Cloud Security Engineer – FedRAMP & AI-Driven Security

Pegasystems

Sterling (VA)

On-site

USD 86,700 - 129,600

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Bonus potential
Employee equity
Learning & development

Job summary

Pega’s Cloud Security team is seeking a Cloud Security Engineer to strengthen FedRAMP and cloud security controls across AWS and multi‑cloud environments. You will write code, build automation, and operate regulated infrastructure with a focus on security, compliance, and scalable delivery.

Responsibilities include IAM governance, vulnerability management, patching cycles, and automation of cloud infrastructure. US citizenship is required for this role, reflecting the regulatory work involved.

Qualifications

  • 3+ years in cloud security engineering in AWS environments.
  • Experience operating in FedRAMP or regulated environments.
  • Proficient with identity platforms: Okta administration, SailPoint or equivalent IGA tooling.

Responsibilities

  • Own IAM administration across environments, including MFA resets and access reviews.
  • Operate vulnerability scanning and remediation using Nessus/Tenable and Netsparker.
  • Execute FedRAMP patching cycles and automate patching across environments.
  • Develop cloud infrastructure automation (CloudFormation, Terraform) and role provisioning.
  • Contribute to AI-driven remediation features and SOAR integrations.

Skills

AWS IAM & CloudFormation
Okta administration
SailPoint IAM tooling
Python scripting
Terraform / IaC
GitHub Actions / CI-CD
AI tooling usage

Tools

Nessus/Tenable
Netsparker
AWS Inspector
CloudFormation
Terraform
GitHub
SSM
AWS Config
GuardDuty

Job description

Search All Jobs

Cloud Security Engineer

Job Category: Engineering & Cloud

Location: US - Virginia - Sterling

  • Apply now
  • Share Share via Facebook Share via X Share via LinkedIn Share via Email Copying... Copied!

Meet Our Team:

This team is part of Pega’s Cloud Cybersecurity organization within the Cloud Cybersecurity Operations tribe. We help build and operate the security controls, automation, and response capabilities that protect Pega's cloud environments, including FedRAMP-regulated government infrastructure, commercial AWS, and multi-cloud platforms. We work across IAM, vulnerability management, compliance automation, SOAR response actions, and AI-driven security tooling. Engineers on this team own their domains end-to-end: design, build, operate, and iterate.

Due to the nature of the role's work with FedRamp, US Citizenship is required

Picture Yourself At Pega:

You'll be a part owner of Pega's FedRamp/cloud environment, responsible for both day-to-day operational security and sprint-based feature delivery. You'll work alongside peers delivering AI-driven remediation pipelines, identity automation, and cloud security tooling, and are expected to contribute to that innovation work alongside your responsibilities.

This is an engineering role. You write code, build automation, operate regulated infrastructure, and ship features, not just process tickets.

What You'll Do At Pega:

Access Governance & Identity Operations (30%)

  • Own Okta administration for PCFG and Commercial environments: MFA resets, account provisioning, Okta Verify troubleshooting, policy enforcement
  • Manage IAM roles, permission boundaries, deployment entitlements, and access reviews across PCFG accounts (CloudOps, Jenkins, deployment pipelines)
  • Build and maintain entitlement automation workflows for joiner/mover/leaver processes
  • Support SailPoint quarterly certifications and access request workflows; contribute to AI-assisted certification automation

Vulnerability Scanning & Remediation (25%)

  • Operate Nessus/Tenable and Netsparker scanning across PCFG RnD and PCFG Prod
  • Respond to audit scan requests (UKCE, SOC, FedRAMP assessors) with findings and evidence
  • Track and ensure zero high-severity findings outstanding beyond 30 days

Compliance Patching & BAU (25%)

  • Execute FedRAMP Control Plane patching cycle every sprint — mandatory compliance obligation, non-negotiable
  • Execute PCFG RnD OS automated patching and validate Commercial environment patches (SailPoint, PingCastle)
  • Maintain patch compliance metrics; escalate blockers before sprint close
  • Contribute to SSM Patch Manager automation to reduce manual patching overhead over time

Cloud Infrastructure & Automation Engineering (20%)

  • Build infrastructure automation: Control Tower account provisioning, PCFG account lifecycle, CloudFormation role deployment
  • Develop SSM Patch Manager alerting and role infrastructure
  • Respond to ad-hoc infrastructure requests: IAM policy changes, Global Accelerator, Lambda roles, Bedrock model enablement
  • Contribute to team-wide AI-driven remediation features — SOAR response actions, AWS Config automation, and AI intake tooling

What You've Accomplished:

  • 3+ years in cloud security engineering or a closely adjacent role; hands-on with AWS (IAM, CloudFormation, SSM, Inspector, Config, GuardDuty)
  • Experience operating in a FedRAMP or similarly regulated environment, you understand what compliance-driven delivery looks like
  • Proficient with identity platforms: Okta administration, SailPoint or equivalent IGA tooling
  • Comfortable writing automation: Python, shell, CloudFormation/Terraform, you don't wait for someone else to build the script
  • Familiar with vulnerability scanning tools (Nessus/Tenable, Netsparker, or AWS Inspector)
  • You operate well in a team that splits time between BAU obligations and feature delivery, context-switching is part of the job
  • Exposure to SOAR platforms (Chronicle SecOps, Siemplify, or similar) is a plus
  • Experience with GitHub-based CI/CD pipelines,you're comfortable with PR-gated workflows, GitHub Actions, and treating infrastructure and security content as code that gets reviewed before it ships
  • You use AI tools (Copilot, ChatGPT, or similar) as part of how you build, scaffolding automation, generating test cases, accelerating repetitive engineering work and you know how to validate what comes out

Pega Offers You:

  • Gartner Analyst acclaimed technology leadership across our categories of products
  • Continuous learning and development opportunities
  • An innovative, inclusive, agile, flexible, and fun work environment
  • Competitive global benefits program inclusive of pay + bonus incentive, employee equity in the company ()

Additional Information

Base salary range for this role is 86,700 - 129,600 USD annually. This role may also be eligible for annual bonus OR commission, as well as benefits and other incentives.

The final compensation will be determined during the offer process based on the candidate's education, experience, skills, and qualifications, as well as market conditions and may vary from the posted range. We will share an information on benefits, bonus/commission, and other pay components for this role at the relevant recruitment stage.

Job ID: 23853

Ready to build a Blueprint?

Choose the reinvention engine for your needs.

For workflows & app design

Reimagine your processes and turn any workflow into a build-ready application with confidence.

Pega Blueprint™

For marketing & CX strategy design

Visualize customer journeys and engagement strategies across all touchpoints and activate them.

Pega Customer Engagement Blueprint™

Additional Information

Base salary range for this role is 86,700 - 129,600 USD annually. This role may also be eligible for annual bonus OR commission, as well as benefits and other incentives.

The final compensation will be determined during the offer process based on the candidate's education, experience, skills, and qualifications, as well as market conditions and may vary from the posted range. We will share an information on benefits, bonus/commission, and other pay components for this role at the relevant recruitment stage.

Job ID: 23853

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cloud Security Engineer
Cloud Security Engineer

Pegasystems • Sterling (VA)

On-site
USD 86,700 - 129,600
Bonus potential
Employee equity
Learning & development
Senior Cloud Operations Engineer, Infrastructure
Senior Cloud Operations Engineer, Infrastructure

Pegasystems, Inc. • Boston (MA)

Remote
USD 102,000 - 153,000
Pay + bonus incentive
Employee equity
Continuous learning opportunities
Senior Cloud Operations Engineer, Infrastructure
Senior Cloud Operations Engineer, Infrastructure

Pegasystems, Inc. • New Hampshire

Hybrid
USD 102,000 - 153,000
Competitive benefits
Bonus program
Employee equity
+2
Senior Cloud Operations Engineer, Deployments
Senior Cloud Operations Engineer, Deployments

Pegasystems • Waltham (MA), Northern (KY)

On-site
USD 102,000 - 153,000
Competitive global benefits
Bonus potential
Employee equity
Senior Cloud Operations Engineer, Infrastructure
Senior Cloud Operations Engineer, Infrastructure

Pegasystems • Waltham (MA)

On-site
USD 102,000 - 153,000
Senior Cloud Operations Engineer, Infrastructure
Senior Cloud Operations Engineer, Infrastructure

Pegasystems • Massachusetts

On-site
USD 102,000 - 153,000
Continuous learning opportunities
Inclusive, agile work environment
Global benefits program including pay/
Senior Cloud Operations Engineer, Infrastructure
Senior Cloud Operations Engineer, Infrastructure

Pegasystems • Manchester (NH)

On-site
USD 102,000 - 153,000
Senior System Architect
Senior System Architect

Pega • Washington, Northern (KY)

Hybrid
USD 114,000 - 177,000
Bonus incentive
Employee equity
Lead System Architect
Lead System Architect

Pega • California (MO), Northern (KY)

Hybrid
USD 141,000 - 215,000
Gartner leadership acknowledgement
Learning & development opportunities
Innovative, flexible culture
+1
Client Executive (Amazon)
Client Executive (Amazon)

Pegasystems • Northern (KY)

On-site
USD 131,000 - 200,000
Uncapped commission
Pega equity
Bonus eligibility
+1