> Markdown version of [/jobs/ext/658967-security-engineer](https://www.wearedevelopers.com/jobs/ext/658967-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** AALYRIA TECHNOLOGIES, INC. - **Location:** United States - **Experience:** Expert - **Salary:** $170,000.0 - $200,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Active Directory, Amazon Web Services, Microsoft Azure, Cloud Computing, Cloud Computing Security, Cloud Engineering, CompTIA Security+, Cyber Security, Linux, Domain Name System Security Extensions, Multi-Factor Authentication, Cryptographic Protocols, Federal Information Processing Standards (FIPS), Hardware Security Module, Identity and Access Management, Intrusion Detection Systems, Subnetting, Virtual Private Networks (VPN), Key Management, Network Security, Lightweight Directory Access Protocols (LDAP), Network Architecture, Network Diagrams, Network Monitoring, Network Segmentation, Peering, Public Key Infrastructure, Role-Based Access Control, Ansible, Zero Trust Network Access, Security Information and Event Management, Traffic Analysis, Software Vulnerability Management, Wide Area Networks, Data Logging, Cloud-native Network Functions (CNF), Google Cloud, Network Access Control, SARS Software Products, Cloud Platform System, In-Plane Switching (IPS), Firewalls (Computer Science), Amazon Virtual Private Cloud (VPC), Infrastructure Automation Frameworks, Information Technology, Fortinet, Hardware Infrastructure, CIS Benchmarks, Firewall Services Module, Terraform, Vulnerability Analysis - **Published:** June 26, 2026 - **Apply:** https://www.dice.com/job-detail/427f0c92-bed4-466c-9dd5-0ab5527fd5f9 ## About the Role * 5+ years of experience in cloud infrastructure security, network security, or IT systems engineering with a security focus * Hands-on experience securing cloud environments in Google Cloud Platform, AWS, or Azure, including networking, IAM, and logging controls (Google Cloud Platform strongly preferred) * Demonstrated experience designing and managing cloud network security controls: firewalls, security groups, VPC/VNet architecture, and traffic inspection * Proficiency with next-generation firewalls (e.g., Palo Alto, Fortinet, or cloud-native equivalents) including policy management and traffic analysis * Working knowledge of PKI concepts, certificate lifecycle management, and cryptographic protocols (TLS, mTLS, FIPS 140-2/3) * Hands-on experience implementing and managing IAM, PAM, MFA, RBAC, and SSO systems in enterprise or federal environments * Direct experience implementing technical controls for CMMC L2, FedRAMP, or NIST 800-171 compliance programs * Strong understanding of zero trust architecture principles and practical implementation across hybrid environments * Experience with SIEM platforms, log aggregation, and security monitoring for infrastructure and network event data * Excellent communication skills with ability to explain security architecture and compliance posture to both technical teams and leadership, * Active Secret or Top Secret clearance, or ability to obtain * Experience designing and operating PKI infrastructure at scale, including enterprise or government CA hierarchies * Familiarity with FIPS 140-2/140-3 validated cryptographic modules and their deployment in federal environments * Experience with cloud security platforms such as Wiz, AWS Security Hub, Google Cloud Platform Security Command Center, or Azure Defender * Proficiency with infrastructure-as-code tools (Terraform, Ansible) for automating security configurations and compliance baselines * Knowledge of DISA STIGs, CIS Benchmarks, and hardening standards for Linux, Windows, and cloud platforms * Experience with network access control (NAC), SD-WAN, or SASE platforms in enterprise or federal environments * Background in IT systems engineering, network engineering, or systems administration with a transition to security * Familiarity with hardware security modules (HSMs) and their integration into PKI or secrets management workflows * Security certifications such as CISSP, CCSP, CompTIA Security+, Google Cloud Platform Professional Cloud Security Engineer, or equivalent, * U.S. citizen or national * U.S. lawful permanent resident () * Refugee under 8 U.S.C. 1157 * Asylee under 8 U.S.C. 1158 (B) Be eligible to access export-controlled information without requiring an export authorization. (C) Be eligible and reasonably likely to obtain the necessary export authorization from the appropriate U.S. government agency. ## Description We are looking for an experienced Senior Security Engineer to join our team. The ideal candidate is a skilled infrastructure and cloud security professional who can own cloud and network security, compliance operations, and identity systems for our products and environments. You will serve as the technical security expert responsible for securing our cloud infrastructure, network architecture, and access control systems supporting defense and federal customers., This role requires a security professional with deep experience in cloud infrastructure, network security, and federal compliance frameworks. You will work closely with the Director of Security & IT to secure our cloud environments and systems in alignment with CMMC L2, FedRAMP, and NIST 800-171 requirements. Some of the kinds of responsibilities you may have are listed below., * Design, implement, and manage secure cloud networking architectures including VPCs, subnets, peering, and transit gateways across Google Cloud Platform, AWS, or Azure * Configure and maintain cloud-native firewall rules, security groups, network ACLs, and perimeter controls to enforce least-privilege traffic policies * Implement and manage cloud security posture management (CSPM) tooling and continuously remediate misconfigurations across cloud environments * Design and operate network segmentation and micro-segmentation strategies aligned with zero trust architecture principles * Manage and harden cloud IAM, including role definitions, service account policies, privileged access controls, and just-in-time access Firewall & Network Security * Manage next-generation firewall (NGFW) platforms, including policy development, rule lifecycle management, and traffic inspection configurations * Implement and maintain IDS/IPS, DNS security, and network monitoring solutions to detect and respond to threats * Design and enforce network access control (NAC) policies and segmentation for both cloud and on-premises environments * Conduct regular firewall rule reviews and access path analysis to identify and remediate overly permissive configurations PKI & Identity Management * Design, implement, and operate PKI infrastructure including certificate authorities, certificate lifecycle management, and trust store management * Manage certificates for device identity, mutual TLS (mTLS), VPN authentication, and code signing in compliance with federal requirements * Administer and enforce access control policies across identity providers (IdPs), directory services (Active Directory / LDAP), and SSO platforms * Implement and maintain multi-factor authentication (MFA), privileged access management (PAM), and role-based access control (RBAC) systems * Ensure cryptographic implementations meet FIPS 140-2/140-3 requirements and federal standards Compliance & Risk Management * Implement and maintain technical controls mapped to CMMC Level 2, FedRAMP, and NIST 800-171 control families * Develop and manage system security plans (SSPs), security assessment reports (SARs), and plans of action and milestones (POA&Ms) * Conduct continuous monitoring, log review, and evidence collection to support compliance audits and third-party assessments * Perform risk assessments and vulnerability management across cloud and on-premises infrastructure in accordance with NIST RMF * Maintain configuration baselines and enforce hardening standards (DISA STIGs, CIS Benchmarks) across systems and cloud resources Security Operations & Documentation * Maintain and tune SIEM integrations, security logging pipelines, and alerting rules for cloud and network infrastructure * Manage endpoint detection and response (EDR) and vulnerability scanning tools across the infrastructure fleet * Build and maintain automation for compliance evidence collection, configuration auditing, and security reporting * Document security architecture, network diagrams, access control matrices, and ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Transforming Education: A Journey from interactive Markdown to Remote-Labs](https://www.wearedevelopers.com/videos/941-transforming-education-a-journey-from-interactive-markdown-to-remote-labs) - [Dev & Test in the Cloud? Deploy your cloud environments with Ansible & Terraform](https://www.wearedevelopers.com/videos/1607-dev-test-in-the-cloud-deploy-your-cloud-environments-with-ansible-terraform) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [The best of two worlds - Bringing enterprise-grade Linux to the vehicle](https://www.wearedevelopers.com/videos/67-the-best-of-two-worlds-bringing-enterprise-grade-linux-to-the-vehicle) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)