AWS Cloud Engineer

CDIT

Norfolk (VA)

On-site

USD 150,000 - 190,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

CDIT in Norfolk, VA, seeks an AWS Cloud Engineer (Expert) to own architecture, engineering, and security of AWS GovCloud-based infrastructure for the NMMES program.

Senior, hands-on role; mentor engineers; align cloud foundation with DoD SRG/RMF and NIST controls; emphasize security, cost efficiency, and compliance.

You will implement multi-account environments, IaC, CI/CD, and incident response, collaborating with AI, data, and application teams to deliver a resilient platform.

Qualifications

  • 7+ years of IT experience with 5+ years designing/operating production AWS environments.
  • Active DoD Secret clearance at time of hire.
  • Experience across DoD RMF, NIST SP 800-53, and DoD SRG requirements.
  • Strong IaC skills with Terraform and/or CloudFormation/CDK.
  • Experience in AWS GovCloud(US) or other regulated cloud environments.
  • Practical scripting in Python, Bash, or PowerShell for automation.
  • Knowledge of containerization (Docker) and orchestration (ECS/EKS/Kubernetes).

Responsibilities

  • Design and implement multi-account AWS GovCloud environments using Organizations, Control Tower, landing zones, and account vending automation.
  • Author and maintain IaC with Terraform and/or CloudFormation/CDK; enforce changes via Git workflows.
  • Architect networking (VPC, Transit Gateway, DirectConnect, PrivateLink), identity (IAM) and data-protection controls (KMS, S3 encryption, Macie).
  • Build and operate CI/CD pipelines (CodePipeline, CodeBuild, GitHub Actions, GitLab CI) for containerized/serverless workloads.
  • Implement observability with CloudWatch, X-Ray, Splunk, and Datadog for Navy monitoring/audit needs.
  • Support A&A/RMF processes: diagrams, control statements, and evidence aligned to NIST SP 800-53 and DoD SRG.
  • Optimize cost/performance via right-sizing, Savings Plans.
  • Lead incident response and root-cause analysis; improve runbooks and automated remediation.
  • Collaborate with AI/data/application teams to land workloads on a compliant, resilient platform.

Skills

AWS
VPC
Terraform
CloudFormation
Python
Bash
PowerShell
Git
CI/CD
Security
DoD RMF
KMS
S3

Education

Bachelor's degree in Computer Science, Information Systems, Engineering

Tools

Terraform
CloudFormation
CDK
CodePipeline
CodeBuild
GitHub Actions
GitLab CI
Docker
ECS/EKS
CloudWatch
Splunk
Datadog

Job description

Norfolk, United States | Posted on 07/28/2026

The AWS Cloud Engineer (Expert) will lead the architecture, engineering, and operational stewardship of AWS-based infrastructure supporting the NMMES program in Norfolk, VA. The role owns the cloud foundation on which NMMES applications, data pipelines, and AI/ML workloads are built, with a strong emphasis on security, cost efficiency, and compliance with DoD Cloud Computing Security Requirements Guide (SRG) Impact Levels.

This is a senior, hands-on engineering role. The engineer will translate Navy mission requirements into well-architected, automated, and repeatable cloud solutions in AWS GovCloud(US), and will mentor mid-level engineers on infrastructure-as-code, resilience, and secure DevSecOps practices.

Key Responsibilities
  • Design and implement multi-account AWS GovCloud environments using AWS Organizations, Control Tower patterns, landing zones, and account-vending automation.
  • Author and maintain infrastructure-as-code using Terraform and/or AWS CloudFormation/CDK; enforce change control through Git-based workflows.
  • Architect networking (VPC, Transit Gateway, DirectConnect, PrivateLink), identity (IAM, IAM Identity Center, federation with DoD identity providers), and data-protection controls (KMS, S3 encryption, Macie).
  • Build and operate CI/CD pipelines (CodePipeline, CodeBuild, GitHub Actions, GitLab CI) supporting containerized and serverless workloads.
  • Implement observability using CloudWatch, X-Ray, and third-party tooling (e.g., Splunk, Datadog) to meet Navy monitoring and audit requirements.
  • Support the Assessment & Authorization (A&A) / RMF process: produce architecture diagrams, control implementation statements, and evidence artifacts aligned to NIST SP 800-53 and DoD SRG.
  • Optimize cost and performance through right-sizing, reserved capacity / Savings Plans, and workload placement analysis.
  • Lead incident response and root-cause analysis for cloud-hosted workloads; drive continuous improvement of runbooks and automated remediation.
  • Partner with the AI, data, and application teams to ensure their workloads land on a compliant, resilient, and cost-effective platform.
Required Qualifications
  • 7+ years of professional IT experience, with 5+ years designing and operating production AWS environments.
  • Demonstrated expertise across core AWS services: VPC,EC2, S3, IAM, KMS, RDS, Lambda, ECS/EKS, CloudWatch, and CloudTrail.
  • Strong infrastructure-as-code skills with Terraform(preferred) and/or CloudFormation/CDK.
  • Proven experience in AWS GovCloud(US) or another regulated cloud environment (FedRAMP High, DoD IL4/IL5).
  • Practical scripting proficiency in Python, Bash, or PowerShell for automation and tooling.
  • Working knowledge of DoD RMF, NIST SP 800-53, and DoD Cloud Computing SRG.
  • Experience with containerization (Docker) and orchestration (ECS, EKS, or Kubernetes).
  • Active DoD Secret clearance at time of hire.
Preferred Qualifications
  • Prior experience supporting Navy, NAVSEA, Marine Corps, or other DoD programs in Norfolk / Hampton Roads.
  • Familiarity with Platform One, Iron Bank, or other DoD DevSecOps reference implementations.
  • Experience integrating with DoD PKI, CAC-based authentication, and ICAM services.
Education

Bachelor’s degree in Computer Science, Information Systems, Engineering, or a related technical field. Additional years of directly relevant experience may substitute for the degree in accordance with contract labor-category definitions.

Certifications
Required
  • DoD 8570 / 8140 IAT Level II baseline certification (Security+ CE minimum); IAT Level III (CISSP, CASP+, or CCSP) required for privileged access to accredited systems.
Preferred
  • AWS Certified Security – Specialty
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

AWS Cloud Technical Subject Matter Expert (SME)
AWS Cloud Technical Subject Matter Expert (SME)

Nucorevision, Inc • Norfolk (VA)

On-site
USD 150,000 - 190,000
Senior Application Developer/Engineer (AWS & DevOps)
Senior Application Developer/Engineer (AWS & DevOps)

Nucorevision, Inc • Norfolk (VA)

On-site
USD 120,000 - 150,000
Senior AWS GovCloud Engineer – DoD Security
Senior AWS GovCloud Engineer – DoD Security

CDIT • Norfolk (VA)

On-site
USD 150,000 - 190,000
AWS Cloud Solutions / Engineer
AWS Cloud Solutions / Engineer

Thorben Consulting, LLC • Arlington (VA)

On-site
USD 120,000 - 150,000
Employer paid health insurance
401K retirement plan with employer match
Unlimited paid time off
System Engineer (Cloud)
System Engineer (Cloud)

By Light Professional IT Services • Scott Air Force Base (IL)

On-site
USD 140,000 - 190,000
AWS Cloud Engineer
AWS Cloud Engineer

Saic • Shiloh (IL)

On-site
USD 120,000 - 160,000
Potential sign-on bonus
Competitive salary range
Chief Cloud Architect & Infrastructure Subject Matter Expert
Chief Cloud Architect & Infrastructure Subject Matter Expert

UIC Arctic Response Services, LLC • Arlington (VA)

On-site
USD 140,000 - 190,000
Cloud Engineer
Cloud Engineer

Endurion • Tampa (FL)

On-site
USD 95,000 - 140,000
AWS Cloud Engineer
AWS Cloud Engineer

Aqua IT • O'Fallon (IL)

On-site
USD 100,000 - 130,000
000 – Senior Azure Cloud Engineer – Entra ID
000 – Senior Azure Cloud Engineer – Entra ID

Defense Engineering Inc. • Fort Belvoir (VA)

On-site
USD 140,000 - 190,000