AWS Cloud Security Engineer - CMMC Level 2 Compliance
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+15 more
Job description
We are seeking an experienced AWS Cloud Security Engineer to design, implement, maintain, and continuously improve secure AWS environments supporting Cybersecurity Maturity Model Certification (CMMC) Level 2 requirements. The ideal candidate will possess deep expertise in AWS cloud security, NIST SP 800-171 controls, FedRAMP concepts, security automation, and compliance evidence management. This role will work closely with Information Security, DevOps, Compliance, and Program Management teams to ensure AWS-hosted systems handling Controlled Unclassified Information (CUI) meet CMMC Level 2 requirements and are prepared for C3PAO assessments. AWS follows a shared responsibility model, meaning the engineer must implement and manage customer-owned security controls rather than relying solely on AWS infrastructure compliance. (Amazon Web Services, Inc.)
Key Responsibilities AWS Security Architecture
- Design and maintain secure AWS environments supporting CMMC Level 2 workloads.
- Implement AWS security best practices across:
- IAM
- VPC Security
- EC2
- S3
- KMS
- CloudTrail
- Config
- Security Hub
- GuardDuty
- Inspector
- Support AWS GovCloud deployments when required.
- Implement encryption for data at rest and in transit.
CMMC Level 2 Compliance
- Implement and maintain controls aligned with:
- CMMC 2.0 Level 2
- NIST SP 800-171 Rev. 2
- DFARS 252.204-7012
- FedRAMP Moderate concepts
- Assist with System Security Plans (SSP).
- Maintain Plans of Action & Milestones (POA&M).
- Develop control implementation statements and evidence packages.
- Support internal audits and external C3PAO assessments.
Security Operations
- Monitor cloud environments for threats and vulnerabilities.
- Configure SIEM integrations and alerting.
- Conduct security investigations and incident response activities.
- Manage vulnerability scanning and remediation programs.
Identity & Access Management
- Implement least-privilege access.
- Configure MFA and privileged access controls.
- Manage role-based access control (RBAC).
- Review user access periodically.
Continuous Compliance & Automation
- Build compliance monitoring solutions using:
- AWS Config
- Security Hub
- CloudWatch
- Lambda
- Infrastructure as Code
- Automate compliance reporting and evidence collection.
- Develop security baselines and guardrails.
Documentation & Assessment Support
- Maintain:
- Security policies
- Procedures
- Network diagrams
- Asset inventories
- Risk assessments
- Incident response documentation
- Support Shared Responsibility Matrix/Customer Responsibility Matrix development and maintenance. (Amazon Web Services, Inc.)
Requirements
Do you have experience in Virtual Private Clouds?, Do you have a Bachelor’s degree?, * Bachelor’s degree in:
- Cybersecurity
- Computer Science
- Information Systems
- Related field
Experience
- 5+ years of AWS cloud engineering or cloud security experience.
- 3+ years supporting regulated environments.
- Experience implementing NIST SP 800-171 controls.
- Experience supporting CMMC readiness or certification initiatives.
- Experience with Infrastructure as Code:
- Terraform
- CloudFormation
- Experience managing security tools in AWS.
AWS Skills Strong experience with:
- AWS IAM
- Organizations
- Control Tower
- Security Hub
- GuardDuty
- Inspector
- CloudTrail
- Config
- KMS
- Systems Manager
- VPC Security
Compliance Knowledge Strong understanding of:
- CMMC 2.0 Level 2
- NIST SP 800-171
- NIST 800-53
- DFARS
- FedRAMP
- Shared Responsibility Model in AWS environments (Amazon Web Services, Inc.)
Preferred Certifications AWS
- AWS Certified Security - Specialty
- AWS Certified Solutions Architect - Professional
- AWS Certified Advanced Networking - Specialty
Security
- CISSP
- CCSP
- CISM
- Security+
Compliance
- Certified CMMC Professional (CCP)
- Certified CMMC Assessor (CCA) - Preferred
Desired Skills
- CUI boundary design and management
- AWS GovCloud experience
- Security automation scripting (Python, PowerShell, Bash)
- SIEM platforms (Splunk, Sentinel, ELK)
- Zero Trust Architecture
- Incident Response
- Risk Management Framework (RMF)
- Continuous Monitoring Programs
Success Metrics
- Successful implementation of CMMC Level 2 controls.
- Reduced compliance gaps and POA&M findings.
- Audit-ready evidence collection and reporting.
- Successful C3PAO assessment support.
- Improved cloud security posture and continuous compliance monitoring.
Clearance Preference: Active Secret Clearance or ability to obtain one is highly desirable.
Pay: $112,596.82 - $135,600.47 per year
Experience:
- AWS cloud engineering or cloud security: 5 years (Required)
- CMMC readiness or certification initiatives: 5 years (Required)
- NIST SP 800-171 controls: 5 years (Required)
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on indeed.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Best Paying Jobs in Technology
7 Cloud Computing Trends Coming in 2025 for Developers
Highest Paying Tech Companies for Developers
DevOps Engineer Salary [2023]