Central Strategies is seeking a Senior Information System Security Engineer (ISSE) to support cloud modernization initiatives for the United States Coast Guard (USCG) at the Command, Control, Communication, Computer, Cyber, and Intelligence Service Center in the Alexandria, Virginia area. The ISSE will provide senior-level security engineering leadership for secure, scalable cloud environments supporting mission-critical Coast Guard capabilities.
This position will lead the design, implementation, and governance of cloud security solutions across AWS and Azure environments. The ISSE will work closely with cloud engineers, cybersecurity personnel, compliance teams, operations staff, and program leadership to protect the confidentiality, integrity, and availability of cloud-hosted systems while enabling secure modernization and operational resilience.
The role combines cloud security architecture, NIST Risk Management Framework (RMF) modernization, authorization-to-operate support, DevSecOps security integration, continuous monitoring, and cross-functional technical leadership.
Work Location: Hybrid in Alexandria, Virginia. Full-time, day shift; up to 25% travel may be required.
Key Responsibilities
Cloud Security Architecture & Engineering
- Architect, implement, and improve secure cloud infrastructure across AWS and Microsoft Azure environments.
- Establish cloud security architecture patterns, technical standards, guardrails, and automated controls that support secure enterprise adoption.
- Design and support identity and access management, encryption, key management, network security, and workload-protection capabilities for cloud-hosted systems.
- Apply cloud-native security controls and shared-responsibility principles to system design, implementation, and operations.
- Lead threat modeling, security risk assessments, and security engineering analysis for cloud-native applications, services, and infrastructure.
- Support federal Authorization to Operate (ATO) modernization efforts, including transition of applicable controls and documentation from NIST RMF Revision 4 to Revision 5.
- Develop, update, and maintain System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), security architecture documentation, and related compliance artifacts.
- Support continuous ATO (cATO) practices by integrating evidence collection, control monitoring, automation, and repeatable security validation into the delivery lifecycle.
- Ensure cloud security engineering activities remain aligned with applicable federal, DHS, USCG, and program security requirements.
DevSecOps, Automation & Platform Security
- Integrate security controls, testing, and policy enforcement into CI/CD pipelines and DevOps workflows.
- Use infrastructure-as-code and configuration-management technologies such as Terraform, Ansible, or Puppet to promote secure, repeatable cloud deployments.
- Support secure containerization and orchestration using technologies such as Docker and Kubernetes.
- Develop or apply scripting and automation using technologies such as Python, Bash, or PowerShell to improve security operations, compliance, and engineering efficiency.
Cloud Security Operations & Continuous Monitoring
- Monitor cloud environments using security information and event management (SIEM), cloud security posture management (CSPM), cloud workload protection platforms (CWPP), and related security tooling.
- Support incident response and technical investigation for cloud security events and vulnerabilities.
- Assess emerging cloud threats, vulnerabilities, and attack patterns and recommend practical mitigation strategies.
- Promote continuous improvement through technical feedback loops, process refinement, and security engineering lessons learned.
- Collaborate across cloud engineering, cybersecurity, compliance, operations, and program management teams to enable secure cloud modernization.
- Facilitate technical discussions, security reviews, and stakeholder coordination across engineering and mission organizations.
- Translate security requirements and risk decisions into actionable architecture, engineering, and operational guidance.
- Ensure security engineering activities support USCG mission priorities, program delivery objectives, and enterprise modernization goals.
Required Qualifications
- Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, Engineering, Business, or a related field with 12+ years of relevant experience; or a Master’s degree with 10+ years of relevant experience. Additional experience may be considered in lieu of a degree; a doctorate in a technical discipline may also qualify.
- Extensive experience in information security engineering, cloud security architecture, cybersecurity engineering, or closely related technical disciplines.
- Deep hands-on knowledge of AWS and Azure security services, architecture, and cloud-native security controls.
- Strong understanding of cloud shared-responsibility models and security engineering for enterprise cloud environments.
- Experience with infrastructure-as-code, configuration management, or orchestration tools such as Terraform, Ansible, or Puppet.
- Hands-on experience with containerization and orchestration technologies such as Docker and Kubernetes.
- Current cloud-security certification such as CCSP, AWS Certified Security – Specialty, or Microsoft Azure Security Engineer Associate.
- Demonstrated experience supporting ATO modernization or upgrades involving NIST RMF Revision 4 to Revision 5, including control-family transition and mapping activities.
- Experience developing and maintaining federal cybersecurity artifacts, including SSPs, SARs, POA&Ms, and security architecture documentation.
- Experience supporting continuous ATO (cATO) or comparable continuous authorization practices for federal information systems.
- Excellent facilitation, written and verbal communication, and stakeholder-engagement skills.
- Ability to perform effectively in a fast-paced, mission-focused technical environment.
- Ability to obtain and maintain a Public Trust and a DoD Secret clearance.
Preferred Qualifications
- Experience applying zero trust principles and secure multi-cloud architecture strategies.
- Experience with compliance frameworks or security requirements such as FedRAMP, SOC 2, HIPAA, or PCI DSS.
- Experience using automation or governance platforms such as RegScale to support cATO, evidence collection, or continuous compliance.
- Proficiency with Python, Bash, PowerShell, or other scripting and security-automation technologies.
- Familiarity with UiPath or related automation platforms.
- Prior experience supporting DHS, USCG, DoD, or other federal cloud modernization programs.
- Experience working with multidisciplinary teams spanning cloud engineering, cybersecurity, enterprise IT, compliance, and program management.
Desired Certifications
- DoD 8570/8140-aligned certification appropriate to the position level, including applicable IAT, IAM, or IASAE categories.
- Security+
- CISSP
- CASP+ CE
- ISSEP