> Markdown version of [/jobs/ext/3275967-cloud-security-engineer](https://www.wearedevelopers.com/jobs/ext/3275967-cloud-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cloud Security Engineer - **Company:** AnaVation, LLC - **Location:** San Antonio, TX, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Java (Programming Language), Artificial Intelligence, Amazon Web Services, Microsoft Azure, C++ (Programming Language), Cloud Computing, Cloud Computing Security, Cloud Engineering, Cyber Security, Databases, Linux, Subnetting, Python (Programming Language), Network Segmentation, Peering, Ansible, Zero Trust Network Access, Security Information and Event Management, Software Engineering, Software Factory, Software Vulnerability Management, Data Logging, Enterprise Software Applications, Okta, Istio, Amazon Virtual Private Cloud (VPC), Gitlab, Git, Gitlab-ci, Kubernetes, Information Technology, CIS Benchmarks, Software Coding, Terraform, Devsecops, Docker, Security Orchestration, Automation & Response, Golang, Microservices - **Published:** September 17, 2026 - **Apply:** https://startup.jobs/cloud-security-engineer-anavation-10095879 ## About the Role * Clearance: U.S. Citizen, current TS/SCI; current CI Polygraph * Education: Bachelor's degree in Cybersecurity, Computer Science, Cloud Computing, IT, or related technical field. * Certification: DoD 8140/8570 IAT Level II and an AWS certification. * Location: Full-time on-site in San Antonio, TX. * Experience and knowledge: * Subject Matter Expert: provides technical and management leadership on major tasks; domain and expert technical knowledge; decisions may have critical project impact; may lead others. * Highly experienced with AWS; advanced networking, VPC, peering, and subnet experience. * GitLab CI experience; Terraform experience including writing custom modules and collaboration at scale; Ansible experience. * Proficient in Linux; SRE experience for a mid-to-large enterprise system. * Designing, implementing, and maintaining AWS cloud architecture; creating/maintaining implementation documentation. * Experience supporting RMF, ATO, cATO, and continuous monitoring; SIEM and security automation (familiarity with SOAR/IMS). * Minimum years of experience - 10 years of relevant experience., * Clearance: Active TS/SCI * Education: Advanced degree in a related technical field. * Certification: AWS Certified Security - Specialty, CCSP, CISSP, CKS, or CKA. * Experience and Knowledge: * General cloud architecture experience with Azure or GCP (a plus, not required); experience with Kubernetes and Docker. * Knowledge of SQL databases and coding skills (Java, Python, Go, C++); microservices architectures. * Security framework experience (RMF, DISA STIG, CIS Benchmarks); software engineering background. * Experience engineering SOAR/IMS and supporting Incident Response Teams (IRT); applying AI/ML to security automation. * Experience supporting software factory environments (Iron Bank, Big Bang); IL4/IL5/IL6 cloud environments. Benefits ## Description Position Responsibilities: This position sets the engineering direction for the Government's zero trust and cloud security modernization, translating roadmap objectives into deployed, measurable capability., * Lead zero trust engineering and interoperability initiatives, future-proofing implementations as tools and requirements evolve. * Design, implement, and maintain AWS cloud architecture using Terraform (including custom modules) and Ansible. * Administer relevant cloud infrastructure-level consoles (e.g., AWS) and secure cloud services and accounts; apply advanced networking, VPC, peering, and subnet design. * Support the SIEM, SOAR, Incident Management System (IMS), and Incident Response Team (IRT) roadmap, engineering, and integration. * Architect logging, monitoring, and telemetry, coordinating delivery with the Cyber Security Service Provider (CSSP). * Advance security automation and automated evidence collection to increase inheritance and continuous monitoring maturity. * Provide flexible SME support and reach-back across DevSecOps automation, supply chain security, enterprise vulnerability management, and AI. * Provide updates to the Cyber Assessment Roadmap; create/maintain documentation and brief technical and non-technical stakeholders. * Collaborate with ISSMs, ISSEs, Value Stream engineers, COT, CPT, and Government stakeholders using tools like git. * Support Zero Trust enforcement, cloud security controls, and Infrastructure as Code security across mission environments. * Maintain and validate A&A control evidence in eMASS (control implementation, SIAs, SRCs, POA&Ms) supporting continuous monitoring and cATO readiness. * Architect and integrate an enterprise SIEM ingesting logs from AWS (VPC, EKS, CloudTrail), Okta, Istio, GitLab, and host logs (systemd, audit), with dashboards for runtime monitoring, defense, and forensics. * Enforce Zero Trust through ICAM integration and micro-segmentation validation and manage enterprise security tooling. ## Related Videos - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [Rate-limiting using eBPF and Istio: How to protect your SaaS customers from themselves](https://www.wearedevelopers.com/videos/100220-rate-limiting-using-ebpf-and-istio-how-to-protect-your-saas-customers-from-themselves) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Git for Code Reviews](https://www.wearedevelopers.com/videos/429-git-for-code-reviews) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)