Cloud Security Engineer

ECS Corporate Services

Fairfax (VA)

Hybrid

USD 120,000 - 160,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Hybrid work in Fairfax, VA
U.S. Citizenship
Active DoD Secret clearance

Job summary

Everforth ECS in Fairfax, VA is seeking a Cloud Security Engineer to design, implement, configure, and maintain cybersecurity technologies and secure Azure-based infrastructure across enterprise systems and cloud environments.

You will collaborate with SOC analysts, system administrators, network engineers, and stakeholders to ensure systems are protected, monitored, and hardened according to security requirements, standards, and best practices.

Qualifications

  • Bachelor's degree in a security-related field with 5+ years of relevant experience.
  • Hands-on Azure security implementation and operations.
  • Experience with security tools and collaborating with SOC and admins.
  • U.S. Citizen and active DoD Secret clearance.

Responsibilities

  • Implement, configure, maintain, and support cybersecurity technologies, tools, platforms, and technical security controls.
  • Assist with engineering secure solutions for enterprise systems, networks, endpoints, cloud environments, applications, and operational support platforms.
  • Support security architecture decisions by providing implementation input, technical feasibility analysis, and operational considerations.
  • Apply security engineering practices across the system lifecycle, including planning, deployment, configuration, testing, operations, and sustainment.
  • Review system configurations, permissions, authentication settings, logging settings, encryption settings, and access controls for alignment with security requirements.
  • Support implementation of vulnerability remediation, configuration changes, patching activities, and risk reduction measures in coordination with system owners.
  • Validate that security controls are operating as intended and support remediation when control gaps or technical weaknesses are identified.
  • Security Tool Support & Integration: Support deployment, tuning, and sustainment of tools such as SIEM, EDR, vulnerability scanners, firewalls, IDS/IPS, email security, identity security, logging, and monitoring platforms.
  • Integrate security tools with enterprise systems, data sources, ticketing systems, dashboards, identity platforms, and incident response workflows.
  • Troubleshoot tool performance, connectivity, data collection, alerting, agent health, policy enforcement, and integration issues.
  • Coordinate with SOC analysts, engineers, threat hunters, and system administrators to ensure security tooling supports monitoring, investigation, and response requirements.
  • Vulnerability, Risk & Remediation Support: Analyze vulnerability scan results, configuration findings, security alerts, and control weaknesses to support prioritization and remediation planning.
  • Work with technical teams to identify root causes, validate remediation options, and confirm closure of vulnerabilities or security findings.
  • Support risk treatment activities by documenting technical constraints, compensating controls, residual risk, and remediation status.
  • Assist control assessors and assessment leads by providing technical evidence, configuration details, screenshots, logs, and implementation explanations.
  • Incident Response & Operational Support: Provide technical engineering support during security incidents, investigations, containment activities, eradication efforts, and recovery actions.
  • Assist with log collection, tool validation, endpoint or network containment actions, access changes, system isolation, and forensic preservation activities as directed.
  • Develop and maintain scripts, queries, automation, and repeatable procedures to improve security operations and engineering response efficiency.
  • Participate in after‑action reviews and support implementation of technical improvements based on incident lessons learned.
  • Documentation, Standards & Continuous Improvement: Develop and maintain technical documentation, configuration standards, diagrams, implementation guides, runbooks, and operational procedures.
  • Support change management, configuration management, asset documentation, and security engineering governance processes.
  • Recommend improvements to security tools, engineering processes, baselines, automation, monitoring coverage, and technical control implementation.
  • Stay current with emerging threats, security technologies, hardening guidance, and engineering best practices relevant to enterprise security environments.

Skills

Security engineering
Azure
Threat analysis
SOC collaboration
Incident response
Automation scripting

Education

Bachelor's degree

Tools

SIEM
EDR
Vulnerability scanners
Firewalls
IDS/IPS
Identity security
Logging & monitoring

Job description

Everforth ECS is seeking a Cloud Security Engineer to work in our Fairfax, VA office. Everforth ECS is seeking a Microsoft Azure based Cloud Security Engineer to support the design, implementation, configuration, and maintenance of cybersecurity technologies, controls, and secure infrastructure capabilities across enterprise systems and security operations environments. This role will help ensure that systems, applications, networks, endpoints, and cloud environments are protected, monitored, hardened, and aligned with organizational security requirements. The ideal candidate has hands-on experience implementing and supporting security tools, troubleshooting technical security issues, applying secure configuration standards, and collaborating with SOC analysts, system administrators, network engineers, control assessors, and program stakeholders to improve the organization’s security posture.

Key Responsibilities
  • Security Engineering & Implementation: Implement, configure, maintain, and support cybersecurity technologies, tools, platforms, and technical security controls.
  • Assist with engineering secure solutions for enterprise systems, networks, endpoints, cloud environments, applications, and operational support platforms.
  • Support security architecture decisions by providing implementation input, technical feasibility analysis, and operational considerations.
  • Apply security engineering practices across the system lifecycle, including planning, deployment, configuration, testing, operations, and sustainment.
  • System Hardening & Secure Configuration: Apply secure configuration baselines, hardening standards, and technical control requirements to servers, endpoints, network devices, applications, and Azure cloud services.
  • Review system configurations, permissions, authentication settings, logging settings, encryption settings, and access controls for alignment with security requirements.
  • Support implementation of vulnerability remediation, configuration changes, patching activities, and risk reduction measures in coordination with system owners.
  • Validate that security controls are operating as intended and support remediation when control gaps or technical weaknesses are identified.
  • Security Tool Support & Integration: Support deployment, tuning, and sustainment of tools such as SIEM, EDR, vulnerability scanners, firewalls, IDS/IPS, email security, identity security, logging, and monitoring platforms.
  • Integrate security tools with enterprise systems, data sources, ticketing systems, dashboards, identity platforms, and incident response workflows.
  • Troubleshoot tool performance, connectivity, data collection, alerting, agent health, policy enforcement, and integration issues.
  • Coordinate with SOC analysts, engineers, threat hunters, and system administrators to ensure security tooling supports monitoring, investigation, and response requirements.
  • Vulnerability, Risk & Remediation Support: Analyze vulnerability scan results, configuration findings, security alerts, and control weaknesses to support prioritization and remediation planning.
  • Work with technical teams to identify root causes, validate remediation options, and confirm closure of vulnerabilities or security findings.
  • Support risk treatment activities by documenting technical constraints, compensating controls, residual risk, and remediation status.
  • Assist control assessors and assessment leads by providing technical evidence, configuration details, screenshots, logs, and implementation explanations.
  • Incident Response & Operational Support: Provide technical engineering support during security incidents, investigations, containment activities, eradication efforts, and recovery actions.
  • Assist with log collection, tool validation, endpoint or network containment actions, access changes, system isolation, and forensic preservation activities as directed.
  • Develop and maintain scripts, queries, automation, and repeatable procedures to improve security operations and engineering response efficiency.
  • Participate in after‑action reviews and support implementation of technical improvements based on incident lessons learned.
  • Documentation, Standards & Continuous Improvement: Develop and maintain technical documentation, configuration standards, diagrams, implementation guides, runbooks, and operational procedures.
  • Support change management, configuration management, asset documentation, and security engineering governance processes.
  • Recommend improvements to security tools, engineering processes, baselines, automation, monitoring coverage, and technical control implementation.
  • Stay current with emerging threats, security technologies, hardening guidance, and engineering best practices relevant to enterprise security environments.

Other duties, as assigned.

Salary Range: $120,000 - $160,000

General Description of Benefits
  • U.S. Citizen.
  • Active DoD Secret security clearance.
  • Bachelor's degree with 5+ years of experience in cybersecurity engineering, security operations, systems administration, network administration, cloud security, or related technical security roles.
  • Active DoD 8140 IAT Level II Security+ (or higher).
  • Ability to work in a hybrid capacity in Fairfax, VA (up to 3 days in office).
  • Ability to travel < 20% throughout the lifespan of the Program to CONUS / OCONUS customer sites and government installations.
Hands‑on experience
  • Implementing, configuring, or supporting Microsoft Azure‑Based security tools, technical controls, secure configurations, and enterprise security technologies.
  • With Windows, Linux, networking, identity and access management, endpoint security, logging, vulnerability management, and common security architectures.
  • Experience applying security requirements, hardening standards, vulnerability remediation guidance, and configuration baselines across Azure Cloud environments.
  • Ability to troubleshoot technical security issues involving systems, networks, applications, integrations, agents, logs, policies, and monitoring tools.
  • Familiarity with cybersecurity frameworks, standards, and best practices such as NIST, CIS Controls, DISA STIGs, ISO 27001, or organizational security baselines.
  • Strong problem‑solving and decision‑making capabilities, with a proven ability to weigh the relative costs and benefits of potential actions and identify the most appropriate solution.
  • Highly developed interpersonal and oral/written communication skills, with the ability to effectively and professionally interact with a diverse set of stakeholders (from peers to end‑users to executive management).
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cloud Security Engineer
Cloud Security Engineer

ECS • Fairfax (VA)

Hybrid
USD 120,000 - 160,000
Azure Cloud Architect
Azure Cloud Architect

ECS • Fairfax (VA)

Hybrid
USD 180,000 - 220,000
Cloud Security Engineer
Cloud Security Engineer

ECS • Arlington (VA)

Hybrid
USD 140,000 - 170,000
Senior Cloud Engineer
Senior Cloud Engineer

ECS • Fairfax (VA)

Hybrid
USD 170,000 - 200,000
Hybrid work model
Lead Technical Engineer
Lead Technical Engineer

ECS • Fairfax (VA)

Hybrid
USD 175,000 - 210,000
Security Engineer
Security Engineer

Gravity IT Resources • Salt Lake City (UT)

On-site
USD 120,000 - 160,000
Senior Security Engineer
Senior Security Engineer

ECS • Arlington (VA)

Hybrid
USD 140,000 - 180,000
Senior Azure Cloud Engineer
Senior Azure Cloud Engineer

ShorePoint • Washington

On-site
USD 150,000 - 190,000
144 hours PTO
11 holidays
Insurance premium covered 85%
+2
Cloud Security Engineer
Cloud Security Engineer

ECS • Washington

Hybrid
USD 120,000 - 130,000
Senior Security Engineer
Senior Security Engineer

Zermount, Inc. • United States Virgin Islands

On-site
USD 100,000 - 150,000