Cloud Guardrails Engineer — Remote/Hybrid, Secret Clearance

D9Tech Resources LLC

Arlington (VA)

Hybrid

USD 140,000 - 210,000

Full time

29 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

D9Tech Resources is seeking a cloud security engineer with active clearance to design and enforce guardrails in a multi-account AWS environment. You will author policy layers, IAM boundaries, and automated remediation while coordinating with the authorization team.

The role supports remote or hybrid work across CONUS, with occasional on-site accreditation activities for government programs. Citizenship is required for this role and security clearances apply.

Qualifications

  • Active Secret clearance or higher.
  • U.S. citizenship.
  • Hands-on experience in a multi-account AWS Organizations environment, including OU design and account structure.
  • Authorship of Service Control Policies; familiarity with Resource Control Policies and data perimeter patterns.
  • Deep IAM fluency: roles, trust policies, condition keys, and permission boundaries.
  • Production experience with AWS Config rules, conformance packs, and automated remediation.
  • Working knowledge of KMS key policies and encryption controls.
  • Infrastructure as code proficiency, since guardrails are deployed and versioned as code.

Responsibilities

  • Author the policy layer. Write, test, and version Service Control Policies and Resource Control Policies across the AWS Organizations structure, including region locks and data perimeter controls.
  • Design permission boundaries. Build IAM permission boundaries and delegated administration models that let account owners move quickly inside a fenced blast radius.
  • Codify detection. Develop AWS Config rules and conformance packs mapped to the control set, and wire automated remediation through Systems Manager or Lambda.
  • Own the key material. Design KMS customer-managed key policies, rotation, grants, and cross-account access patterns that hold up under review.
  • Run Security Hub as a working queue. Tune standards and findings, suppress the noise with justification, and drive real remediation instead of dashboard maintenance.
  • Prove the guardrails work. Build test cases that attempt the prohibited action and confirm the policy denies it, then keep those tests running as the environment changes.
  • Partner with the authorization team. Supply the technical evidence, artifacts, and control narratives that support the accreditation package without owning the package yourself.

Skills

IAM fluency
Service Control Policies
AWS Config rules
Python scripting
KMS policies
AWS Organizations
Data perimeter controls

Tools

AWS Config
AWS Lambda
AWS Systems Manager
KMS
CloudFormation (IaC)
AWS Organizations

Job description

D9Tech Resources is seeking a cloud security engineer with active clearance to design and enforce guardrails in a multi-account AWS environment. You will author policy layers, IAM boundaries, and automated remediation while coordinating with the authorization team.

The role supports remote or hybrid work across CONUS, with occasional on-site accreditation activities for government programs. Citizenship is required for this role and security clearances apply.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cloud Security Guardrails Engineer with Security Clearance
Cloud Security Guardrails Engineer with Security Clearance

D9Tech Resources LLC • Arlington (VA)

Hybrid
USD 140,000 - 210,000
Cloud Security Engineer — Hybrid (Azure/AWS/GCP)
Cloud Security Engineer — Hybrid (Azure/AWS/GCP)

Recology • Sacramento (CA)

Hybrid
USD 150,000 - 190,000
Paid time off
Health and wellness benefits
Employee Stock Ownership Plan
Cloud Security Engineer - AI-Driven GovCloud & Hybrid (LA)
Cloud Security Engineer - AI-Driven GovCloud & Hybrid (LA)

Altium • Los Angeles (CA)

Hybrid
USD 150,000 - 160,000
Senior Cloud Security Engineer — Remote & DevOps
Senior Cloud Security Engineer — Remote & DevOps

Chainguard, Inc. • Northern (KY)

Hybrid
USD 137,000 - 160,000
Flexible & Remote-First Culture
Equity stock options with 10 years to
100% Covered Health Insurance
+2
AWS Cloud Security Engineer — Guardrails & Automation
AWS Cloud Security Engineer — Guardrails & Automation

Xcel Energy • Minneapolis (MN)

Hybrid
USD 98,000 - 139,000
Annual Incentive Program
Medical/Pharmacy Plan
Dental
Cloud Security Engineer
Cloud Security Engineer

apex-technology-inc • Los Angeles (CA)

On-site
USD 180,000 - 240,000
AWS Cloud Engineer – TS/SCI Clearance | IaC & CI/CD
AWS Cloud Engineer – TS/SCI Clearance | IaC & CI/CD

cyber • Arlington (VA)

On-site
USD 140,000 - 190,000
26 Days of Paid Leave
Annual PTO Increase
Paid Parental Leave
+6
Cloud Security Guardrails & Automation Engineer
Cloud Security Guardrails & Automation Engineer

Amazon Web Services, Inc. • Sparks (NV)

On-site
USD 120,000 - 170,000
Remote Cloud Security Engineer — AWS & DevSecOps Lead
Remote Cloud Security Engineer — AWS & DevSecOps Lead

Hidden Jobs • United States

Hybrid
USD 120,000 - 135,000
Stock options
Paid benefits
Employee perks
Secure Cloud DevSecOps Engineer — Remote (Secret Clearance)
Secure Cloud DevSecOps Engineer — Remote (Secret Clearance)

LMI Government Consulting • Fort Belvoir (VA)

Hybrid
USD 84,000 - 144,000