Job DescriptionThe Cybersecurity Engineer (Cloud) secures and accredits CMCC's multi tenant cloud environments (Dev, Integration, Test). The role implements JSIG/NIST/STIG baselines, engineers secure multi classification cloud designs, validates Capability Provider and External cyber artifacts, and ensures all required evidence is provided to the Infrastructure TO for Baseline updates. The Cybersecurity Engineer (Cloud) develops RMF/ATO packages for cloud environments, partners closely with DSOP, Platform, CE, and Cloud SMEs, and contributes hands on effort to early DSOP/cloud design and environment build out.
Job Duties include:
• Build and secure multi-tenant CMCC cloud environments.
• Implement JSIG, NIST SP 800-53, STIG, and MLS/MILS baselines across Dev/Integration/Test cloud enclaves.
• Own RMF/ATO packages for cloud environments, producing SSP, POA&M, and full RMF evidence.
• Validate STIG, ACAS/Nessus, SAST/DAST, and container-security outputs prior to environment promotion.
• Perform functional validation of CP/External cyber artifacts; coordinate delivery of validated evidence to Infrastructure TO.
• Maintain cloud-aligned continuous monitoring, including audit logs, cloud telemetry, and Prometheus/Grafana security metrics.
• Support Cloud + DSOP joint early design efforts; collaborate to integrate pipeline-aware cloud security.
• Validate IaC/CaC baselines (Terraform, Ansible, Helm) for secure, consistent cloud deployments and promotion gates.
• Provide cyber recommendations during CCB promotion evaluations
QualificationsRequired Qualifications & Experience:
- Bachelors and nine (9) years or more experience; Masters and seven (7) years or more experience ; PhD or JD and four (4) years or more experience.
• Proven experience securing multi classification cloud environments.
• Hands on experience performing STIG review/hardening, validating ACAS/Nessus outputs, and adjudicating SAST/DAST results.
• Experience maintaining RMF/ATO artifacts (SSP, POA&M, continuous monitoring evidence).
• Familiarity with Jira/Xacta workflows for RMF and vulnerability tracking.
• DoD 8140 aligned certifications: CISSP, CCSP, CASP+, or equivalent. - Desired qualifications and experience:
• Experience architecting and securing hybrid cloud and MLS/MILS cross domain environments.
• Prior support to SCA assessments (finding remediation, documentation, assessor coordination).
• Knowledge of secure DevSecOps pipeline integration, including image signing, SBOM/SCA, and environment gate validation. - Desired Skills and Certifications:
• Experience with advanced cyber assessment, scanning, and STIG automation tools.
• Experience with cloud IaC/CaC security tooling (Terraform, Ansible, Helm, Argo CD).
• Familiarity with Zero Trust architecture, container hardening, and cloud security automation platforms.
• Strong documentation and communication skills aligned with RMF evidence and CMCC governance.