Job Requirements
Remote
Secret Polygraph not specified
Mid Level Career (5+ yrs experience)
Salary not specified
Join Premium to unlock estimated salaries
Job Description
We are hiring a cleared Cybersecurity Cloud Engineer with strong AWS infrastructure skills to join our team. In this role, you will help implement, maintain, and monitor security controls across our secure cloud environments. Working closely with senior engineers and DevOps teams, you will configure secure AWS architectures, deploy Infrastructure-as-Code (IaC), and monitor cloud telemetry for potential threats. Experience with Elastic SIEM (Elastic Security) is highly valued and considered a strong bonus for this position.
Please note: This position requires compliance with Department of Defense (DoD) Directive 8570 and/or DoD Manual 8140 cyber workforce requirements.
Key Responsibilities
· Cloud Security Configuration: Configure and maintain AWS VPC designs, subnets, security groups, and Network Access Control Lists (NACLs) according to established security baselines and DoD STIGs.
· Security Monitoring & Triage: Monitor security alerts using AWS native tools and SIEM platforms, triage potential threats, and assist in incident response and remediation within cleared environments.
· SIEM Support & Log Analysis: Assist with monitoring security telemetry and managing cloud logs (CloudTrail, VPC Flow Logs, GuardDuty). Experience working within or connecting logs to Elastic SIEM is a plus.
· Vulnerability Scanning: Run vulnerability assessments across cloud assets using tools like AWS Inspector, identify misconfigurations, and coordinate remediation timelines with engineering teams.
· Access Management Maintenance: Implement and audit IAM policies, roles, and resource permissions following the principle of least privilege.
· Documentation & Compliance: Help maintain technical security documentation and verify that cloud controls meet rigorous defense compliance requirements (such as NIST SP 800-53, FedRAMP, or DoD SRG).
Required Qualifications
· Security Clearance: Must possess and maintain an active DoD Secret Security Clearance.
· Experience: 3+ years of professional experience in cloud engineering, system administration, or cybersecurity, with a minimum of 1–2 years focused directly on AWS security configurations.
· DoD 8570/8140 Compliance: Must possess an active baseline certification qualifying for IAT Level II or higher (e.g., Security+ CE, CySA+, CCNA Cyber Ops, GSEC) or a relevant CSSP baseline certification at the time of hire.
· AWS Security Tools: Hands-on experience using core AWS security and monitoring tools, including IAM, GuardDuty, Security Hub, AWS Config, CloudTrail, and KMS.
· Infrastructure as Code: Practical experience deploying infrastructure using Terraform or AWS CloudFormation.
· Networking Basics: Solid understanding of TCP/IP networking, VPC architecture, routing tables, and firewalls.
· Scripting Skills: Ability to write basic automation or remediation scripts using Python or Bash.
Preferred Qualifications
· SIEM Bonus: Experience with Elastic SIEM (Elastic Security) or the Elastic (ELK) Stack for log analysis, dashboard creation, or threat detection rules. · Advanced Certifications: AWS Certified Security - Specialty or AWS Certified SysOps Administrator.
· Familiarity with the MITRE ATT&CK framework and mapping defense strategies to it.
· Practical experience working in AWS GovCloud environments.
Please note: This position requires compliance with Department of Defense (DoD) Directive 8570 and/or DoD Manual 8140 cyber workforce requirements.
Key Responsibilities
· Cloud Security Configuration: Configure and maintain AWS VPC designs, subnets, security groups, and Network Access Control Lists (NACLs) according to established security baselines and DoD STIGs.
· Security Monitoring & Triage: Monitor security alerts using AWS native tools and SIEM platforms, triage potential threats, and assist in incident response and remediation within cleared environments.
· SIEM Support & Log Analysis: Assist with monitoring security telemetry and managing cloud logs (CloudTrail, VPC Flow Logs, GuardDuty). Experience working within or connecting logs to Elastic SIEM is a plus.
· Vulnerability Scanning: Run vulnerability assessments across cloud assets using tools like AWS Inspector, identify misconfigurations, and coordinate remediation timelines with engineering teams.
· Access Management Maintenance: Implement and audit IAM policies, roles, and resource permissions following the principle of least privilege.
· Documentation & Compliance: Help maintain technical security documentation and verify that cloud controls meet rigorous defense compliance requirements (such as NIST SP 800-53, FedRAMP, or DoD SRG).
Required Qualifications
· Security Clearance: Must possess and maintain an active DoD Secret Security Clearance.
· Experience: 3+ years of professional experience in cloud engineering, system administration, or cybersecurity, with a minimum of 1–2 years focused directly on AWS security configurations.
· DoD 8570/8140 Compliance: Must possess an active baseline certification qualifying for IAT Level II or higher (e.g., Security+ CE, CySA+, CCNA Cyber Ops, GSEC) or a relevant CSSP baseline certification at the time of hire.
· AWS Security Tools: Hands-on experience using core AWS security and monitoring tools, including IAM, GuardDuty, Security Hub, AWS Config, CloudTrail, and KMS.
· Infrastructure as Code: Practical experience deploying infrastructure using Terraform or AWS CloudFormation.
· Networking Basics: Solid understanding of TCP/IP networking, VPC architecture, routing tables, and firewalls.
· Scripting Skills: Ability to write basic automation or remediation scripts using Python or Bash.
Preferred Qualifications
· SIEM Bonus: Experience with Elastic SIEM (Elastic Security) or the Elastic (ELK) Stack for log analysis, dashboard creation, or threat detection rules. · Advanced Certifications: AWS Certified Security - Specialty or AWS Certified SysOps Administrator.
· Familiarity with the MITRE ATT&CK framework and mapping defense strategies to it.
· Practical experience working in AWS GovCloud environments.
group id: 10191027