Senior Cloud Infrastructure Consultant (Active TS/SCI)

cginfinity

Chantilly (VA)

On-site

USD 180,000 - 230,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

CG Infinity is seeking a Senior Cloud Infrastructure Consultant to design and stand up secure AWS Landing Zones in air‑gapped, classified regions, serving as the foundational platform for mission applications.

You will implement Terraform modules, configure VPCs, and harden IAM, aligning with RMF/ATO requirements and DoD/IC accreditation standards. This hands‑on role emphasizes secure, auditable deployments within SCIF environments.

Qualifications

  • U.S. Citizenship and active Top Secret / SCI clearance.
  • Five (5) or more years of hands-on AWS engineering experience.
  • Demonstrated experience designing multi-account AWS architectures and AWS Landing Zone patterns.
  • Advanced AWS networking knowledge: VPC design, Transit Gateway, PrivateLink, hybrid DNS, and on‑premises connectivity patterns.
  • Proficiency with Infrastructure-as-Code, specifically Terraform and/or AWS CloudFormation.
  • Experience implementing AWS security controls, IAM at scale, KMS, audit logging, and resource‑based policies.
  • Familiarity working in classified or highly regulated environments and producing artifacts suitable for compliance review.
  • Bachelor's degree in Computer Science, Engineering, or a related discipline — or equivalent professional experience.
  • Clear written and verbal communication skills for technical documentation, stakeholder coordination, and customer‑facing delivery.

Responsibilities

  • Design and deploy AWS Landing Zones in air‑gapped, classified regions, including AWS Control Tower equivalents and account‑vending automation.
  • Architect multi‑account AWS organizations with appropriate OU structure, SCPs, and tag governance.
  • Build and maintain Infrastructure-as‑Code modules in Terraform (and AWS CloudFormation where required) for repeatable, auditable deployments.
  • Configure VPCs, subnets, route tables, Transit Gateways, VPC endpoints, DNS (Route 53 / hybrid resolvers), and private connectivity to on‑premises enclaves.
  • Implement IAM policies, permission boundaries, role federation, and break‑glass procedures aligned to least‑privilege principles.
  • Stand up centralized logging, audit, and monitoring (CloudTrail, Config, GuardDuty, Security Hub, CloudWatch) and integrate with the customer’s SIEM.
  • Integrate the cloud platform with enterprise identity (ICAM; PIV; CAC) and compliance tooling.
  • Collaborate with AWS Professional Services, mission application teams, and RMF/ATO authorizing officials.
  • Produce architecture diagrams, runbooks, and design decision records suitable for ATO body‑of‑evidence packages.

Skills

AWS engineering
Terraform
CloudFormation
Networking
IAM security
SCIF compliance
Scripting (Python/PowerShell)
Documentation

Education

Bachelor's degree in CS/Engineering or equivalent

Tools

AWS CloudFormation
CI/CD tooling (GitLab/Jenkins)
VPC/Transit Gateway tooling

Job description

SENIOR CLOUD INFRASTRUCTURE CONSULTANT

Location: 100% on site in Chantilly, VA

Active TS/SCI clearance verifiable in DISS required. The Senior Cloud Infrastructure Consultant will work in a Secured Compartmentalized Information Facility (SCIF).

POSITION SUMMARY

CG Infinity is expanding our AWS Professional Services delivery team to support a high-priority national-security program. As a Senior Cloud Infrastructure Consultant, you will design and stand up secure, multi-account AWS Landing Zones in air-gapped and classified regions that serve as the foundational platform for downstream mission applications. You will partner directly with AWS Professional Services architects and government technical leads, owning architecture decisions across networking, identity, security, and automation.

This is a hands‑on engineering role: you will write Terraform, configure VPCs and Transit Gateways, harden IAM, and deploy logging and audit pipelines that satisfy DoD/IC accreditation requirements. The work directly enables Authority to Operate (ATO) and accelerates the customer's adoption of cloud‑native capabilities.

KEY RESPONSIBILITIES
  • Design and deploy AWS Landing Zones in air‑gapped, classified regions, including AWS Control Tower equivalents and account‑vending automation.
  • Architect multi‑account AWS organizations with appropriate Organizational Unit (OU) structure, Service Control Policies (SCPs), and tag governance.
  • Build and maintain Infrastructure-as‑Code modules in Terraform (and AWS CloudFormation where required) for repeatable, auditable deployments.
  • Configure VPCs, subnets, route tables, Transit Gateways, VPC endpoints, DNS (Route 53 / hybrid resolvers), and private connectivity to on‑premises enclaves.
  • Implement IAM policies, permission boundaries, role federation, and break‑glass procedures aligned to least‑privilege principles.
  • Stand up centralized logging, audit, and monitoring (CloudTrail, Config, GuardDuty, Security Hub, CloudWatch) and integrate with the customer's SIEM.
  • Integrate the cloud platform with enterprise identity (e.g., Identity, Credential, and Access Management (ICAM); Personal Identity Verification (PIV); Common Access Card (CAC)) and compliance tooling.
  • Collaborate with AWS Professional Services, mission application teams, and the customer's Risk Management Framework (RMF) / Authority to Operate (ATO) authorizing officials.
  • Produce architecture diagrams, runbooks, and design decision records suitable for ATO body‑of‑evidence packages.
REQUIRED QUALIFICATIONS
  • U.S. Citizenship and active Top Secret / SCI clearance.
  • Five (5) or more years of hands‑on AWS engineering experience, including building environments from inception (greenfield).
  • Demonstrated experience designing multi‑account AWS architectures and AWS Landing Zone patterns.
  • Advanced AWS networking knowledge: VPC design, Transit Gateway, PrivateLink, hybrid DNS, and on‑premises connectivity patterns.
  • Proficiency with Infrastructure-as-Code, specifically Terraform and/or AWS CloudFormation, including module design and state management.
  • Experience implementing AWS security controls, IAM at scale, KMS, audit logging, and resource‑based policies.
  • Familiarity working in classified or highly regulated environments and producing artifacts suitable for compliance review.
  • Bachelor's degree in Computer Science, Engineering, or a related discipline — or equivalent professional experience.
  • Clear written and verbal communication skills for technical documentation, stakeholder coordination, and customer‑facing delivery.
PREFERRED QUALIFICATIONS
  • Prior delivery experience in AWS GovCloud (US), AWS Secret Region / AWS Secret‑West, or AWS Top Secret‑East/West.
  • Working knowledge of DISA STIGs, NIST SP 800‑53 / 800‑171, and the DoD Cloud Computing Security Requirements Guide (SRG).
  • Direct experience supporting Risk Management Framework (RMF) / Authority to Operate (ATO) packages (SSP, control implementation, POA&M).
  • Experience with CI/CD for infrastructure (GitLab CI, Jenkins, AWS CodePipeline).
  • Scripting in Python or PowerShell for automation and integration tasks.
PREFERRED CERTIFICATIONS
  • AWS Certified Solutions Architect – Professional
  • AWS Certified Advanced Networking – Specialty
  • AWS Certified Security – Specialty
  • HashiCorp Certified: Terraform Associate
  • HashiCorp Certified: Terraform Authoring & Operations Professional
WORK ENVIRONMENT & PHYSICAL REQUIREMENTS

Onsite work within a Sensitive Compartmented Information Facility (SCIF). Mobile devices are not permitted in the work area.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cloud Infrastructure Architect - AWS (TS/SCI Clearance Required)
Cloud Infrastructure Architect - AWS (TS/SCI Clearance Required)

North Point Technology • Washington

On-site
USD 130,000 - 170,000
Cloud Infrastructure Architect - AWS (TS/SCI Clearance Required)
Cloud Infrastructure Architect - AWS (TS/SCI Clearance Required)

North-Point-Technology • Washington

On-site
USD 180,000 - 240,000
Senior Cloud Infrastructure Architect — SCIF Onsite
Senior Cloud Infrastructure Architect — SCIF Onsite

cginfinity • Chantilly (VA)

On-site
USD 180,000 - 230,000
Cloud Engineer (TS/SCI with Poly Required)
Cloud Engineer (TS/SCI with Poly Required)

GCI Incorporated • Chantilly (VA)

On-site
USD 120,000 - 180,000
Senior Cloud Infrastructure Engineer
Senior Cloud Infrastructure Engineer

Global Solutions Consulting LLC. • Washington

Hybrid
USD 120,000 - 150,000
Continuous learning environment
Professional growth opportunities
Modern enterprise technology stack
Cloud Engineer - AWS (Top Secret Clearance Required)
Cloud Engineer - AWS (Top Secret Clearance Required)

North Point Technology • St. Louis (MO)

On-site
USD 90,000 - 125,000
Lead Cloud Architect (2026-0135)
Lead Cloud Architect (2026-0135)

acclaimtechnicalservices • Chantilly (VA)

On-site
USD 140,000 - 180,000
Lead Cloud Architect (2026-0135)
Lead Cloud Architect (2026-0135)

Acclaim Technical Services, Inc. • Chantilly (VA)

On-site
USD 130,000 - 160,000
TS/SCI CI Poly Cloud Engineer
TS/SCI CI Poly Cloud Engineer

Insight Global • Chantilly (VA)

On-site
USD 110,208 - 130,872
Senior Cloud Engineer (AWS, Azure, Oracle and GCP cloud services)
Senior Cloud Engineer (AWS, Azure, Oracle and GCP cloud services)

CACI International Inc • Chantilly (VA)

On-site
USD 120,000 - 266,000
Healthcare
Continuing education
Retirement benefits