AWS Cloud Engineer (Zero Trust Focus)

Socket.dev

Arlington (VA)

On-site

USD 120,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Nakupuna is seeking an AWS Cloud Engineer with Zero Trust expertise to manage AWS GovCloud environments and Windows Server 2022. The role focuses on secure cloud operations and alignment with DoDIN security posture, guiding DoD customers toward a Zero Trust posture.

Based in Arlington, VA, the position is on-site with some travel and requires Top-Secret clearance. Responsibilities include deploying CDK-based infrastructure, Lambda data pipelines, and implementing least-privilege access within

Qualifications

  • Bachelor’s degree in a STEM field or equivalent military/work experience.
  • Minimum of 3 years of relevant professional experience in systems administration and cloud operations.
  • Active DoD security clearance at Top Secret level required.
  • Experience supporting DoD IT environments preferred and familiarity with Agile/JIRA is desirable.

Responsibilities

  • Provision and configure AWS services using CDK IaC.
  • Provision and configure data and log pipelines using Lambda, Fire Hose, Glue, and related services.
  • Write and debug AWS Lambda functions to automate operational and security processes.
  • Implement and maintain Zero Trust architecture, including least-privilege access, within AWS environments.

Skills

AWS CDK
Python scripting
High availability systems
DoD IT security
Zero Trust
AWS Lambda
AWS GovCloud

Education

Bachelor's degree in STEM or related field

Tools

AWS Config
Systems Manager
Patch Manager

Job description

Overview

Nakupuna is looking for an Amazon Web Services (AWS) Cloud Engineer with knowledge of Zero Trust. The Amazon Web Services (AWS) Cloud Engineer is primarily responsible for operations within an AWS GovCloud and Microsoft Windows Server 2022 environment. This role will provide support and expertise for the management and administration of AWS services supporting Zero Trust organizational goals. In addition, the AWS Cloud Engineer ensures compliance of current and planned system architectures to prevent any adverse impact on the Department of Defense Information Network (DoDIN) security posture. Specifically, this role will play a key role in overseeing, advising, and guiding the customer towards a Zero Trust posture.

Responsibilities
  • Provision and configure AWS services using AWS Cloud Development Kit (CDK) Infrastructure as Code (IAC)
  • Provision and configure data and log transformation pipelines using AWS Lambda, FireHose, Glue, and other services.
  • Build log mappings from application-native formats to OCSP standardized log format with the aid of AI tools
  • Writing and debug AWS Lambda functions to automate operational and security processes.
  • Lead discovery and prototyping efforts using artificial intelligence and machine learning services available in AWS, such as Amazon SageMaker, Comprehend, and Recognition.
  • Identify, evaluate, and recommend emerging AWS-native AI/ML tools and services to enhance automation, analytics, and operational efficiency.
  • Evaluate and integrate Zero Trust security frameworks into existing and new AWS system architectures.
  • Implement and maintain Zero Trust Architecture principles, including least-privilege access, continuous authentication, and micro-segmentation within AWS environments.
  • Collaborate with project stakeholders and cross-functional teams to manage cloud-related initiatives from planning through execution.
  • Responsible for performing regular operational tasks in the AWS Console including creating new Amazon Elastic Compute Cloud (Amazon EC2) instances, debugging connectivity, provisioning users, managing credentials, configuring backup policies, and reviewing logs.
  • Provide programmatic support including coordination, scheduling, budget tracking, and oversight of AWS infrastructure initiatives to ensure alignment with organizational objectives.
  • Responsible for configuring and managing EC2 management tools like AWS Config, Systems Manager, and Patch Manager.
  • Support DevSecOps implementation and team integration including automated testing, release pipelines, automated deployment, with AWS CodePipeline and its related components.
  • Supports migration to serverless AWS offerings with the goal of reducing operational footprint on EC2 instances.
  • Provides technical support and troubleshooting assistance.
  • Responsible for system security hardening per DoD Security and Technical Implementation Guidelines (STIG) and providing required security documentation.
  • Provide STIG guidance and assist in configuring computer and network devices.
  • Supports Information Assurance Vulnerability Alert (IAVA) patching requirements for servers and systems.
  • Develop and maintain documentation including Standard Operating Procedures (SOPs).
  • Perform upgrades to server operating systems and applications.
  • Assist technicians to maintain existing AWS Gov Cloud installation.
Qualifications

Skills/Qualifications: Excellent technical, organizational, decision‑making, analytical, and planning skills. Effective communicator who takes initiative and the ability to adapt to dynamic environments. In addition, the following technical skills are needed:

  • Experience developing AWS solutions using AWS Cloud Development Kit (CDK)
  • Experience writing and debugging Python scripts with Object‑Oriented Programming experience a plus
  • Experience with design and development of high availability virtual platforms.
  • In-depth performance monitoring of virtual system(s).
  • Must excel at system documentation, to include in-depth system configuration, topology, and development of standard operating procedures.

Education/Experience:
• Bachelor’s degree in a STEM field from an accredited institution, or equivalent years of related work or military experience.
• Minimum of 3 years of relevant professional experience, including systems administration and cloud operations.
• Experience supporting DoD IT environments preferred.
• Experience using Agile methodologies and ticketing systems such as JIRA is desirable.

Certification

Required:
• Active IAT II Certification which may include CompTIA Advanced Security Practitioner (CASP+), CompTIA Cybersecurity Analyst (CySA+), Certified Information Systems Security Professional (CISSP), or CompTIA Security+.
• AWS certification (e.g., AWS Certified AI Practitioner, AWS Certified Cloud Practitioner, AWS SysOps Administrator Associate, AWS Solutions Architect Associate)

Clearance Requirements
  • Must currently have at least a Top‑Secret level security clearance.
  • Must be a U.S. citizen.
Work Location

Position is based in Arlington, VA.
Preferred: on‑site three (3) days per week. Will consider fewer days on‑site for the correct candidate.
Occasional travel (1–2 weeks per year) within the Continental U.S. or to Hawaii may be required.
This position may require working outside of normal business hours, including evenings and weekends, to meet operational or project demands.

Physical Requirements
  • Ability to perform repetitive motions with the hands, wrists, and fingers.
  • Ability to engage in and follow audible communications in emergency situations.
  • Ability to sit for prolonged periods at a desk and working on a computer.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

AWS Cloud Engineer (Zero Trust Focus)
AWS Cloud Engineer (Zero Trust Focus)

Nakupuna Consulting • Arlington (VA)

On-site
USD 115,000 - 145,000
AWS Cloud Engineer
AWS Cloud Engineer

Aqua IT • O'Fallon (IL)

On-site
USD 100,000 - 130,000
Cloud Engineer
Cloud Engineer

Dine Development Corporation • Arizona

Hybrid
USD 110,000 - 165,000
Medical insurance
Dental insurance
Vision insurance
+4
AWS Cloud Engineer — Zero Trust & DoDIN Security
AWS Cloud Engineer — Zero Trust & DoDIN Security

Nakupuna Consulting • Arlington (VA)

On-site
USD 115,000 - 145,000
Cloud Engineer - MID
Cloud Engineer - MID

Socket.dev • Fairfax (VA)

On-site
USD 125,000 - 173,000
Benefits package
DevOps Engineer (Mid) TS/SCI
DevOps Engineer (Mid) TS/SCI

PAE Government Services Inc. • Arlington (VA)

On-site
USD 130,000 - 145,000
Health, dental, and vision insurance
Paid time off and holidays
Retirement benefits (401(k) matching)
+5
AWS Cloud Engineer
AWS Cloud Engineer

SAIC • Scott Air Force Base (IL)

On-site
USD 120,000 - 160,000
Sign-on bonus
Senior Cloud / DevSecOps Engineer (R-00200)
Senior Cloud / DevSecOps Engineer (R-00200)

Socket.dev • United States

Remote
USD 140,000 - 210,000
Competitive salary
Medical coverage
401k match
+3
AWS Cloud Engineer
AWS Cloud Engineer

Saic • Shiloh (IL)

On-site
USD 120,000 - 160,000
Potential sign-on bonus
Competitive salary range
Cloud Engineer - Journeyman
Cloud Engineer - Journeyman

TJ Consulting Group • Scott Air Force Base (IL)

On-site
USD 110,000 - 160,000
PTO
Holiday Pay
401K with a 4% Match
+13