Job Requirements
Fort Belvoir, VA
Top Secret Polygraph not specified
Career Level not specified
Salary not specified
Join Premium to unlock estimated salaries
Job Description
DEI is seeking to fill an AWS GOV Cloud Engineer for our customer in Fort Belvoir, VA. DEI combines experience and innovative ideas to provide our clients the right solution with the right people at the right time. We are a proven IT services and solutions provider for full-lifecycle engineering of network, storage, cyber security, communication, and policy compliance needs. We focus on delivering IT solutions to meet complex technological and business challenges within mission-critical enterprises. DEI is an ISO 9001:2015-certified, process-oriented company. Our engineers, administrators, project and program managers and support staff focus on consistently enhancing, optimizing, operating, and maintaining your entire enterprise IT environment, from the backend infrastructure to individual end-user devices and everything that connect them.
One of our clients in Fort Belvoir, VA. needs an AWS GOV Cloud Engineer for a permanent position.
• Title: AWS GOV Cloud Engineer
• Location: Fort Belvoir, VA.
• Position Type: Permanent position.
• Travel: No.
• Clearance: Top Secret.
Job Description:
The ideal candidate will have extensive hands-on experience deploying the Virtual Data Center Security Stack (VDSS) and Virtual Data Center Managed Services (VDMS). You will possess advanced expertise in multi-account governance, including the authoring, testing, and continuous enforcement of restrictive Service Control Policies (SCPs). This position is crucial to enabling our mission partners to deploy critical DoD Impact Level 4 (IL4) and Impact Level 5 (IL5) workloads safely into the cloud.
Responsibilities:
• VDSS Implementation: Design, deploy, and maintain the Virtual Data Center Security Stack (VDSS) to protect mission applications. Implement secure network boundary controls, application-aware firewalls, intrusion detection/prevention systems (IDS/IPS), and perimeter defenses.
• VDMS Management: Standardize and manage host security and shared management services under the Virtual Data Center Managed Services (VDMS) framework, including directory services, vulnerability scanning, host-based security, patching, and configuration governance.
• Landing Zone Automation: Utilize the AWS Landing Zone Accelerator (LZA) or custom Control Tower implementations to automate the deployment of multi-account SCCA architectures.
• TCCM Enforcement: Operate as or support the Trusted Cloud Credential Manager (TCCM) role, implementing strict Role-Based Access Control (RBAC) and ensuring least-privileged IAM policies.
• Service Control Policies (SCPs): Architect, write, and manage highly restrictive Service Control Policies (SCPs) at the AWS Organization and Organizational Unit (OU) level. Prevent unauthorized service usage, enforce geographical region locks (restricting actions to AWS GovCloud), and deny modification of critical security and logging resources.
• Compliance & Drift Guarding: Establish continuous automated monitoring to detect and remediate drift from SCCA compliance baselines using native AWS governance capabilities.
• Draft all cloud infrastructure using secure, modular Infrastructure as Code (IaC) (primarily Terraform or AWS CloudFormation).
• Maintain Infrastructure as Code in secure Git repositories and integrate automated security scanning (e.g., tfsec, Checkov) into CI/CD pipelines.
• Integrate third-party security appliances (e.g., Palo Alto, Fortinet) within VDSS transit environments where appropriate.
• Configure and integrate native DoD security tooling, including Host Based Security System (HBSS), Assured Compliance Assessment Solution (ACAS), and CSSP security operations.
Qualifications:
• Active U.S. Government Secret clearance (Top Secret/SCI preferred) due to handling DoD IL4/IL5 systems and data.
• Bachelor’s degree in computer science, Cybersecurity, Information Systems, or equivalent experience, combined with 5+ years of dedicated AWS engineering and security experience.
• Direct, demonstrable experience implementing the DISA Cloud Computing Security Requirements Guide (CC SRG) and building SCCA compliant networks (VDSS/VDMS/CAP).
• Strong background deploying workloads exclusively within the AWS GovCloud (US-East/US-West) regions.
• Extensive experience designing, troubleshooting, and managing nested SCPs in complex organizational environments.
• Must possess a baseline certification meeting IAT Level III or IAM Level III (e.g., CISSP, CASP+, CISM, or Security+ CE with relevant AWS specialty certifications).
• Advanced proficiency in writing and maintaining Terraform or CloudFormation templates in highly regulated environments.
Preferred Skills:
• AWS Certified Security - Specialty, AWS Certified Solutions Architect - Professional, or AWS Certified DevOps Engineer - Professional.
• Experience configuring SAML 2.0 federation with DoD identity providers (IdAPs) for Common Access Card (CAC) / PIV authentication.
• Experience working alongside a Cyber Security Service Provider (CSSP) for authorization and ATO processes.
Employee Benefits:
• Great Benefits: Paid time off, flexible work schedule, teleworking allowed, medical/dental/vision plan, 401k; and more.
• Tuition assistance for continuing or career-related education.
• Our cultural focus is on people and results - not bureaucracy.
• Ample opportunity for career growth – we promote from within
• Leadership takes a constructive interest in every team member’s success.
• Work/Life Balance and flexible hours
• Be part of a close-knit team that works and plays together and helps one another succeed.
• You will not be micromanaged: plan, prioritize, schedule, and be accountable for your own tasks.
• Casual workplace
• Open-door policy with all management
An Equal Opportunity Employer:
DEI is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, age, protected veteran status, isability status, gender identity or national origin.
One of our clients in Fort Belvoir, VA. needs an AWS GOV Cloud Engineer for a permanent position.
• Title: AWS GOV Cloud Engineer
• Location: Fort Belvoir, VA.
• Position Type: Permanent position.
• Travel: No.
• Clearance: Top Secret.
Job Description:
The ideal candidate will have extensive hands-on experience deploying the Virtual Data Center Security Stack (VDSS) and Virtual Data Center Managed Services (VDMS). You will possess advanced expertise in multi-account governance, including the authoring, testing, and continuous enforcement of restrictive Service Control Policies (SCPs). This position is crucial to enabling our mission partners to deploy critical DoD Impact Level 4 (IL4) and Impact Level 5 (IL5) workloads safely into the cloud.
Responsibilities:
• VDSS Implementation: Design, deploy, and maintain the Virtual Data Center Security Stack (VDSS) to protect mission applications. Implement secure network boundary controls, application-aware firewalls, intrusion detection/prevention systems (IDS/IPS), and perimeter defenses.
• VDMS Management: Standardize and manage host security and shared management services under the Virtual Data Center Managed Services (VDMS) framework, including directory services, vulnerability scanning, host-based security, patching, and configuration governance.
• Landing Zone Automation: Utilize the AWS Landing Zone Accelerator (LZA) or custom Control Tower implementations to automate the deployment of multi-account SCCA architectures.
• TCCM Enforcement: Operate as or support the Trusted Cloud Credential Manager (TCCM) role, implementing strict Role-Based Access Control (RBAC) and ensuring least-privileged IAM policies.
• Service Control Policies (SCPs): Architect, write, and manage highly restrictive Service Control Policies (SCPs) at the AWS Organization and Organizational Unit (OU) level. Prevent unauthorized service usage, enforce geographical region locks (restricting actions to AWS GovCloud), and deny modification of critical security and logging resources.
• Compliance & Drift Guarding: Establish continuous automated monitoring to detect and remediate drift from SCCA compliance baselines using native AWS governance capabilities.
• Draft all cloud infrastructure using secure, modular Infrastructure as Code (IaC) (primarily Terraform or AWS CloudFormation).
• Maintain Infrastructure as Code in secure Git repositories and integrate automated security scanning (e.g., tfsec, Checkov) into CI/CD pipelines.
• Integrate third-party security appliances (e.g., Palo Alto, Fortinet) within VDSS transit environments where appropriate.
• Configure and integrate native DoD security tooling, including Host Based Security System (HBSS), Assured Compliance Assessment Solution (ACAS), and CSSP security operations.
Qualifications:
• Active U.S. Government Secret clearance (Top Secret/SCI preferred) due to handling DoD IL4/IL5 systems and data.
• Bachelor’s degree in computer science, Cybersecurity, Information Systems, or equivalent experience, combined with 5+ years of dedicated AWS engineering and security experience.
• Direct, demonstrable experience implementing the DISA Cloud Computing Security Requirements Guide (CC SRG) and building SCCA compliant networks (VDSS/VDMS/CAP).
• Strong background deploying workloads exclusively within the AWS GovCloud (US-East/US-West) regions.
• Extensive experience designing, troubleshooting, and managing nested SCPs in complex organizational environments.
• Must possess a baseline certification meeting IAT Level III or IAM Level III (e.g., CISSP, CASP+, CISM, or Security+ CE with relevant AWS specialty certifications).
• Advanced proficiency in writing and maintaining Terraform or CloudFormation templates in highly regulated environments.
Preferred Skills:
• AWS Certified Security - Specialty, AWS Certified Solutions Architect - Professional, or AWS Certified DevOps Engineer - Professional.
• Experience configuring SAML 2.0 federation with DoD identity providers (IdAPs) for Common Access Card (CAC) / PIV authentication.
• Experience working alongside a Cyber Security Service Provider (CSSP) for authorization and ATO processes.
Employee Benefits:
• Great Benefits: Paid time off, flexible work schedule, teleworking allowed, medical/dental/vision plan, 401k; and more.
• Tuition assistance for continuing or career-related education.
• Our cultural focus is on people and results - not bureaucracy.
• Ample opportunity for career growth – we promote from within
• Leadership takes a constructive interest in every team member’s success.
• Work/Life Balance and flexible hours
• Be part of a close-knit team that works and plays together and helps one another succeed.
• You will not be micromanaged: plan, prioritize, schedule, and be accountable for your own tasks.
• Casual workplace
• Open-door policy with all management
An Equal Opportunity Employer:
DEI is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, age, protected veteran status, isability status, gender identity or national origin.
group id: 10322569