Cloud Security Engineer *

FGS, LLC

Suitland (MD)

On-site

USD 154,000 - 166,000

Full time

2 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

FGS, LLC is seeking a Cloud Security Engineer to engineer, implement, assess, and improve cybersecurity capabilities for secure cloud and hybrid-cloud solutions supporting the Office of Naval Intelligence in Suitland, Maryland.

The selected candidate will integrate security requirements into cloud platforms, applications, data services, networks, and automated delivery pipelines throughout the system lifecycle.

Qualifications

  • U.S. Citizenship is required.
  • Active TS/SCI clearance at time of hire.
  • Minimum eight years of cybersecurity experience.
  • At least five years supporting complex Government information systems.
  • Demonstrated depth in cloud security, system security engineering, vulnerability mitigation, or related specialization.
  • Experience implementing cloud-security controls for identity, networking, encryption, logging, monitoring, and secure configuration.
  • Experience assessing cloud architectures, documenting gaps, and developing remediation plans.
  • Experience developing security documentation and supporting risk management, control assessment, and continuous monitoring.

Responsibilities

  • Engineer and implement cloud-security controls for IAM, segmentation, encryption, logging, monitoring, vulnerability management, and configuration management.
  • Assess cloud and hybrid-cloud architectures for security gaps, vulnerabilities, and compliance risks.
  • Develop remediation plans and coordinate actions with cloud, systems, network, application, data, and cybersecurity teams.
  • Integrate security into IaC, CI/CD, DevSecOps, containers, platforms, and app-development workflows.
  • Maintain secure cloud baselines, configuration standards, hardening guidance, and reusable security patterns.
  • Implement and validate least privilege, MFA, federation, and service identities across cloud environments.
  • Design security logging, telemetry, alerting, audit, and SIEM integration for cloud workloads.
  • Support vulnerability scanning, secure configuration assessment, patch tracking, and remediation validation using ACAS, Nessus, STIG, SCAP.

Skills

Cloud security engineering
Vulnerability mitigation
Secure configuration
Automation
Security controls
Infrastructure as Code
DevSecOps
SIEM
Technical writing

Education

Master's degree in Engineering, CS, IT

Tools

ACAS
Nessus
STIG
SCAP
Terraform
CloudFormation
Bicep
Ansible
GitLab

Job description

Requires US Citizenship


Employment Term and Type: Regular, Full Time


Required Security Clearance: (Minimum for hire) TS/SCI


Required Education: (Minimum for hire) Master's degree in Engineering, Computer Science, Information Technology, or related technical discipline; additional relevant experience may be considered in lieu of education when permitted by applicable contract requirements.


Salary Band: $153,717 to $166,217


Job Description:

FGS, LLC is seeking a Cloud Security Engineer to engineer, implement, assess, and improve cybersecurity capabilities for secure cloud and hybrid-cloud solutions supporting the Office of Naval Intelligence in Suitland, Maryland. The selected candidate will integrate security requirements into cloud platforms, applications, data services, networks, and automated delivery pipelines throughout the system lifecycle.


The Cloud Security Engineer will work with cloud architects, systems engineers, developers, network engineers, cybersecurity personnel, and Government stakeholders to implement security controls, identify and remediate technical risk, and support authorization and continuous monitoring. This role requires hands-on technical depth in cloud security engineering, vulnerability mitigation, secure configuration, automation, and classified Government information systems.


Primary Duties and Responsibilities:


  • Engineer and implement cloud-security controls for identity, access management, segmentation, encryption, logging, monitoring, vulnerability management, and configuration management.

  • Assess cloud and hybrid-cloud architectures, services, configurations, and workloads for security gaps, vulnerabilities, threats, and compliance risks.

  • Develop prioritized remediation plans and coordinate corrective actions with cloud, systems, network, application, data, and cybersecurity teams.

  • Integrate security into Infrastructure as Code, CI/CD, DevSecOps, container, platform, and application-development workflows.

  • Develop and maintain secure cloud baselines, configuration standards, hardening guidance, reusable security patterns, and implementation procedures.

  • Implement and validate least privilege, role-based and attribute-based access, privileged-access controls, multifactor authentication, federation, and service identities.

  • Design and implement security logging, telemetry, alerting, audit, and SIEM integration for cloud platforms and workloads.

  • Support vulnerability scanning, secure configuration assessment, patch and remediation tracking, and validation using ACAS, Nessus, STIG, SCAP, cloud-native, and related tools.

  • Apply NIST SP 800-53, CNSSI 1253, DoD Cloud Computing Security Requirements Guide, DISA STIGs, and applicable Department of the Navy and Intelligence Community requirements.

  • Support risk assessments, security-control implementation, system authorization, continuous monitoring, and development of required cybersecurity artifacts.

  • Evaluate cloud-native and third-party security technologies and conduct technical trade studies, proofs of concept, and implementation reviews.

  • Implement security automation, policy as code, secrets management, cryptographic key management, certificate management, and automated compliance checks.

  • Investigate security events and technical findings, determine root cause and mission impact, and coordinate containment, remediation, and lessons learned.

  • Review implementation artifacts and delivered capabilities for conformance with approved architectures, security requirements, and technical baselines.

  • Brief Government and program leadership on cloud-security posture, technical risks, remediation status, dependencies, and recommended decisions.


Required Qualifications:


  • U.S. Citizenship.

  • Active TS/SCI security clearance at the time of hire.

  • Minimum eight years of relevant cybersecurity experience.

  • At least five years supporting complex Government information systems.

  • Demonstrated technical depth in cloud security, system security engineering, vulnerability mitigation, or a comparable cybersecurity specialization.

  • Experience implementing cloud-security controls for identity, networking, encryption, logging, monitoring, vulnerability management, and secure configuration.

  • Experience assessing cloud architectures and technical implementations, documenting security gaps, and developing actionable remediation plans.

  • Experience developing security documentation and supporting risk management, security-control assessment, system authorization, or continuous-monitoring activities.

  • Experience integrating security requirements into engineering, development, Infrastructure as Code, DevSecOps, or automated deployment workflows.

  • Knowledge of applicable NIST, DoD, Department of the Navy, and Intelligence Community cybersecurity standards and guidance.

  • Strong technical writing, analytical, problem-solving, collaboration, and verbal communication skills.


Desired Qualifications:


  • Professional cloud-security certification, such as CCSP, AWS Certified Security - Specialty, Microsoft Certified Cybersecurity Architect Expert, or comparable certification.

  • CISSP, CASP+, CISM, Security+ CE, or another certification appropriate to the assigned DoD 8140 work role.

  • Experience with AWS GovCloud, Azure Government, or other accredited Government cloud environments.

  • Experience with cloud-security posture management, cloud workload protection, containers, Kubernetes, and runtime security.

  • Experience with Terraform, CloudFormation, Bicep, Ansible, GitLab, or comparable Infrastructure as Code and automation technologies.

  • Experience with SIEM integration, security orchestration and automation, endpoint protection, network detection, and cloud-native security services.

  • Experience with cryptographic key management, secrets management, certificate services, data protection, and policy as code.

  • Experience implementing Zero Trust security principles in cloud and hybrid-cloud environments.


Education Requirements:


  • Master's degree in Engineering, Computer Science, Information Technology, or a related technical discipline. Additional relevant experience may be considered in lieu of education when permitted by applicable contract requirements.


Security Clearance Requirements:


  • U.S. citizenship and an active TS/SCI clearance are required at the time of hire. The employee must maintain clearance eligibility throughout employment.


Physical, Work Environment & Conditions:


  • Primarily onsite in Suitland, Maryland, with limited telework when authorized.

  • Work is performed in a professional office, secure-facility, and occasional data-center or equipment-room environment.

  • Must be able to use standard office and information-technology equipment and work at a computer for extended periods.

  • Must be able to communicate effectively with technical, mission, program, and senior leadership stakeholders.

  • Occasional schedule flexibility or limited travel may be required to support security assessments, integration, or deployment activities.


This position description is not intended as, nor should it be construed as, exhaustive of all responsibilities, skills, efforts, and working conditions associated with this job. This and all positions are eligible for organization-wide transfer. Management reserves the right to assign or reassign duties and responsibilities at any time.


Company Overview:

FGS, LLC is an international, leading-edge provider of technical services to include Secure Information Systems, Security and Engineering and Intelligence Analysis. Our turn-key solutions include design, engineering, deployment operations, and sustainment of secure technology and critical infrastructure for the protection and safety of our customers' mission-critical information, processes, and personnel. Demonstrating an unyielding commitment to our customers, superior trust and dedication with our partners, and leading-edge technical expertise over the past seven years, FGS has experienced explosive growth providing superior services throughout the world, from North America and the Pacific Rim to the Middle East and Europe.


FGS provides secure, leading-edge technology and process management services to military, government, and commercial clients worldwide.


FGS offers a generous compensation package including health, dental, vision, 401(k), group life insurance, educational reimbursement, among other benefits.


We value our employees and strive to offer many opportunities for professional growth.


FGS, LLC is an Equal Opportunity Employer as to all protected groups, including protected veterans and individuals with disabilities


FGS Careers


113 Howard St., Suite 301


La Plata, MD 20646

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Computer Network Architect , Senior
Computer Network Architect , Senior

FGS, LLC • Suitland (MD)

On-site
USD 185,000 - 200,000
Health insurance
Dental & vision
401(k)
+1
Cyber Security Engineer II*
Cyber Security Engineer II*

FGS, LLC • Tampa (FL)

On-site
USD 90,000 - 130,000
Health insurance
Dental insurance
Vision insurance
+1
Security Engineer
Security Engineer

The Squires Group • Washington

Hybrid
USD 96,000 - 138,000
PTO
Medical coverage
Dental coverage
+4
Senior Cloud Security Engineer (TS/SCI) - Onsite
Senior Cloud Security Engineer (TS/SCI) - Onsite

FGS, LLC • Suitland (MD)

On-site
USD 154,000 - 166,000
Cyber Security Engineer II* Clearance TS/SCI MacDill AFB, FL ID 16764663
Cyber Security Engineer II* Clearance TS/SCI MacDill AFB, FL ID 16764663

FGS, LLC • Town of Florida (NY)

On-site
USD 110,000 - 160,000
Health insurance
401(k)
Educational reimbursement
Cloud Engineer 660
Cloud Engineer 660

Freedom Technology Solutions Group, LLC • Chantilly (VA)

On-site
USD 120,000 - 160,000
Matching 401k
Fully paid medical
Paid time off
+1
AWS Cloud Engineer
AWS Cloud Engineer

D2 Consulting • Springfield (VA)

On-site
USD 140,000 - 150,000
Health benefits
401(k) match
PTO
+2
Cloud Security Architect
Cloud Security Architect

Futrend Technology • Bethesda (MD)

On-site
USD 140,000 - 190,000
AWS Cloud Systems Security Engineer (AE26091225)
AWS Cloud Systems Security Engineer (AE26091225)

Government Technical Services Corporation • Annapolis (MD)

On-site
USD 159,000 - 171,000
401K match
PTO 25 days
Education assistance
+3
Cyber Cloud Implementation Engineer
Cyber Cloud Implementation Engineer

D2 Consulting • Springfield (VA)

On-site
USD 135,000 - 145,000
Health/Dental/Vision
401(k) match
Accrued PTO
+3