user avatar

AWS Cloud Security and Identity Engineer

D9Tech Resources, LLC

Posted today

Job Requirements

Remote
Secret Polygraph not specified
Mid Level Career (5+ yrs experience)
$180,000 - $200,000

Job Description

CLOUD ENGINEERING | ACTIVE SECRET CLEARANCE REQUIRED | U.S. CITIZENSHIP REQUIRED | REMOTE (CONUS) WITH QUARTERLY TRAVEL

ABOUT THE ROLE
A Service Control Policy that blocks every risky action and also blocks the deployment automation is not a security control; it is an outage. This seat writes the policies that draw the line correctly, then proves the line holds. You will own the preventive layer across a multi-account AWS organization, stand up the detective services that catch what prevention misses, and wire the automated response that closes findings without waiting on a ticket.
The work runs through a delegated administrator model, where a central security account owns organization-level configuration for GuardDuty, Security Hub, Config, and IAM Access Analyzer. Everything is deployed as code and mapped to a control framework, so you will spend as much time on NIST 800-53, FedRAMP, CMMC, and Impact Level requirements as on the console. Data residency and sovereignty constraints are enforced technically here rather than described in a policy document, and that enforcement is yours.

WHAT YOU WILL DO
● Author the preventive layer. Design and test Service Control Policies, including region-deny, service restriction, and quarantine policies, without breaking the landing zone automation roles.
● Design identity. Configure IAM Identity Center permission sets, permission boundaries, least-privilege access patterns, and the organizational RBAC model for operations teams.
● Own encryption. Build KMS customer-managed key hierarchies, rotation, and alias strategy, and enforce encryption at rest and in transit across the organization.
● Run detective controls. Deploy AWS Config managed and custom rules, conformance packs aligned to CIS and NIST baselines, and Config Aggregators for organization-wide visibility.
● Manage threat detection. Configure GuardDuty and Security Hub at the organization level from the delegated administrator account, and tune findings into a queue the team can actually work.
● Automate remediation. Build SSM Automation documents, Lambda functions, and EventBridge routing that remediate non-compliant resources on detection.
● Own the audit trail. Maintain organization-wide CloudTrail with log integrity validation, centralized delivery to the log archive account, and immutable retention.
● Map controls to frameworks. Translate deployed technical controls into NIST 800-53, FedRAMP, CMMC, and Impact Level language that assessors accept, and enforce data residency requirements through policy.
● Prove the controls hold. Build test cases that attempt the prohibited action and confirm the policy denies it, then keep those tests running as the environment changes.

REQUIRED QUALIFICATIONS
● Active Secret clearance. Interim clearances are not accepted for this engagement.
● U.S. citizenship.
● Hands-on experience in a multi-account AWS Organizations environment, including OU design and SCP inheritance.
● Demonstrated authorship of Service Control Policies in a production organization.
● Deep IAM fluency: roles, trust policies, condition keys, permission boundaries, and identity federation.
● Production experience with AWS Config rules and automated remediation through SSM Automation or Lambda.
● Working knowledge of KMS key policies and organization-level encryption enforcement.
● Security services depth across GuardDuty, Security Hub, CloudTrail, and the delegated administrator model.
● Ability to map technical controls to a compliance framework such as NIST SP 800-53, FedRAMP, or CMMC.
● Infrastructure as code proficiency, since controls are deployed and versioned as code rather than configured by hand.
● Willingness to travel to Charleston, South Carolina approximately quarterly.

PREFERRED QUALIFICATIONS
● Landing Zone Accelerator or AWS Control Tower experience, particularly authorship of the security configuration file.
● AWS GovCloud, Secret, or Top Secret partition experience.
● Data perimeter design, including Resource Control Policies and exfiltration prevention across account boundaries.
● Working knowledge of AWS Network Firewall and VPC Flow Log analysis, since network security controls sit alongside this seat.
● AWS Certified Security Specialty or Solutions Architect Professional.
● CompTIA Security+ (Sec+ CE) or an equivalent DoD 8140 baseline certification.
● Familiarity with Zero Trust architecture principles applied to multi-account environments.
● Experience with digital sovereignty and data residency enforcement in a regulated environment.

WORKING ENVIRONMENT
The role is fully remote within the continental United States, with quarterly travel to Charleston, South Carolina for program increment planning sessions. Expect roughly one trip per quarter, planned well in advance.

The initial engagement runs approximately 30 days to close out an existing period of performance. A follow-on award is anticipated to extend the work approximately twelve months, subject to execution of that award.

An active Secret clearance is required at start. Interim clearances will not be accepted for this engagement, and clearance status is verified before any offer is extended.
This is a small team supporting a large solution, so the person in this seat carries more breadth than a comparable role at a larger shop would. Depth in the core area is expected; working competence across the adjacent areas is what makes the seat viable.

ABOUT D9TECH RESOURCES
D9Tech Resources is a Service-Disabled Veteran-Owned Small Business and SBA 8(a) participant delivering cleared cloud, cybersecurity, network, data, and AI engineering to Federal and Department of Defense customers.
group id: 90970085

Similar Jobs


Job Category
IT - Software
Clearance Level
Secret