Cloud Security Engineer

DANASTAR Professional Services, LLC

Washington (District of Columbia)

On-site

USD 140,000 - 190,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

EastBay Systems seeks a Senior Cloud Security Engineer to lead cloud security architecture, secure Azure/AWS/hybrid environments, and ensure compliance with FISMA, RMF, FedRAMP, and Zero Trust. You will guide security engineering, IAM, and monitoring while collaborating with DevSecOps, SOC, and GRC teams.

Responsibilities include designing secure Landing Zones, enforcing baselines, and implementing CSPM/CWPP practices while shaping cloud governance in federal contexts.

Qualifications

  • 8+ years of experience in cloud security engineering or cybersecurity engineering.
  • 5+ years securing Azure and/or AWS environments.
  • Experience with cloud networking, IAM, virtualization, storage, and infrastructure security.
  • Experience implementing Entra ID, Conditional Access, PIM, IAM, and RBAC.
  • Familiar with Azure Policy, AWS Config, cloud governance, and secure cloud architectures.
  • Experience designing logging, monitoring, and security telemetry solutions.
  • Strong leadership and communication skills for technical guidance.

Responsibilities

  • Design secure Azure, AWS, and hybrid cloud architectures and reference models.
  • Develop and enforce cloud security baselines and PPS standards.
  • Lead cloud security engineering across identity, network, and monitoring domains.
  • Collaborate with DevSecOps, SOC, and GRC to ensure compliant cloud platforms.
  • Support FISMA/NIST/FedRAMP compliance activities and security assessments.

Skills

Cloud security engineering
Azure/AWS security
Cloud networking
Identity management
RBAC/PIM
CLI tools
Technical leadership

Education

Bachelor's degree in Computer Science or related field

Tools

Azure CLI
AWS CLI
PowerShell
Terraform
Kubernetes
OpenShift

Job description

About EastBay Systems (Formerly DANASTAR Professional Services)

EastBay Systems is a cybersecurity and information technology consulting firm supporting Federal civilian agencies in delivering secure, resilient, and compliant enterprise systems. We specialize in Cybersecurity Program Management, Security Engineering, Governance, Risk & Compliance (GRC), Security Operations Center (SOC) operations, Cloud Security, and Continuous Monitoring.

We are seeking a Senior Cloud Security Engineer to serve as the organization’s technical lead for cloud security architecture, engineering, infrastructure protection, and cloud compliance across Azure, AWS, and hybrid environments.

Position Summary

The Senior Cloud Security Engineer is responsible for designing, implementing, securing, and continuously improving enterprise cloud infrastructure supporting Federal information systems. This position serves as the technical authority for cloud security architecture, cloud identity, cloud networking, infrastructure hardening, security monitoring, vulnerability management, and cloud governance.

The engineer works closely with Cloud Engineers, Security Engineers, DevSecOps, SOC analysts, GRC specialists, and Federal stakeholders to ensure cloud platforms are secure, resilient, continuously monitored, and compliant with FISMA, RMF, FedRAMP, Zero Trust Architecture, and OMB cybersecurity requirements.

This position focuses on securing the cloud platforms and infrastructure that host enterprise applications. Application security, secure software development, and CI/CD pipeline security are performed by the DevSecOps Engineer.

Cloud Security Architecture
  • Design and implement secure Azure, AWS, and hybrid cloud architectures.
  • Develop cloud security reference architectures, engineering standards, and implementation guidance.
  • Support enterprise cloud adoption initiatives and secure cloud migrations.
  • Design secure Landing Zones, subscription/account architectures, and cloud governance models.
  • Review cloud solution architectures for compliance with Federal cybersecurity requirements.
  • Implement Zero Trust principles within cloud environments.
Cloud Infrastructure Security
  • Secure cloud infrastructure, including virtual networks, compute, storage, databases, platform services, and cloud-native resources.
  • Implement and maintain security controls for Azure and AWS services.
  • Configure and maintain Network Security Groups (NSGs), AWS Security Groups, firewalls, Web Application Firewalls (WAFs), Application Gateways, load balancers, VPNs, ExpressRoute, Direct Connect, Private Endpoints, and cloud networking components.
  • Develop and maintain secure cloud configuration baselines and hardening standards.
  • Perform cloud security architecture reviews and recommend improvements to reduce attack surface.
Identity & Access Management
  • Design and implement secure cloud identity architectures.
  • Administer Microsoft Entra ID, cloud IAM services, Privileged Identity Management (PIM), Conditional Access, managed identities, and role-based access control (RBAC).
  • Develop least-privilege access models and identity governance standards.
  • Support identity federation, authentication, authorization, and privileged access management.
Cloud Security Monitoring & Logging
  • Design and implement cloud security monitoring architectures.
  • Identify and enable cloud platform logs required to support Continuous Monitoring (ISCM), threat detection, incident response, and forensic investigations.
  • Ensure Azure, AWS, and hybrid infrastructure generates and forwards required security logs to enterprise monitoring platforms.
  • Manage infrastructure logging, including cloud activity logs, identity logs, network flow logs, firewall logs, storage logs, platform diagnostics, and cloud service audit logs.
  • Collaborate with the SOC to integrate cloud telemetry into enterprise SIEM and detection engineering processes.
  • Define cloud log retention, protection, integrity, and archival requirements in accordance with Federal policies.
Cloud Security Baselines
  • Establish and maintain secure infrastructure configuration baselines.
  • Develop and maintain Ports, Protocols, and Services (PPS) baselines for cloud infrastructure components, virtual networks, platform services, and cloud-hosted resources.
  • Validate approved network communications, segmentation, trust relationships, ingress and egress rules, and service exposure.
  • Review firewall rules, routing, DNS configurations, and network security controls to minimize attack surface.
  • Ensure infrastructure configurations comply with Zero Trust Architecture and least functionality principles.
Cloud Security Engineering
  • Implement and manage Cloud Security Posture Management (CSPM) and Cloud Workload Protection Platform (CWPP) capabilities.
  • Secure containers, Kubernetes clusters, serverless services, storage platforms, databases, and cloud-native services from an infrastructure perspective.
  • Implement cloud vulnerability management, configuration compliance monitoring, and security policy enforcement.
  • Support cloud encryption, key management, certificate management, and secrets management solutions.
Federal Compliance
  • Support FISMA, RMF, FedRAMP, and Continuous Monitoring (ISCM) activities related to cloud infrastructure.
  • Develop technical documentation supporting NIST SP 800-53 security controls.
  • Support Security Assessment and Authorization (A&A) activities.
  • Assist with remediation of cloud-related POA&M findings.
  • Participate in audits, assessments, and compliance reviews.
  • Implement cloud security controls consistent with OMB directives, Federal Zero Trust guidance, and agency cybersecurity policies.
Collaboration
  • Partner with DevSecOps Engineers to ensure secure deployment of applications into cloud environments.
  • Collaborate with Cybersecurity Engineering on enterprise security standards and cloud architecture.
  • Work closely with SOC analysts to improve cloud detection, monitoring, and incident response capabilities.
  • Support GRC teams during assessments, audits, and continuous monitoring activities.
  • Provide technical leadership on cloud security technologies, architectures, and best practices.
Required Qualifications
  • Bachelor's degree in Computer Science, Computer Engineering, Information Technology, Cybersecurity, or a related technical discipline.
  • 8+ years of experience in cloud security engineering or cybersecurity engineering.
  • 5+ years securing Azure and/or AWS environments.
  • Strong knowledge of cloud networking, identity management, virtualization, storage, and infrastructure security.
  • Experience implementing Microsoft Entra ID, Conditional Access, PIM, IAM, and RBAC.
  • Experience with Azure Policy, AWS Config, cloud governance, and secure cloud architectures.
  • Experience designing cloud logging, monitoring, and security telemetry solutions.
  • Experience establishing infrastructure security baselines and Ports, Protocols, and Services (PPS) standards.
  • Experience with Microsoft Defender for Cloud or comparable CSPM/CWPP platforms.
  • Strong understanding of Zero Trust Architecture, cloud hardening, and cloud security best practices.
  • Experience supporting FISMA, NIST RMF, NIST SP 800-53 Rev. 5, FedRAMP, and Continuous Monitoring (ISCM).
  • Experience with PowerShell, Azure CLI, AWS CLI, or Python.
  • Excellent communication and technical leadership skills.
Preferred Qualifications
  • CISSP
  • CCSP
  • Microsoft Certified: Azure Security Engineer Associate (AZ-500)
  • AWS Certified Security – Specialty
  • AWS Solutions Architect – Professional
  • Microsoft Cybersecurity Architect (SC-100)
  • GIAC Cloud Security certifications
  • Experience with Microsoft Defender for Cloud, Microsoft Sentinel, Azure Monitor, AWS CloudWatch, CloudTrail, Azure Firewall, AWS Network Firewall, Terraform, Kubernetes, OpenShift, or enterprise cloud governance platforms.
  • Experience supporting FedRAMP High or Moderate cloud environments.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineer
Senior Security Engineer

Hiring Our Heroes • Arlington (VA)

On-site
USD 120,000 - 150,000
Senior Security Engineer
Senior Security Engineer

Zermount, Inc. • United States

On-site
USD 120,000 - 150,000
Cloud Security Engineer
Cloud Security Engineer

Highbrow LLC • Marietta (GA), Omaha (NE), Alpharetta (GA), Berkeley Heights (NJ)

Hybrid
USD 120,000 - 150,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

DANASTAR Professional Services, LLC • Washington

On-site
USD 140,000 - 185,000
Senior Security Engineer
Senior Security Engineer

Zermount, Inc. • United States Virgin Islands

On-site
USD 100,000 - 150,000
Cloud Engineer
Cloud Engineer

Peraton • Linthicum (MD)

On-site
USD 120,000 - 155,000
Cloud Security Engineer
Cloud Security Engineer

Digital Global Connectors • McLean (VA)

Hybrid
USD 130,000 - 170,000
Cloud Security Engineer
Cloud Security Engineer

Booz Allen Hamilton • Alexandria (VA)

On-site
USD 99,000 - 225,000
Health, life, and disability insurance
Retirement plans
Paid leave
Senior Cloud Security Engineer — Federal Cloud Architect
Senior Cloud Security Engineer — Federal Cloud Architect

DANASTAR Professional Services, LLC • Washington

On-site
USD 140,000 - 190,000
Cloud Security Engineer
Cloud Security Engineer

TechDigital Group • Frisco (TX)

On-site
USD 80,000 - 120,000