Security Engineer

The Phoenix Group

Arlington (VA)

On-site

USD 100,000 - 150,000

Full time

2 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

The Phoenix Group is seeking a junior DevOps/SRE security engineer to implement cloud security controls across AWS/GCP/Azure. You will apply IaC with Terraform, manage IAM and secrets, and support monitoring and incident response to maintain compliance.

You'll work under senior engineers to verify least privilege, automate pipelines with GitHub Actions or GitLab CI, and help maintain dashboards in Grafana and CloudWatch. Arlington, VA-based role.

Qualifications

  • 1+ years of experience in DevOps, SRE or Security Engineering capacity.
  • Proficiency in Linux command-line environment (Bash), managing system logs, permissions, and basic troubleshooting.
  • Foundational understanding of networking concepts (DNS, TCP/IP, HTTP/HTTPS, SSH, subnets, firewalls).
  • Basic exposure to cloud platforms (AWS preferred) and version control systems (Git, GitHub, GitLab).
  • Familiarity with scripting languages such as Python or Bash for automation.
  • Strong security awareness including principles like least privilege, multi-factor authentication, IAM, and encryption fundamentals.

Responsibilities

  • Monitor and verify the operational status of Zero Trust Network Access tools (e.g., Zscaler ZPA / Prowler).
  • Support secrets management workflows in HashiCorp Vault, including credential generation, secret updates, and automated rotation processes.
  • Review and confirm IAM policies, roles, and permissions align with least privilege principles under senior engineer oversight.
  • Execute, test, and troubleshoot Infrastructure as Code (IaC) modules using Terraform across cloud platforms (AWS, Azure, GCP).
  • Monitor and troubleshoot build and deployment pipelines in systems like GitHub Actions, GitLab CI, or Azure Pipelines.
  • Assist with container image security, building, and deployment for Kubernetes environments such as EKS, AKS, or GKE.
  • Support collection of audit evidence for FedRAMP Continuous Monitoring cycles, focusing on controls such as CM-2, CM-6, AU-2, and SC-12.
  • Maintain and optimize dashboards and metrics in Grafana and CloudWatch, ensuring alert configurations are accurate.
  • Perform low-severity system health checks and manage alert triaging to prevent alert fatigue
  • Support open telemetry operations for real-time application and system monitoring. Core

Skills

DevOps
SRE
Security Engineering
Linux
Bash
Python
Networking
IAM
Encryption
Least privilege

Tools

Terraform
CloudFormation
Docker
Kubernetes
GitHub Actions
GitLab CI
Azure Pipelines
HashiCorp Vault
Zscaler ZPA
Prowler
Grafana
CloudWatch

Job description

Will assist in implementing and supporting cloud security protocols, infrastructure automation, and compliance programs across multiple cloud platforms. This position’s scope includes managing identity access, infrastructure as code, vulnerability management, monitoring, and incident response to ensure operational excellence and regulatory compliance.

Key Responsibilities
  • Monitor and verify the operational status of Zero Trust Network Access tools (e.g., Zscaler ZPA / Prowler).
  • Support secrets management workflows in HashiCorp Vault, including credential generation, secret updates, and automated rotation processes.
  • Review and confirm IAM policies, roles, and permissions align with least privilege principles under senior engineer oversight.
  • Execute, test, and troubleshoot Infrastructure as Code (IaC) modules using Terraform across cloud platforms (AWS, Azure, GCP).
  • Monitor and troubleshoot build and deployment pipelines in systems like GitHub Actions, GitLab CI, or Azure Pipelines.
  • Assist with container image security, building, and deployment for Kubernetes environments such as EKS, AKS, or GKE.
  • Support collection of audit evidence for FedRAMP Continuous Monitoring cycles, focusing on controls such as CM-2, CM-6, AU-2, and SC-12.
  • Maintain and optimize dashboards and metrics in Grafana and CloudWatch, ensuring alert configurations are accurate.
  • Perform low-severity system health checks and manage alert triaging to prevent alert fatigue
  • Support open telemetry operations for real-time application and system monitoring. Core
Qualifications & Requirements
  • 1+ years of experience in DevOps, SRE or Security Engineering capacity
  • Proficiency in Linux command-line environment (Bash), managing system logs, permissions, and basic troubleshooting.
  • Foundational understanding of networking concepts (DNS, TCP/IP, HTTP/HTTPS, SSH, subnets, firewalls).
  • Basic exposure to cloud platforms (AWS preferred) and version control systems (Git, GitHub, GitLab).
  • Familiarity with scripting languages such as Python or Bash for automation.
  • Strong security awareness including principles like least privilege, multi-factor authentication, IAM, and encryption fundamentals.
Nice-to-Have Qualifications
  • Experience with Infrastructure as Code tools (Terraform, CloudFormation).
  • Familiarity with container technologies (Docker) and CI/CD pipelines (GitHub Actions, GitLab CI).
  • Knowledge of ticketing and monitoring tools (Jira, ServiceNow, CloudWatch, Grafana).
  • Awareness of federal security standards (FedRAMP, NIST 800-53, SOC 2).
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Jr. DevSecOps Engineer
Jr. DevSecOps Engineer

Code Red Partners • Arlington (VA)

On-site
USD 60,000 - 85,000
Journeyman Cloud Security Engineer (Q Clearance)
Journeyman Cloud Security Engineer (Q Clearance)

ShorePoint • Las Vegas (NV)

On-site
USD 120,000 - 180,000
144 hours PTO
11 holidays
Insurance premiums covered 85%
+3
Security Engineer
Security Engineer

Enterprise Engineering Inc. (EEI) • New York (NY)

On-site
USD 120,000 - 160,000
Senior Security Engineer
Senior Security Engineer

Curate Partners • Boston (MA)

On-site
USD 120,000 - 160,000
Senior Security Engineer
Senior Security Engineer

Red Cup IT, Inc. • Los Angeles (CA)

On-site
USD 120,000 - 160,000
Journeyman Cloud Security Engineer (Q Clearance)
Journeyman Cloud Security Engineer (Q Clearance)

ShorePoint • Washington, Northern (KY)

Hybrid
USD 150,000 - 210,000
PTO 144 hours
11 holidays
Insurance premium coverage 85%
+4
Journeyman Cloud Security Engineer (Q Clearance) with Security Clearance
Journeyman Cloud Security Engineer (Q Clearance) with Security Clearance

ShorePoint, LLC • North Las Vegas (NV)

On-site
USD 120,000 - 180,000
PTO 144 hours
11 holidays
Health insurance 85% covered
+3
Cyber Cloud Security Engineer
Cyber Cloud Security Engineer

Pierce • New York (NY)

On-site
USD 140,000 - 190,000
Sr. Security Engineer
Sr. Security Engineer

California Water Service • San Jose (CA)

On-site
USD 180,000 - 240,000
Sr Network Security Engineer
Sr Network Security Engineer

brobstongroup.com - Jobboard • Seattle (WA)

Hybrid
USD 120,000 - 160,000