom modules) and Ansible.
  • Administer relevant cloud infrastructure-level consoles (e.g., AWS) and secure cloud services and accounts; apply advanced networking, VPC, peering, and subnet design.
  • Support the SIEM, SOAR, Incident Management System (IMS), and Incident Response Team (IRT) roadmap, engineering, and integration.
  • Architect logging, monitoring, and telemetry, coordinating delivery with the Cyber Security Service Provider (CSSP).
  • Advance security automation and automated evidence collection to increase inheritance and continuous monitoring maturity.
  • Provide flexible SME support and reach-back across DevSecOps automation, supply chain security, enterprise vulnerability management, and AI.
  • Provide updates to the Cyber Assessment Roadmap; create/maintain documentation and brief technical and non-technical stakeholders.
  • Collaborate with ISSMs, ISSEs, Value Stream engineers, COT, CPT, and Government stakeholders using tools like git.
  • Support Zero Trust enforcement, cloud security controls, and Infrastructure as Code security across mission environments.
  • Maintain and validate A&A control evidence in eMASS (control implementation, SIAs, SRCs, POA&Ms) supporting continuous monitoring and cATO readiness.
  • Architect and integrate an enterprise SIEM ingesting logs from AWS (VPC, EKS, CloudTrail), Okta, Istio, GitLab, and host logs (systemd, audit), with dashboards for runtime monitoring, defense, and forensics.
  • Enforce Zero Trust through ICAM integration and micro-segmentation validation and manage enterprise security tooling.

Requirements

  • Clearance: U.S. Citizen, current TS/SCI; current CI Polygraph
  • Education: Bachelor’s degree in Cybersecurity, Computer Science, Cloud Computing, IT, or related technical field.
  • Certification: DoD 8140/8570 IAT Level II and an AWS certification.
  • Location: Full-time on-site in San Antonio, TX.
  • Experience and knowledge:
  • Subject Matter Expert: provides technical and management leadership on major tasks; domain and expert technical knowledge; decisions may have critical project impact; may lead others.
  • Highly experienced with AWS; advanced networking, VPC, peering, and subnet experience.
  • GitLab CI experience; Terraform experience including writing custom modules and collaboration at scale; Ansible experience.
  • Proficient in Linux; SRE experience for a mid-to-large enterprise system.
  • Designing, implementing, and maintaining AWS cloud architecture; creating/maintaining implementation documentation.
  • Experience supporting RMF, ATO, cATO, and continuous monitoring; SIEM and security automation (familiarity with SOAR/IMS).
  • Minimum years of experience - 10 years of relevant experience., * Clearance: Active TS/SCI
  • Education: Advanced degree in a related technical field.
  • Certification: AWS Certified Security - Specialty, CCSP, CISSP, CKS, or CKA.
  • Experience and Knowledge:
  • General cloud architecture experience with Azure or GCP (a plus, not required); experience with Kubernetes and Docker.
  • Knowledge of SQL databases and coding skills (Java, Python, Go, C++); microservices architectures.
  • Security framework experience (RMF, DISA STIG, CIS Benchmarks); software engineering background.
  • Experience engineering SOAR/IMS and supporting Incident Response Teams (IRT); applying AI/ML to security automation.
  • Experience supporting software factory environments (Iron Bank, Big Bang); IL4/IL5/IL6 cloud environments. Benefits

Benefits & conditions

  • Generous cost sharing for medical insurance for the employee and dependents
  • 100% company paid dental insurance for employees and dependents
  • 100% company paid long-term and short-term disability insurance
  • 100% company paid vision insurance for employees and dependents
  • 401k plan with generous match and 100% immediate vesting
  • Competitive Pay
  • Generous paid leave and holiday package
  • Tuition and training reimbursement
  • Life and AD&D Insurance

About the company

In a world of technology, people make the difference. We believe if we invest in great people, then great things will happen. At AnaVation, we provide unmatched value to our customers and employees through innovative solutions and an engaging culture., AnaVation is seeking a Cloud Security Engineer to support one of our cybersecurity programs in our San Antonio office. In this position, the right candidate will lead zero trust engineering, interoperability, and modern security capability development across the Government enterprise. The Cloud Security Engineer will manage security systems and tools for cloud technologies, investigate and enhance existing cloud structures, and drives issue identification/resolution, integration, gap assessment, and continuous improvement, while providing flexible reach-back across the Government’s Cyber Assessment Roadmap., AnaVation is the leader in solving the most complex technical challenges for collection and processing in the U.S. Federal Intelligence Community. We are a US owned company headquartered in Chantilly, Virginia. We deliver groundbreaking research with advanced software and systems engineering that provides an information advantage to contribute to the mission and operational success of our customers. We offer complex challenges, a top-notch work environment, and a world-class, collaborative team. If you want to grow your career and make a difference while doing it, AnaVation is the perfect fit for you! AnaVation is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to sex, race, color, religion, national origin, disability, protected Veteran status, age, or any other characteristic protected by law.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on startup.jobs
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:53 min

Configuring dynamic proxy updates with Istio Pilot

Jan Mensch Jan Mensch · World Congress 2026 Europe

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann Chris Heilmann +2 · LIVE

6:21 min

Investigating push inefficiencies with upstream Git experts

Jonathan Creamer · Coffee With Developers

7:15 min

Installing Istio programmatically with bash scripts

Thomas Südbröcker · LIVE

4:37 min

Architecting single sign-on flows across multiple application domains

Gift Egwuenu · World Congress 2023

Videos

See all

Related articles

See all