Cloud Security Guardrails Engineer with Security Clearance

D9Tech Resources LLC

Arlington (VA)

Hybrid

USD 140,000 - 210,000

Full time

28 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

D9Tech Resources is seeking a cloud security engineer with active clearance to design and enforce guardrails in a multi-account AWS environment. You will author policy layers, IAM boundaries, and automated remediation while coordinating with the authorization team.

The role supports remote or hybrid work across CONUS, with occasional on-site accreditation activities for government programs. Citizenship is required for this role and security clearances apply.

Qualifications

  • Active Secret clearance or higher.
  • U.S. citizenship.
  • Hands-on experience in a multi-account AWS Organizations environment, including OU design and account structure.
  • Authorship of Service Control Policies; familiarity with Resource Control Policies and data perimeter patterns.
  • Deep IAM fluency: roles, trust policies, condition keys, and permission boundaries.
  • Production experience with AWS Config rules, conformance packs, and automated remediation.
  • Working knowledge of KMS key policies and encryption controls.
  • Infrastructure as code proficiency, since guardrails are deployed and versioned as code.

Responsibilities

  • Author the policy layer. Write, test, and version Service Control Policies and Resource Control Policies across the AWS Organizations structure, including region locks and data perimeter controls.
  • Design permission boundaries. Build IAM permission boundaries and delegated administration models that let account owners move quickly inside a fenced blast radius.
  • Codify detection. Develop AWS Config rules and conformance packs mapped to the control set, and wire automated remediation through Systems Manager or Lambda.
  • Own the key material. Design KMS customer-managed key policies, rotation, grants, and cross-account access patterns that hold up under review.
  • Run Security Hub as a working queue. Tune standards and findings, suppress the noise with justification, and drive real remediation instead of dashboard maintenance.
  • Prove the guardrails work. Build test cases that attempt the prohibited action and confirm the policy denies it, then keep those tests running as the environment changes.
  • Partner with the authorization team. Supply the technical evidence, artifacts, and control narratives that support the accreditation package without owning the package yourself.

Skills

IAM fluency
Service Control Policies
AWS Config rules
Python scripting
KMS policies
AWS Organizations
Data perimeter controls

Tools

AWS Config
AWS Lambda
AWS Systems Manager
KMS
CloudFormation (IaC)
AWS Organizations

Job description

CLOUD SECURITY | ACTIVE SECRET CLEARANCE REQUIRED, TS/SCI PREFERRED | U.S. CITIZENSHIP REQUIRED | REMOTE OR HYBRID (CONUS)
About the role

Guardrails are the difference between a cloud environment that is compliant on paper and one that stays compliant on a Tuesday afternoon when an engineer is in a hurry. This seat writes those guardrails. You will author the policies that make the insecure action impossible rather than merely discouraged, and you will do it in a multi-account AWS organization where a single misdrafted statement can lock out a mission team. The role is deliberately narrow and deeply technical. It is not an audit seat and it is not a documentation seat; a separate Security Authorization Lead owns the ATO package. What you own is the enforcement layer: service control policies, resource control policies, permission boundaries, config rules, key policies, and the automated remediation that closes findings without a human ticket.

What you will do
  • Author the policy layer. Write, test, and version Service Control Policies and Resource Control Policies across the AWS Organizations structure, including region locks and data perimeter controls.
  • Design permission boundaries. Build IAM permission boundaries and delegated administration models that let account owners move quickly inside a fenced blast radius.
  • Codify detection. Develop AWS Config rules and conformance packs mapped to the control set, and wire automated remediation through Systems Manager or Lambda.
  • Own the key material. Design KMS customer-managed key policies, rotation, grants, and cross-account access patterns that hold up under review.
  • Run Security Hub as a working queue. Tune standards and findings, suppress the noise with justification, and drive real remediation instead of dashboard maintenance.
  • Prove the guardrails work. Build test cases that attempt the prohibited action and confirm the policy denies it, then keep those tests running as the environment changes.
  • Partner with the authorization team. Supply the technical evidence, artifacts, and control narratives that support the accreditation package without owning the package yourself.
Required Qualifications
  • Active Secret clearance or higher.
  • U.S. citizenship.
  • Hands-on experience in a multi-account AWS Organizations environment, including OU design and account structure.
  • Demonstrated authorship of Service Control Policies, and familiarity with Resource Control Policies and data perimeter patterns.
  • Deep IAM fluency: roles, trust policies, condition keys, and permission boundaries.
  • Production experience with AWS Config rules, conformance packs, and automated remediation.
  • Working knowledge of KMS key policies and encryption controls.
  • Infrastructure as code proficiency, since guardrails are deployed and versioned as code rather than clicked into a console.
Preferred Qualifications
  • AWS GovCloud, IL4, IL5, or classified region experience.
  • Landing Zone Accelerator or Control Tower deployment experience.
  • Familiarity with NIST SP 800-53 and the DoD Cloud Computing Security Requirements Guide.
  • AWS Certified Security Specialty, or Solutions Architect Associate or Professional.
  • CompTIA Security+ (Sec+ CE) or an equivalent DoD 8140 baseline certification.
  • Scripting depth in Python for custom rules, remediation, and policy testing.
Working environment

The seat is remote or hybrid within the continental United States, depending on the supported program. Some engagements require periodic on-site presence for accreditation activities.

Cleared engineers with this skill set are placed from D9Tech’s bench. Applying while you are still under contract elsewhere is normal and expected; we track availability rather than assume it.

About D9Tech Resources

D9Tech Resources is a Service-Disabled Veteran-Owned Small Business and SBA 8(a) participant delivering cleared cloud, cybersecurity, network, data, and AI engineering to Federal and Department of Defense customers. Bench engineers are interviewed, verified, and kept ready, so that when a billet opens we place a known quantity instead of starting a search.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cloud Guardrails Engineer — Remote/Hybrid, Secret Clearance
Cloud Guardrails Engineer — Remote/Hybrid, Secret Clearance

D9Tech Resources LLC • Arlington (VA)

Hybrid
USD 140,000 - 210,000
Security Engineer, Cloud Security
Security Engineer, Cloud Security

Saronic • San Diego (CA)

On-site
USD 140,000 - 210,000
Security Authorization Lead (RMF and ATO) with Security Clearance
Security Authorization Lead (RMF and ATO) with Security Clearance

D9Tech Resources LLC • Arlington (VA)

Hybrid
USD 120,000 - 150,000
AWS Cloud Engineer
AWS Cloud Engineer

D2 Consulting • Springfield (VA)

On-site
USD 140,000 - 150,000
Health benefits
401(k) match
PTO
+2
Cloud Security Engineer
Cloud Security Engineer

apex-technology-inc • Los Angeles (CA)

On-site
USD 180,000 - 240,000
AWS Cloud Engineer
AWS Cloud Engineer

D2 Consulting • St. Louis (MO)

On-site
USD 130,000 - 140,000
Health/Dental/Vision
401(k) match
PTO accrual
+3
Security Engineer
Security Engineer

qualityworksconsulting • Los Angeles (CA)

On-site
USD 120,000 - 150,000
AWS Cloud Engineer
AWS Cloud Engineer

D2 Technical Services • Springfield (VA)

On-site
USD 140,000 - 150,000
Health/Dental/Vision
401(k) match
PTO
+2
Cloud Security Engineer (DevOps)- Active Clearance is required
Cloud Security Engineer (DevOps)- Active Clearance is required

Liberty Personnel Services, Inc. • Westminster (CO)

On-site
USD 140,000 - 170,000
Security Engineer
Security Engineer

QualityWorks Consulting Group, LLC • Los Angeles (CA)

On-site
USD 124,000 - 207,000