> Markdown version of [/jobs/ext/3545708-cloud-security-engineer](https://www.wearedevelopers.com/jobs/ext/3545708-cloud-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cloud Security Engineer - **Company:** General Dynamics Information Technology - **Location:** Rockville, MD, United States - **Experience:** Expert - **Salary:** $124,093.0 - $149,500.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Bash Shell, Biometrics, Cloud Computing Security, Configuration Management, Cyber Security, Domain Name System (DNS), Hypertext Transfer Protocols (HTTP), Identity and Access Management, Intrusion Detection and Prevention, Virtual Private Networks (VPN), Information Systems Security Architecture Professional, Python (Programming Language), Network Security, Network Troubleshooting, Network Segmentation, Performance Tuning, Public Key Infrastructure, Software Tools, Ansible, Zero Trust Network Access, Security Information and Event Management, Systems Integration, TCP/IP, Software Vulnerability Management, Workflow Management Systems, Data Logging, Scripting, Transport Layer Security, Large Language Models, Agentic-AI, Infrastructure Automation Frameworks, Palo Alto Networks, Hardware Infrastructure, Terraform, Prisma Cloud Platform, Devsecops, Security Orchestration, Automation & Response - **Published:** October 1, 2026 - **Apply:** https://gdit.wd5.myworkdayjobs.com/External_Career_Site/job/USA-MD-Rockville/Sr-Cloud-Security-Engineer_RQ228988-1/apply ## About the Role · Bachelor's degree and 5+ years of hands-on cloud security engineering experience (or, 8+ years of of experience in cloud security engineering in lieu of degree) · Demonstrated experience designing, deploying, managing, and troubleshooting AWS security services and Palo Alto Networks firewalls. · Experience securing hybrid on-premises/AWS environments. · Experience with Infrastructure as Code, scripting and security automation. · Strong understanding of networking and security fundamentals, including TCP/IP, DNS, HTTP/HTTPS, network segmentation, VPNs, TLS/PKI, encryption, IAM, Zero Trust, and threat detection/prevention. · Experience troubleshooting complex security and network issues. · Must be able to obtain and maintain a Public Trust. Preferred: · Experience with Palo Alto Panorama, Prisma Cloud, and/or related Palo Alto technologies. · Experience implementing centralized AWS security architectures in multi-account environments. · Experience with Terraform, Ansible, Python, Bash, APIs, or other infrastructure/security automation technologies. · Experience integrating security controls with SIEM/SOAR platforms. · Experience with CI/CD pipelines and DevSecOps security practices. · Experience with container/Kubernetes security and vulnerability management. · Experience implementing security and compliance controls aligned with NIST, FISMA, FedRAMP, or similar frameworks. · Experience using LLMs, AI agents, or generative AI tools to automate engineering, security, or compliance workflows. · Palo Alto Networks (e.g., PCNSE) and/or AWS security/architecture certifications, or equivalent practical experience. · Ability to independently own and resolve complex technical problems. #GDITFedHealthJobs Work Requirements Years of Experience 5 + years of related experience * may vary based on technical training, certification(s), or degree Certification Travel Required Less than 10% ## Description Cloud & Network Security · Design and implement security controls for AWS multi-account and hybrid-cloud environments. · Deploy and manage AWS security capabilities, including Network Firewall, WAF, Shield, Security Groups/NACLs, GuardDuty, Security Hub, CloudTrail, Config, IAM/Identity Center, KMS, VPC, and Transit Gateway controls. · Design secure connectivity, segmentation, and security boundaries between AWS and on-premises environments. · Design, deploy, manage, and optimize Palo Alto Networks next-generation firewalls, including security policies, NAT, routing, VPN, application controls, threat prevention, and URL filtering. · Manage firewall high availability, upgrades, lifecycle, capacity, and policy optimization. Security Architecture & Automation · Develop secure, resilient architectures spanning AWS and on-premises infrastructure using defense-in-depth and Zero Trust principles. · Modernize environment to leverage Infrastructure as Code using technologies such as Terraform. · Automate security operations, compliance reporting, configuration management, and policy enforcement using APIs, scripting, DevSecOps tooling, and AI-assisted engineering tools. · Support security controls and evidence mapping aligned with frameworks such as NIST 800-53/800-171, FedRAMP, and FISMA. · Evaluate existing security architectures and identify improvements in security, resiliency, scalability, performance, and operational efficiency. Operations & Incident Response · Troubleshoot complex cloud, network, firewall, and application-connectivity issues. · Support security incidents, production outages, and root-cause analysis. · Develop monitoring, logging, alerting, dashboards, runbooks, and engineering standards. · Perform performance tuning, capacity planning, and security infrastructure lifecycle management. · Participate in on-call or escalation support as required. ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Dev & Test in the Cloud? Deploy your cloud environments with Ansible & Terraform](https://www.wearedevelopers.com/videos/1607-dev-test-in-the-cloud-deploy-your-cloud-environments-with-ansible-terraform) - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)