About the RoleThe Sr. Cloud Security Engineer, Federal performs the tasks necessary to analyze, design, configure, implement, and validate security solutions for H3's AWS GovCloud infrastructure. This role serves as a technical leader and "self-starter," working closely with the Director of Federal Operations, Security Operations Manager, and engineering teams to ensure a secure and compliant cloud architecture. Tasks will consist of developing security guardrails, automating threat detection, and managing the end-to-end security lifecycle within the CI/CD pipeline. This position prioritizes Federal AWS environments and compliance (FedRAMP, IL-4/5) while providing subject matter expertise and support for commercial cloud security as the Federal Team grows.
Essential Functions- Cloud Security Engineering: Design and implement robust security controls across AWS environments, including AWS IAM, SCPs, VPC security, S3 bucket policies, and key management.
- Infrastructure as Code (IaC): Utilize Terraform to deploy and manage security configurations, ensuring "Security as Code" is integrated into all cloud deployments.
- DevSecOps Integration: Implement and maintain GitLab CI/CD pipelines for automated security testing and scanning of AWS resources.
- Posture Management & Monitoring: Continuously monitor and improve cloud security posture by managing and tuning services such as GuardDuty, Security Hub, AWS WAF, and CloudTrail.
- Identity & Access Management: Define and enforce IAM best practices, including least privilege, federated identity, RBAC, and automated remediation of deficiencies.
- Threat Modeling & Assessment: Conduct architecture reviews and risk assessments for new cloud features to identify and mitigate vulnerabilities before deployment.
- Incident Response & Analysis: Investigate suspected attacks and lead security incident management, providing post-mortem analysis and developing long-term preventive measures.
- Compliance & Standards: Develop and maintain security policies and procedures to ensure compliance with FedRAMP and DoD IL-4/5.
- Reporting & Metrics: Develop creative reporting mechanisms and metrics to communicate cloud risk and security themes to business owners and leadership.
Competencies- AWS Expertise: Deep knowledge of AWS services and security architecture.
- Automation Proficiency: In-depth knowledge of Terraform and GitLab CI/CD strategies.
- Framework Fluency: Familiarity with cybersecurity frameworks such as NIST, CIS, and MITRE ATT&CK.
- Analytical Problem Solving: Excellent skills in log processing, event analysis, and incident management.
- Communication: Excellent verbal and written skills, with the ability to explain complex technical concepts to non-technical stakeholders.
- Integrity & Ownership: Demonstrated commitment to process improvement, technical integrity, and a "learn-it-all" attitude.
Required Education/Experience- Education: Bachelor's degree in Computer Science or Cybersecurity; Military Service Equivalent.
- Experience: Minimum five (5) years of experience in securing AWS environments; 5+ years of general cybersecurity experience.
- Certifications: AWS Certified Security - Specialty preferred; CISSP or relevant security certifications preferred.
- Clearance/Auth: Must be authorized to work in the U.S. and pass a criminal background check.
- U.S. Government Security Clearance is a plus.
Travel & Environment- Location: Fully remote.
- Travel: Up to 5% for company-approved events or summits.
Other DutiesPlease note this job description is not designed to cover or contain a comprehensive listing of activities. Duties, responsibilities, and activities may change at any time.