AWS Cloud Security Engineer - CMMC Level 2 Compliance

Lotus USA
United States
about 2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Compensation
$112,597.0 - $135,600.0
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services Amazon Elastic Compute Cloud Amazon S3 Bash Shell Cloud Computing Security Cyber Security Information Systems DevOps Identity and Access Management Python (Programming Language) Network Diagrams Windows PowerShell
+15 more
Role-Based Access Control Zero Trust Network Access Security Information and Event Management Scripting Amazon Virtual Private Cloud (VPC) Cloudformation Information Technology Opsworks CIS Benchmarks Cloudwatch Terraform Splunk Virtual Private Clouds Security Orchestration, Automation & Response Vulnerability Analysis

Job description

We are seeking an experienced AWS Cloud Security Engineer to design, implement, maintain, and continuously improve secure AWS environments supporting Cybersecurity Maturity Model Certification (CMMC) Level 2 requirements. The ideal candidate will possess deep expertise in AWS cloud security, NIST SP 800-171 controls, FedRAMP concepts, security automation, and compliance evidence management. This role will work closely with Information Security, DevOps, Compliance, and Program Management teams to ensure AWS-hosted systems handling Controlled Unclassified Information (CUI) meet CMMC Level 2 requirements and are prepared for C3PAO assessments. AWS follows a shared responsibility model, meaning the engineer must implement and manage customer-owned security controls rather than relying solely on AWS infrastructure compliance. (Amazon Web Services, Inc.)

Key Responsibilities AWS Security Architecture

  • Design and maintain secure AWS environments supporting CMMC Level 2 workloads.
  • Implement AWS security best practices across:
  • IAM
  • VPC Security
  • EC2
  • S3
  • KMS
  • CloudTrail
  • Config
  • Security Hub
  • GuardDuty
  • Inspector
  • Support AWS GovCloud deployments when required.
  • Implement encryption for data at rest and in transit.

CMMC Level 2 Compliance

  • Implement and maintain controls aligned with:
  • CMMC 2.0 Level 2
  • NIST SP 800-171 Rev. 2
  • DFARS 252.204-7012
  • FedRAMP Moderate concepts
  • Assist with System Security Plans (SSP).
  • Maintain Plans of Action & Milestones (POA&M).
  • Develop control implementation statements and evidence packages.
  • Support internal audits and external C3PAO assessments.

Security Operations

  • Monitor cloud environments for threats and vulnerabilities.
  • Configure SIEM integrations and alerting.
  • Conduct security investigations and incident response activities.
  • Manage vulnerability scanning and remediation programs.

Identity & Access Management

  • Implement least-privilege access.
  • Configure MFA and privileged access controls.
  • Manage role-based access control (RBAC).
  • Review user access periodically.

Continuous Compliance & Automation

  • Build compliance monitoring solutions using:
  • AWS Config
  • Security Hub
  • CloudWatch
  • Lambda
  • Infrastructure as Code
  • Automate compliance reporting and evidence collection.
  • Develop security baselines and guardrails.

Documentation & Assessment Support

  • Maintain:
  • Security policies
  • Procedures
  • Network diagrams
  • Asset inventories
  • Risk assessments
  • Incident response documentation
  • Support Shared Responsibility Matrix/Customer Responsibility Matrix development and maintenance. (Amazon Web Services, Inc.)

Requirements

Do you have experience in Virtual Private Clouds?, Do you have a Bachelor’s degree?, * Bachelor’s degree in:

  • Cybersecurity
  • Computer Science
  • Information Systems
  • Related field

Experience

  • 5+ years of AWS cloud engineering or cloud security experience.
  • 3+ years supporting regulated environments.
  • Experience implementing NIST SP 800-171 controls.
  • Experience supporting CMMC readiness or certification initiatives.
  • Experience with Infrastructure as Code:
  • Terraform
  • CloudFormation
  • Experience managing security tools in AWS.

AWS Skills Strong experience with:

  • AWS IAM
  • Organizations
  • Control Tower
  • Security Hub
  • GuardDuty
  • Inspector
  • CloudTrail
  • Config
  • KMS
  • Systems Manager
  • VPC Security

Compliance Knowledge Strong understanding of:

  • CMMC 2.0 Level 2
  • NIST SP 800-171
  • NIST 800-53
  • DFARS
  • FedRAMP
  • Shared Responsibility Model in AWS environments (Amazon Web Services, Inc.)

Preferred Certifications AWS

  • AWS Certified Security - Specialty
  • AWS Certified Solutions Architect - Professional
  • AWS Certified Advanced Networking - Specialty

Security

  • CISSP
  • CCSP
  • CISM
  • Security+

Compliance

  • Certified CMMC Professional (CCP)
  • Certified CMMC Assessor (CCA) - Preferred

Desired Skills

  • CUI boundary design and management
  • AWS GovCloud experience
  • Security automation scripting (Python, PowerShell, Bash)
  • SIEM platforms (Splunk, Sentinel, ELK)
  • Zero Trust Architecture
  • Incident Response
  • Risk Management Framework (RMF)
  • Continuous Monitoring Programs

Success Metrics

  • Successful implementation of CMMC Level 2 controls.
  • Reduced compliance gaps and POA&M findings.
  • Audit-ready evidence collection and reporting.
  • Successful C3PAO assessment support.
  • Improved cloud security posture and continuous compliance monitoring.

Clearance Preference: Active Secret Clearance or ability to obtain one is highly desirable.

Pay: $112,596.82 - $135,600.47 per year

Experience:

  • AWS cloud engineering or cloud security: 5 years (Required)
  • CMMC readiness or certification initiatives: 5 years (Required)
  • NIST SP 800-171 controls: 5 years (Required)

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:23 min

Reviewing AWS infrastructure deployment configuration and planning

Devlin Duldulao · LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · World Congress 2026 Europe

6:51 min

Audience questions on cloud security and operational capacity

Steffen Heilmann · World Congress 2021

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

3:18 min

Scaling global network engineering through DevOps culture

Stuart Clark · LIVE

Videos

See all

Related articles

See all