Cloud Security Engineer

apex-technology-inc

Los Angeles (CA)

On-site

USD 180,000 - 240,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

apex-technology-inc is seeking a Cloud Security Engineer to design, implement, and optimize secure cloud environments supporting U.S. government missions.

The role focuses on protecting data in AWS GovCloud, Azure, and hybrid multi-clouds while meeting NIST 800-53, FedRAMP, RMF, and DoD IL requirements. On-site in Playa Vista, CA with collaboration across DevSecOps teams.

Qualifications

  • Bachelor's degree in Cybersecurity, Information Assurance, CS or equivalent and/or 5+ years in cloud security engineering
  • 5+ years of cloud security engineering experience in AWS GovCloud, Azure, GCP or multi-cloud environments
  • Hands-on with regulated environments and federal standards (NIST, FedRAMP, RMF, DoD IL)
  • Strong analytical, communication, and collaboration skills for mission-critical ops

Responsibilities

  • Design secure cloud architectures across AWS GovCloud, Azure and GCP with least-privilege, encryption, and data protection
  • Maintain compliance with NIST 800-53 Rev. 5, FedRAMP, RMF, DoD IL-2/4/5
  • Manage IAM/RBAC/JIT access, KMS, and Zero Trust across clouds
  • Deploy security tools (Microsoft Defender, Azure Sentinel, AWS GovCloud security services, SIEM) for threat detection
  • Conduct vulnerability assessments, penetration testing, and continual monitoring
  • Develop SSP, SAR, POA&M and risk/compliance reporting for cloud ops
  • Analyze IoCs, threat intel, and incidents; perform root-cause analysis and preventive controls
  • Coordinate security reviews and audits for Azure, AWS and hybrid environments
  • Collaborate with DevSecOps to embed security into CI/CD and IaC (Terraform, CloudFormation)
  • Maintain new security policies, guardrails, and documentation for cyber terrain
  • Provide training on secure cloud design patterns and best practices

Skills

Cloud security
Compliance
CI/CD security
Incident response

Education

Bachelor's degree in Cybersecurity or related field

Tools

AWS GovCloud
Azure
GCP / multi-cloud
Terraform
CloudFormation
Elastic SIEM

Job description

About the Role

We are seeking a Cloud Security Engineer to design, implement, maintain, and optimize secure cloud environments supporting U.S. government, DoD, and intelligence community missions.

This role plays a critical part in protecting classified and sensitive data in AWS, Azure, and hybrid/multi-cloud infrastructures while ensuring full compliance with federal standards such as NIST 800-53, FedRAMP, RMF, and DoD Impact Levels (IL-4/IL-5).

The right candidate will bring hands-on experience securing cloud platforms in regulated environments. This role will help the organization meet industry standards such as SOC2, ISO 27001, PCI-DSS, GDPR/CCPA, or other relevant compliance frameworks.

Responsibilities
  • Design and implement secure cloud architectures and configurations across AWS GovCloud, Azure, and/or Google Cloud, applying best practices for least privilege encryption, network segmentation, and data protection.
  • Implement and maintain cloud security frameworks, ensuring ongoing compliance with NIST 800-53 Rev. 5, FedRAMP, DoD IL-2/4/5, RMF, and Secure Cloud Computing Architecture (SCCA) requirements.
  • Configure and manage Identity and Access Management (IAM), Role-Based Access Control (RBAC), Just-In-Time (JIT) access, Key Vaults, and Zero Trust Architecture (ZTA) principles across cloud environments.
  • Engineer, deploy, and optimize cloud-native security tools, including Microsoft Defender for Cloud, Azure Sentinel, AWS GovCloud security services, CSPM/CWPP solutions, and SIEM (Elastic) platforms for threat detection, monitoring, and response.
  • Conduct vulnerability assessments, penetration testing simulations, security configuration reviews (against STIGs, CIS benchmarks, and NIST controls), and continuous monitoring of cloud resources.
  • Develop, maintain, and update System Security Plans (SSP), Security Assessment Reports (SAR), Plans of Action & Milestones (POA&M), and risk/compliance reporting for cloud-based operations.
  • Identify, analyze, and respond to Indicators of Compromise (IoCs), threat intelligence, and security incidents within cloud environments; perform root-cause analysis and implement preventive controls.
  • Perform periodic security reviews and audits of cloud environments (Azure, AWS, hybrid) to ensure sustained compliance, mitigate evolving threats, and update policies/procedures.
  • Collaborate with DevSecOps, infrastructure, and development teams to integrate security into CI/CD pipelines, automate security controls, and support secure cloud migrations or modernization initiatives.
  • Assess current cloud architectures, propose security improvements, review designs through a security lens, and serve as a subject-matter expert on cloud security tools, processes, and best practices.
  • Coordinate with configuration management teams to ensure hardware/software changes adhere to security protocols, maintain version control, and support documentation of the cyber terrain.
  • Develop, enforce, and maintain cloud security policies, standards, and automated guardrails to support secure CI/CD pipelines and infrastructure-as-code (IaC) practices (e.g., using Terraform, CloudFormation).
  • Monitor cloud environments for security incidents, investigate alerts, perform root-cause analysis, and coordinate incident response activities.
  • Identify emerging threats and recommend proactive improvements to cloud security posture, including automation of security controls and processes.
  • Provide guidance and training to engineering teams on secure cloud design patterns and best practices.
Requirements
  • Must be a U.S. citizen.
  • Education: Bachelor's degree in Cybersecurity, Information Assurance, Computer Science, or a related field (or 5+ years equivalent professional experience in cloud security engineering)
  • Experience: 5-9+ years in cloud security engineering, with hands-on work in AWS GovCloud, Azure, Google GCP, or multi-cloud environments.
  • Strong analytical, problem-solving, communication, and collaboration skills; ability to work in fast-paced, mission-critical environment.
  • Location: Ability to be on-site 5 days a week at our office in Playa Vista, CA.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cloud Security Engineer, AWS GovCloud
Senior Cloud Security Engineer, AWS GovCloud

apex-technology-inc • Los Angeles (CA)

On-site
USD 140,000 - 190,000
Cloud Security Engineer, AWS GovCloud
Cloud Security Engineer, AWS GovCloud

apex-technology-inc • Los Angeles (CA)

On-site
USD 140,000 - 190,000
Cloud Security Engineer
Cloud Security Engineer

Endurion • Tampa (FL)

On-site
USD 110,000 - 170,000
Cloud Security Engineer
Cloud Security Engineer

TechDigital Group • Frisco (TX)

On-site
USD 80,000 - 120,000
Cloud Security Engineer
Cloud Security Engineer

Digital Global Connectors • McLean (VA)

Hybrid
USD 130,000 - 170,000
Cloud Security Architect — AWS GovCloud & DoD Compliance
Cloud Security Architect — AWS GovCloud & DoD Compliance

Apex - Satellite Platforms • Los Angeles (CA)

On-site
USD 150,000 - 200,000
Equity in Apex
Company-paid healthcare
PTO 15–20 days+ holidays
+4
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Global Solutions Consulting LLC. • Baltimore (MD)

Hybrid
USD 90,000 - 135,000
Competitive salary and benefits package
Opportunities for professional growth
Collaborative work environment
+1
Mission-Critical Cloud Security Engineer (GovCloud/Azure)
Mission-Critical Cloud Security Engineer (GovCloud/Azure)

Apex • Los Angeles (CA)

On-site
USD 140,000 - 180,000
Equity in Apex
Excellent health benefits
Generous PTO and holidays
+2
Cloud Security Engineer
Cloud Security Engineer

Highbrow LLC • Marietta (GA), Omaha (NE), Alpharetta (GA), Berkeley Heights (NJ)

Hybrid
USD 120,000 - 150,000
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Avantdigitalnow • San Francisco (CA)

On-site
USD 120,000 - 150,000