ECS

Cloud Security Engineer

ECS$140K — $170K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • US citizenship is required.
  • Ability to pass a Public Trust investigation.
  • Bachelor's degree in a related field.
  • 7 years of overall IT experience, with 3 years focused on cloud security or vulnerability management.
  • CISSP, CISA, CISM, or relevant cloud provider certifications required.
  • Hands-on scripting experience in Python, Bash, or PowerShell.
  • Familiarity with compliance frameworks including SOC 2, CIS, NIST, or ISO 27001.

Responsibilities

  • Own vulnerability triage, validation, prioritization, and remediation tracking across environments.
  • Conduct authenticated and unauthenticated scans of web applications, APIs, servers, and network devices.
  • Perform risk-based analysis of findings, including false positive validation.
  • Partner with teams to drive sustainable remediation outcomes.
  • Implement and tune CSPM tools and vulnerability scanners across cloud platforms.
  • Perform security architecture and design reviews.
  • Automate vulnerability validation and remediation tracking using scripting languages.

Benefits

  • Support for continuous learning and professional development.
  • Opportunity for remote work or flexibility in working arrangements.
  • Hands-on experience with the latest security tools and technologies.
  • Exposure to a wide range of cloud environments and security challenges.
Full Job Description
Everforth ECS is seeking a Cloud Security Engineer to work in our Arlington, VA office/remote.

We're looking for a security engineer who understands vulnerability management as an end-to-end discipline. Not just scanning, but contextualizing findings, eliminating false positives, and driving remediation outcomes across engineering, development and platform teams. You have hands-on experience operating security tooling across AWS and Azure, you can perform architecture reviews and deliver actionable guidance, and you're comfortable supporting ATO processes and continuous monitoring under RMF. You work well without heavy direction, you know how to prioritize risk in complex environments, and you can translate technical findings into clear reporting for both technical and executive audiences. You are comfortable giving technical presentations to leadership, that results in understanding and acceptance. You are familiar with Artificial Intelligence GPT prompting.

What You'll Do
  • Own vulnerability triage, validation, prioritization, and remediation tracking across cloud, on-prem, and application environments
  • Conduct authenticated and unauthenticated scans of web applications, APIs, servers, databases, and network devices
  • Perform risk-based analysis of findings including false positive validation, asset context evaluation, and remediation verification
  • Partner with platform, cloud, and application teams to drive sustainable remediation outcomes
  • Implement, operate, and tune CSPM tools, vulnerability scanners, and application security tooling across AWS, Azure, and GCP
  • Perform security architecture and design reviews covering IAM, encryption, logging, monitoring, and network controls
  • Support static, dynamic, container, and dependency scanning and help dev teams understand and fix what's found
  • Perform secure configuration reviews against DISA STIGs and other security baselines
  • Automate vulnerability validation, remediation tracking, and control validation using Python, Bash, PowerShell, and Terraform
  • Manage certificate lifecycle including inventory, renewal tracking, and deployment coordination
  • Support ATO activities, POA&M management, and RMF Step 6 continuous monitoring
  • Build and maintain runbooks, technical reports, executive dashboards, and risk summaries
  • Assist during security audits and incident response investigations involving vulnerable systems
  • Protype and provide training on new tools and solutions.


Salary: $140,000 - $170,000

General Description of Benefits

  • Must have US citizenship.
  • Ability to pass a Public Trust investigation.
  • Bachelor's degree in a related field.
  • 7 years of overall IT experience, with at least 3 years focused specifically on cloud security or vulnerability management
  • CISSP, CISA, CISM, or relevant cloud provider certifications required
  • Hands-on scripting experience in Python, Bash, or PowerShell
  • Familiarity with compliance frameworks including SOC 2, CIS, NIST, or ISO 27001
  • Understanding of CVEs, CWEs, CVSS scoring, and how to apply them in practice
  • Experience generating AI GPT prompts the produce the expected output

About ECS

ECS is a leading provider of digital solutions and services to the federal government. The company was founded in 2001 by Roy Kapani and has since grown to become a trusted partner to a wide range of government agencies. ECS offers a broad range of services, including cloud computing, cybersecurity, and artificial intelligence. The company has been recognized for its innovative solutions and has won numerous awards, including the AWS Public Sector Partner of the Year award.
Learn more about ECS
Size
2,000 employees
Industry

Similar Jobs

More Jobs at ECS

More Information Technology Jobs

Find similar Cloud Security Engineer jobs: