> Markdown version of [/jobs/ext/3286074-principal-cloud-security-engineer](https://www.wearedevelopers.com/jobs/ext/3286074-principal-cloud-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Cloud Security Engineer - **Company:** Koniag Services, Inc. - **Location:** Washington, DC, United States - **Experience:** Expert - **Salary:** $150,000.0 - $190,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Systems Engineering, Microsoft Azure, Software as a Service, Cloud Computing, Cloud Computing Security, Cloud Engineering, Encodings, Cyber Security, Information Systems, Infrastructure as a Service (IaaS), Network Security, OAuth, OpenID, Platform as a Service (PAAS), Cloud Services, Zero Trust Network Access, Security Assertion Markup Language (SAML), Security Information and Event Management, Systems Architecture, Tripwire, Software Vulnerability Management, Google Cloud, SARS Software Products, Multi-Cloud, Infrastructure as Code (IaC), Cloudformation, SC Clearance, Containerization, Kubernetes, Information Technology, Cybercrime, Bicep, Microsoft Sentinel, RSA Archer Platform, Terraform, Splunk, Devsecops, Serverless Computing, Qualys, Security Orchestration, Automation & Response, Servicenow - **Published:** September 20, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=da92c103bd6053f8 ## About the Role Koniag Government Services is seeking an experienced Principal Cloud Security Engineer to join a dynamic team supporting cloud security architecture, implementation, and continuous monitoring across multiple cloud platforms. The ideal candidate is a technically proficient security professional with hands-on experience securing environments across Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform (GCP). This individual will be passionate about cybersecurity, committed to staying current with evolving threats and technologies, and capable of applying their expertise to solve complex, real-world security challenges in a federal government context. The ability to obtain or maintain an active Secret clearance is required to support our government customer., * Bachelor's degree in Computer Science, Information Systems, Cybersecurity, Systems Engineering, or a related field from an accredited college or university. (Master's degree preferred). * 8+ years of progressive professional experience in cybersecurity, cloud security engineering, network defense, or system architecture, with at least 5+ years dedicated to architecting and securing enterprise cloud environments. * Proven track record architecting and executing security controls across at least two major cloud service providers (AWS, Azure, GCP). * Deep expertise with federal security frameworks, including FISMA High/Moderate, FedRAMP, NIST SP 800-53 (Rev. 5), NIST SP 800-37 (RMF), and CMMC. * Active Secret clearance or higher (Top Secret preferred)., * Exceptional written, verbal, and presentation skills, with a proven ability to articulate complex cybersecurity risks and technical architectures to executive leadership, Authorizing Officials, and technical teams. * Advanced proficiency engineering and hardening enterprise infrastructure across AWS, Azure, and GCP (IaaS, PaaS, and SaaS models). * Hands-on expertise configuring and scaling enterprise tools including CSPM/CWPP suites, vulnerability management (e.g., Qualys, Tenable), file integrity monitoring (e.g., Tripwire), and enterprise SIEM/SOAR platforms (e.g., Splunk, Microsoft Sentinel). * Strong experience embedding security testing and guardrails into DevSecOps workflows using Infrastructure as Code (IaC) templates (Terraform, Bicep, CloudFormation) and CI/CD pipelines. * Deep understanding of zero-trust architecture, enterprise identity federation, privilege management, SAML 2.0, OAuth2, and OIDC across multi-tenant cloud environments. * Demonstrated ability to author, review, and defend complex SSPs, control worksheets, and POAMs to secure ATO approvals. * Proven ability to resolve critical technical bottlenecks, address emerging security threats, and drive security automation to reduce operational overhead. Desired Skills and Competencies: * Industry Certifications (One or more strongly preferred): * Executive/Architect: CISSP, CCSP, CISM. * Cloud Provider Specific: AWS Certified Security - Specialty, Microsoft Certified: Cybersecurity Architect Expert (SC-100), Microsoft Certified: Azure Security Engineer Associate (AZ-500), or Google Professional Cloud Security Engineer. * Master's degree in Cybersecurity, Information Assurance, or Computer Science. * Experience integrating security operations with GRC platforms (e.g., ServiceNow GRC, eMASS, CSAM). * Expertise securing containerized workloads and orchestration systems (Kubernetes, EKS, AKS, GKE) and serverless deployment models. * Applied knowledge of NIST SP 800-207 Zero Trust Architecture principles and implementation strategies across hybrid federal enterprises. ## Description The Principal Cloud Security Engineer will serve as the lead technical authority and SME for cloud security architecture, governance, and advanced threat defense across multi-cloud enterprise environments, including AWS, Microsoft Azure, and Google Cloud Platform (GCP). In this leadership role, you will define the multi-cloud security vision, architect complex security frameworks, drive tool selection and integration, and ensure robust security postures that align with federal compliance mandates and agency risk tolerances. As a strategic technical lead, the Principal Engineer will bridge high-level enterprise risk management with hands-on engineering execution. You will mentor engineering teams, partner with agency leadership and System Owners, and lead Assessment and Authorization (A&A) strategies to maintain continuous authorization to operate (ATO) in high-stakes federal cloud environments. Principal responsibilities will include but are not limited to: * Lead the design, engineering, and execution of scalable, resilient multi-cloud security solutions across AWS, Azure, and GCP that address complex threat vectors, zero-trust paradigms, and stringent federal mandates. * Drive the strategic evaluation, selection, architectural integration, and optimization of cloud-native and enterprise third-party security platforms (CSPM, CWPP, CIEM, SIEM, and Vulnerability Management). * Direct the configuration, enforcement, and integration of cloud-native security frameworks (e.g., AWS Security Hub/Config, Azure Defender/Policy, GCP Security Command Center Premium) with enterprise security operations centers (SOC). * Pioneer "Security as Code" initiatives by integrating automated security controls, guardrails, compliance scanning, and vulnerability checks directly into Infrastructure as Code (IaC) and CI/CD pipelines. * Oversee the creation, validation, and maintenance of comprehensive Assessment and Authorization (A&A) packages, including System Security Plans (SSPs), Security Assessment Reports (SARs), and continuous authorization artifacts. * Lead security impact assessments for enterprise-level system architectural changes, evaluating complex risks and defining remediation strategies without impacting operational tempo. * Establish proactive continuous monitoring, threat hunting, and incident handling protocols across multi-cloud environments utilizing integrated SIEM, SOAR, and telemetry platforms (e.g., Splunk, Sentinel, Qualys). * Serve as the principal technical liaison to agency leadership, Authorizing Officials (AOs), CISOs, and cross-functional engineering leads to align technical security strategies with mission objectives. * Mentor senior and mid-level security engineers, establishing operational guidelines, standard operating procedures (SOPs), and engineering baselines across the organization. ## Related Videos - [Back(end) to the Future: Embracing the continuous Evolution of Infrastructure and Code](https://www.wearedevelopers.com/videos/440-back-end-to-the-future-embracing-the-continuous-evolution-of-infrastructure-and-code) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Monoskope: Developer Self-Service Across Clusters](https://www.wearedevelopers.com/videos/329-monoskope-developer-self-service-across-clusters) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Advanced Cypress: custom assertions and tasks](https://www.wearedevelopers.com/videos/790-advanced-cypress-custom-assertions-and-tasks) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)