Security Compliance Engineer, Region Services Corporate Infrastructure

Amazon Web Services (AWS)

Seattle (WA)

On-site

USD 117,000 - 167,000

Full time

7 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

RSUs and sign-on payments
Comprehensive benefits (health, dental
401(k) matching

Job summary

Amazon Web Services (AWS) is seeking a Security Compliance Engineer to monitor vulnerability scans, drive remediation, and ensure DISA STIG and RMF compliance for RMNA networks. You will run Tenable/Nessus, assess findings, and build automation to streamline scoring and reporting.

The role requires active TS/SCI clearance with polygraph and Windows infrastructure knowledge to determine real risk and coordinate with service owners for remediation and accreditation packages.

Qualifications

  • 3+ years of systems administration (Linux or Windows) experience.
  • Knowledge of configuration management systems (Puppet, Chef, Ansible).
  • Active TS/SCI security clearance with polygraph.

Responsibilities

  • Operate Tenable/Nessus scanning infrastructure across multiple environments.
  • Analyze vulnerability results and drive remediation with service teams.
  • Build and maintain security dashboards and compliance artifacts.

Skills

System administration
Configuration management
Security clearance TS/SCI
Vulnerability scanning

Education

Associate degree or Cloud+ or GICSP or GSEC or SSCP

Tools

Puppet
Chef
Ansible

Job description

Description

Region Services Corporate Infrastructure (RSCI) delivers foundational Windows infrastructure services across Amazon Dedicated Cloud (ADC) environments

Description

Region Services Corporate Infrastructure (RSCI) delivers foundational Windows infrastructure services across Amazon Dedicated Cloud (ADC) environments

supporting U.S. Government customers. Our team owns Active Directory, File Services, DHCP, DNS, Enterprise Configuration Manager (ECM), Group Policy, and desktop services that AWS service teams depend on.

We are looking for a Security Compliance Engineer who can monitor, assess, and drive security compliance across our Remote Management and
Administration (RMNA) networks. You will operate vulnerability scanning infrastructure, analyze results, drive service teams to remediation, and ensure our environments maintain compliance with DISA STIGs and the Risk Management Framework (RMF). You will develop and maintain dashboards that give leadership and external security stakeholders clear visibility into our compliance posture, and produce scan data that feeds directly into customer authorization systems.

This is a hands-on role. You will run and analyze Tenable/Nessus scans, track vulnerabilities to closure, develop automation to streamline compliance workflows, build and maintain security dashboards, support our comply-to-connect solution, and contribute to security accreditation packages for services within RSCI. You need to understand Windows infrastructure deeply enough to assess whether a finding is a real risk or a false positive and to drive the right remediation with service owners.

This position requires that the candidate selected must currently possess and maintain an active TS/SCI security clearance with polygraph. The position further requires the candidate to opt into a commensurate clearance for each government agency for which they perform AWS work.

Key job responsibilities
  • Operate and maintain Tenable Security Center and Nessus scanning infrastructure across multiple isolated ADC environments
  • Conduct vulnerability scans, analyze results, and drive service teams to patch compliance within SLA thresholds (Critical/High: 30 days, Moderate: 90 days, Low: 180 days)
  • Develop, operate, and maintain the comply-to-connect solution for RMNA networks
  • Assess environments against DISA STIGs for Windows 11, Windows Server, Microsoft Exchange, and Skype for Business; identify and track compliance gaps
  • Build and maintain security compliance dashboards providing real-time visibility into host health, patch status, and SLA compliance
  • Produce scan data and compliance artifacts for ingestion by AWS security teams and external customer authorization systems
  • Conduct threat assessments against RMNA infrastructure including Ansible automation workflows
  • Contribute to and maintain security accreditation packages (RMF A&A documentation) for RMNA
  • Develop Ansible playbooks and PowerShell automation to streamline compliance scanning, reporting, and remediation tracking
  • Partner with A&A to review and validate scan data prior to customer delivery
  • Create and maintain runbooks, compliance procedures, and standard operating procedures
  • Participate in on-call rotation for security and compliance events
  • Participate in weekly operations meetings reviewing Tenable dashboards and SLA compliance with service managers
Basic Qualifications
  • Associate's degree or above, or Cloud+ or GICSP (Global Industrial Cyber Security Professional) or GSEC (GIAC Security Essentials) or SSCP (Systems Security Certified Practitioner)
  • Knowledge of configuration management systems, such as Puppet, Chef, Ansible, or related systems
  • 3+ years of systems administration (Linux or Windows) experience
  • Current, active US Government Security Clearance of TS/SCI with Polygraph
Preferred Qualifications
  • 3+ years of work with networking fundamentals or Internet protocols such as TCP/IP, UDP, SSL, DNS, HTTP/S, or equivalent experience

Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status.

Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit https://amazon.jobs/content/en/how-we-hire/accommodations for more information. If the country/region you’re applying in isn’t listed, please contact your Recruiting Partner.

The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits.

USA, VA, Arlington - 116,900.00 - 167,400.00 USD annually

USA, VA, Herndon - 116,900.00 - 167,400.00 USD annually

USA, WA, Seattle - 116,900.00 - 167,400.00 USD annually

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Compliance Engineer, Region Services Corporate Infrastructure
Security Compliance Engineer, Region Services Corporate Infrastructure

Amazon Web Services (AWS) • Arlington (VA)

On-site
USD 117,000 - 167,000
Health insurance
401(k) matching
Paid time off
+2
Security Compliance Engineer, Region Services Corporate Infrastructure
Security Compliance Engineer, Region Services Corporate Infrastructure

Socket.dev • Seattle (WA)

On-site
USD 117,000 - 167,000
Security & Compliance Engineer II, AWS Security Assurance Services, LLC
Security & Compliance Engineer II, AWS Security Assurance Services, LLC

Amazon Web Services (AWS) • Dallas (TX)

On-site
USD 159,000 - 203,000
Health insurance
401(k) matching
Security & Compliance Engineer II, AWS Security Assurance Services, LLC
Security & Compliance Engineer II, AWS Security Assurance Services, LLC

Amazon • Seattle (WA)

On-site
USD 159,300 - 202,400
Sec & Compliance Eng Mgr, AWS Security Assurance Services, LLC
Sec & Compliance Eng Mgr, AWS Security Assurance Services, LLC

Amazon Web Services (AWS) • Seattle (WA)

On-site
USD 175,000 - 237,000
Security & Compliance Engineer II, AWS Security Assurance Services, LLC
Security & Compliance Engineer II, AWS Security Assurance Services, LLC

Amazon Web Services (AWS) • Houston (TX)

On-site
USD 159,300 - 202,400
Sec & Compliance Eng Mgr, AWS Security Assurance Services, LLC
Sec & Compliance Eng Mgr, AWS Security Assurance Services, LLC

Amazon Web Services (AWS) • Arlington (VA)

On-site
USD 175,000 - 237,000
Security & Compliance Engineer II, AWS Security Assurance Services, LLC
Security & Compliance Engineer II, AWS Security Assurance Services, LLC

Amazon Web Services (AWS) • Seattle (WA)

On-site
USD 150,000 - 190,000
Health insurance
401(k) matching
Paid time off
Sr. Security & Compliance Engineer, AWS Security Assurance Services, LLC
Sr. Security & Compliance Engineer, AWS Security Assurance Services, LLC

Amazon Web Services (AWS) • Herndon (VA)

On-site
USD 178,000 - 227,000
Sec & Compliance Eng Mgr, AWS Security Assurance Services, LLC
Sec & Compliance Eng Mgr, AWS Security Assurance Services, LLC

Amazon Web Services (AWS) • Dallas (TX)

On-site
USD 175,000 - 237,000