Senior Cloud Security Engineer

Steampunk

McLean (VA)

On-site

USD 130,000 - 180,000

Full time

3 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Steampunk is seeking a Senior Cloud Security Engineer to design, implement, and maintain secure AWS cloud environments across the system lifecycle. You will lead security controls, IAM, vulnerability management, data protection, and continuous monitoring in collaboration with DevSecOps and cybersecurity teams.

The role requires strong hands-on AWS security, risk assessment, and threat modeling experience, plus ability to mentor juniors and work within federal contracting contexts.

Qualifications

  • Bachelor's degree and 10+ years of total experience.
  • 5+ years of experience architecting, designing, developing, implementing, or securing cloud solutions.
  • 5+ years of experience with cloud platforms, including AWS.
  • Experience implementing cloud security architecture, controls, and security best practices in AWS environments.
  • Experience with Cloud-Native Application Protection Platform (CNAPP) or Cloud Security Posture Management (CSPM) solutions.
  • Experience with identity and access management (IAM), authentication, authorization, and least-privilege security principles in cloud environments.
  • Experience identifying, assessing, tracking, and supporting remediation of cloud vulnerabilities and security misconfigurations.
  • Experience conducting security monitoring, risk assessments, threat modeling, and security testing in cloud environments.
  • Experience implementing or supporting continuous security monitoring and vulnerability management processes.
  • Experience with infrastructure as code and orchestration.
  • Experience analyzing technical security findings and identifying appropriate remediation or risk mitigation actions.
  • Experience collaborating across cloud, DevSecOps, software engineering, and cybersecurity teams to implement and maintain security controls.
  • Strong analytical, troubleshooting, problem-solving, communication, and collaboration skills.
  • Current AWS certification.

Responsibilities

  • Design and implement secure cloud architectures and technical solutions with security requirements incorporated throughout the system lifecycle.
  • Identify and implement secure cloud-based solutions, including components supporting zero-trust architectures, identity and access management, and data protection.
  • Implement and maintain IAM controls, including authentication, authorization, and least-privilege access.
  • Assess and harden cloud environments, configurations, authentication mechanisms, and authorization controls.
  • Identify, assess, document, and track vulnerabilities and cloud security risks across systems and environments.
  • Partner with cloud engineers, software engineers, DevSecOps engineers, cybersecurity teams, and other stakeholders to prioritize and remediate vulnerabilities and security weaknesses.
  • Implement and support cloud security posture and application protection to identify misconfigurations, vulnerabilities, and excessive permissions.
  • Monitor cloud environments for suspicious activity using cloud-native monitoring, SIEM, and other security solutions and investigate events.
  • Conduct risk assessments, threat modeling, and security testing to identify and mitigate cloud security risks.
  • Automate security processes, including vulnerability management and configuration assessment.
  • Support enterprise cloud security through infrastructure as code and large-scale deployments.
  • Evaluate infrastructure as code and cloud configurations for security risks and remediation.
  • Design and implement data protection and encryption mechanisms for data at rest and in transit.
  • Document the as-is state of cloud environments, perform gap analyses, and produce options and recommendations.
  • Evaluate changes for security impacts.
  • Provide technical guidance and mentorship to junior team members.
  • Engineer and implement cloud security solutions and provide recommendations for continuous improvement.
  • Present regular status updates and cross-train team members.
  • Maintain awareness of evolving cloud vulnerabilities, threats, security technologies, and practices.

Skills

Cloud security
AWS
IAM
Vulnerability management
Security monitoring
Threat modeling
Automation
Infrastructure as code
Scripting (Bash/PowerShell/Python)
Team collaboration
Communication

Education

Bachelor's degree

Tools

CNAPP
CSPM
Wiz
Palo Alto Cortex
Terraform
CloudFormation
Ansible

Job description

Overview

As a Senior Cloud Security Engineer, you will work with our team and clients to design, implement, and maintain secure cloud environments and architectures. You will support cloud security across the system lifecycle, including security architecture, identity and access management, vulnerability management, data protection, continuous monitoring, and the implementation of cloud security controls.

We are looking for an experienced cloud security professional with strong hands‑on experience securing AWS environments and implementing cloud‑native and third‑party security solutions. The ideal candidate will bring strong analytical and problem‑solving skills and the ability to collaborate across technical teams to identify risks, implement security controls, and continuously improve the security posture of cloud environments.

Contributions

Responsibilities include:

  • Design and implement secure cloud architectures and technical solutions with security requirements incorporated throughout the system lifecycle.

  • Identify and implement secure cloud‑based solutions, including components supporting zero‑trust architectures, identity and access management, and data protection.

  • Implement and maintain identity and access management (IAM) controls, including authentication, authorization, and least‑privilege access.

  • Assess and harden cloud environments, configurations, authentication mechanisms, and authorization controls.

  • Identify, assess, document, and track vulnerabilities and cloud security risks across systems and environments.

  • Partner with cloud engineers, software engineers, DevSecOps engineers, cybersecurity teams, and other technical stakeholders to prioritize and remediate vulnerabilities and security weaknesses.

  • Implement and support cloud security posture and application protection capabilities to identify misconfigurations, vulnerabilities, excessive permissions, and other cloud security risks.

  • Monitor cloud environments for suspicious activity using cloud‑native monitoring, SIEM, and other security solutions and investigate security events as appropriate.

  • Conduct risk assessments, threat modeling, and security testing to identify and mitigate cloud security risks.

  • Automate security processes, including vulnerability management, configuration assessment, and other cloud security activities.

  • Support enterprise cloud security through infrastructure as code, including automated server and network configurations, large‑scale deployments, monitoring, and testing.

  • Evaluate infrastructure as code and cloud configurations to identify security risks and recommend appropriate remediation.

  • Design and implement data protection and encryption mechanisms for data at rest and in transit.

  • Document the as‑is state of cloud environments, perform gap analyses, and produce artifacts that articulate options and recommendations.

  • Evaluate technical changes and cloud configurations for potential security impacts.

  • Provide technical guidance and mentorship to junior team members.

  • Engineer and implement cloud security solutions and provide recommendations for continuous improvement.

  • Present regular status updates and provide cross‑training to other team members.

  • Maintain awareness of evolving cloud vulnerabilities, threats, security technologies, and cloud security engineering practices.

Qualifications
  • Ability to obtain and maintain a U.S. government security clearance.

  • Bachelor's degree and 10+ years of total experience.

  • 5+ years of experience architecting, designing, developing, implementing, or securing cloud solutions.

  • 5+ years of experience with cloud platforms, including AWS.

  • Experience implementing cloud security architecture, controls, and security best practices in AWS environments.

  • Experience with Cloud‑Native Application Protection Platform (CNAPP) or Cloud Security Posture Management (CSPM) solutions.

  • Experience with identity and access management (IAM), authentication, authorization, and least‑privilege security principles in cloud environments.

  • Experience identifying, assessing, tracking, and supporting remediation of cloud vulnerabilities and security misconfigurations.

  • Experience conducting security monitoring, risk assessments, threat modeling, and security testing in cloud environments.

  • Experience implementing or supporting continuous security monitoring and vulnerability management processes.

  • Experience with infrastructure as code and orchestration.

  • Experience analyzing technical security findings and identifying appropriate remediation or risk mitigation actions.

  • Experience collaborating across cloud, DevSecOps, software engineering, and cybersecurity teams to implement and maintain security controls.

  • Strong analytical, troubleshooting, problem‑solving, communication, and collaboration skills.

  • Current AWS certification.

Preferred:

  • Experience with Wiz, Palo Alto Cortex, or similar cloud security platforms.

  • Experience with Data Security Posture Management (DSPM) tools and practices.

  • Certified Information Systems Security Professional (CISSP) or other relevant cybersecurity certification.

  • Experience working within federal government or other highly regulated environments.

  • Knowledge of federal cybersecurity requirements, security controls, and continuous monitoring practices.

  • Experience documenting an as‑is state of the environment, performing gap analyses, and producing artifacts that articulate options and recommendations.

  • Experience with scripting in Bash, PowerShell, Python, Groovy, Ruby, or similar languages.

  • Experience with automation and infrastructure‑as‑code tools such as Chef, Terraform, CloudFormation, or Ansible.

About steampunk

Steampunk relies on several factors to determine salary, including but not limited to geographic location, contractual requirements, education, knowledge, skills, competencies, and experience. The projected compensation range for this position is $130,000 to $180,000. The estimate displayed represents a typical annual salary range for this position. Annual salary is just one aspect of Steampunk's total compensation package for employees. Learn more about additional Steampunk benefits here.

Identity Statement

As part of the application process, you are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud.

Steampunk is aChange Agentin the Federal contracting industry, bringing new thinking to clients in the Homeland, Federal Civilian, Health and DoD sectors. Through ourHuman-Centered delivery methodology, we are fundamentally changing the expectations our Federal clients have for true shared accountability in solving their toughest mission challenges.If you want to learn more about our story, visithttp://www.steampunk.com.

We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status, or any other characteristic protected by law.Steampunk participates in the E-Verify program.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Cloud Security Engineer
Senior Cloud Security Engineer

Steampunk • Washington

On-site
USD 130,000 - 180,000
Cloud Security Engineer
Cloud Security Engineer

Steampunk • Washington

On-site
USD 100,000 - 155,000
AWS/Azure/GCP certifications
Tuition for certifications
Health insurance
+1
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Steampunk, Inc. • Washington

On-site
USD 130,000 - 180,000
Cybersecurity/Technical Engineer
Cybersecurity/Technical Engineer

Steampunk • McLean (VA)

On-site
USD 85,000 - 170,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Steampunk • McLean (VA)

On-site
USD 150,000 - 185,000
Cybersecurity/Technical Engineer
Cybersecurity/Technical Engineer

Steampunk, Inc. • McLean (VA)

On-site
USD 85,000 - 170,000
Cloud Security Engineer
Cloud Security Engineer

Steampunk, Inc. • McLean (VA)

On-site
USD 110,000 - 155,000
Employee owned
Salary range disclosed
AWS Cloud Architect
AWS Cloud Architect

Steampunk • McLean (VA)

On-site
USD 130,000 - 215,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Steampunk • Bloomington (IL)

On-site
USD 90,000 - 165,000
Senior DevSecOps (Pipeline) Engineer
Senior DevSecOps (Pipeline) Engineer

Steampunk • Bloomington (IL)

On-site
USD 150,000 - 185,000