Cloud Security Engineer (Security Builder), AWS GovCloud Program
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
We are hiring a Cloud Security Engineer to write the guardrails that keep an AWS GovCloud environment safe. You will work at the organization level, where a single policy decision ripples across every account beneath it. One day you are authoring service control policies and resource control policies; the next you are designing KMS key policies, tightening IAM permissions boundaries, and clearing Security Hub findings before they pile up. The role has a documentation half too, and it carries just as much weight: the SSP-aligned PPSM evidence, the POAMs, and the Body of Evidence artifacts you produce are what move the ATO package forward. If you are equally at home in the console and in the control narrative, you will do well here.
What you’ll do
- Author and maintain service control policies (SCPs) and resource control policies (RCPs) at the AWS Organizations level.
- Design and enforce IAM permissions boundaries that keep account access scoped to least privilege.
- Build and tune AWS Config rules to detect and prevent drift from the security baseline.
- Design KMS key policies that hold up to DoD encryption and key management expectations.
- Triage and remediate Security Hub findings, then close the loop so they stay closed.
- Produce SSP-aligned PPSM evidence packages, POAMs, and Body of Evidence artifacts that feed the ATO package.
- Partner with the platform and networking teams so the guardrails protect the environment without blocking delivery.
Requirements
Do you have experience in Public Cloud?, * Active Secret clearance.
- U.S. citizenship (required for this program).
- Hands-on experience writing security guardrails at the AWS Organizations level, including SCP and RCP authoring.
- Strong command of IAM permissions boundaries, AWS Config rules, KMS key policy design, and Security Hub remediation.
- Experience producing ATO documentation, including SSP-aligned PPSM evidence, POAMs, and Body of Evidence artifacts.
- Ability to work a hybrid schedule in the Arlington, VA area.
Nice to have
- Hands-on Landing Zone Accelerator experience, especially the custom policy and IAM files.
- Familiarity with IL5 and CC SRG control mapping., * Do you currently hold an active Secret clearance or higher?
- Are you a U.S. citizen?
- How many years of hands-on cloud security engineering experience do you have?
- Have you personally authored service control policies (SCPs) or resource control policies (RCPs) at the AWS Organizations level?
- Do you have hands-on experience with IAM permissions boundaries, AWS Config rules, KMS key policy design, and Security Hub remediation?
- Have you produced ATO documentation such as SSP-aligned PPSM evidence, POAMs, or Body of Evidence artifacts?
- Can you work a hybrid schedule in the Arlington, VA area?
Work Location: Hybrid remote in Washington, DC 20301
Benefits & conditions
$70 - $90 an hour - Full-time, Contract
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on indeed.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
What Are The Top Skills Required For Azure Developers?
7 Cloud Computing Trends Coming in 2025 for Developers
Why Attend a Developer Event in 2026?
Dev Digest 134 - Where pixels sing?