Senior Cloud Security Engineer, AWS GovCloud

Apex

$130K — $155K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • U.S. citizenship mandatory.
  • Bachelor's degree in Cybersecurity, Information Assurance, Computer Science, or related field, or 5+ years of experience in cloud security engineering.
  • 5-9+ years of hands-on cloud security engineering experience, especially in regulated environments like AWS GovCloud, Azure, or Google Cloud.
  • Strong analytical and problem-solving capabilities, effective communication skills, and a collaborative work ethic.
  • Deep expertise in cloud security principles, IAM/RBAC, and compliance frameworks.

Responsibilities

  • Design and implement secure cloud architectures across multiple cloud environments following best practices.
  • Maintain compliance with federal security standards, including NIST 800-53 and FedRAMP.
  • Configure and manage IAM and security frameworks adhering to Zero Trust Architecture principles.
  • Deploy and optimize a variety of cloud-native security tools for effective threat detection and response.
  • Conduct vulnerability assessments and continuous monitoring of cloud resources to maintain security.
  • Lead the development of crucial security documentation and compliance reports for cloud operations.
  • Collaborate with cross-functional teams to integrate security into the development lifecycle and cloud migrations.

Benefits

  • Opportunity to work on critical national security projects within government sectors.
  • Comprehensive training and development to stay updated on emerging cloud security threats.
  • Potential for career advancement in a rapidly expanding field.
  • On-site work environment fostering collaboration and teamwork.
  • Access to advanced cloud security tools and technologies.
Full Job Description
We are seeking a Senior Cloud Security Engineer, AWS GovCloud to design, implement, maintain, and optimize secure cloud environments supporting U.S. government, DoD, and intelligence community missions.

This role plays a critical part in protecting classified and sensitive data in AWS, Azure, and hybrid/multi-cloud infrastructures while ensuring full compliance with federal standards such as NIST 800-53, FedRAMP, RMF, and DoD Impact Levels (IL-4/IL-5).

The right candidate will bring hands-on experience securing cloud platforms in regulated environments. This role will help the organization meet industry standards such as SOC2, ISO 27001, PCI-DSS, GDPR/CCPA, or other relevant compliance frameworks.

Responsibilities:
  • Design and implement secure cloud architectures and configurations across AWS GovCloud, Azure, and/or Google Cloud, applying best practices for least privilege encryption, network segmentation, and data protection.
  • Implement and maintain cloud security frameworks, ensuring ongoing compliance with NIST 800-53 Rev. 5, FedRAMP, DoD IL-2/4/5, RMF, and Secure Cloud Computing Architecture (SCCA) requirements.
  • Configure and manage Identity and Access Management (IAM), Role-Based Access Control (RBAC), Just-In-Time (JIT) access, Key Vaults, and Zero Trust Architecture (ZTA) principles across cloud environments.
  • Engineer, deploy, and optimize cloud-native security tools, including Microsoft Defender for Cloud, Azure Sentinel, AWS GovCloud security services, CSPM/CWPP solutions, and SIEM (Elastic) platforms for threat detection, monitoring, and response.
  • Conduct vulnerability assessments, penetration testing simulations, security configuration reviews (against STIGs, CIS benchmarks, and NIST controls), and continuous monitoring of cloud resources.
  • Develop, maintain, and update System Security Plans (SSP), Security Assessment Reports (SAR), Plans of Action & Milestones (POA&M), and risk/compliance reporting for cloud-based operations.
  • Identify, analyze, and respond to Indicators of Compromise (IoCs), threat intelligence, and security incidents within cloud environments; perform root-cause analysis and implement preventive controls.
  • Perform periodic security reviews and audits of cloud environments (Azure, AWS, hybrid) to ensure sustained compliance, mitigate evolving threats, and update policies/procedures.
  • Collaborate with DevSecOps, infrastructure, and development teams to integrate security into CI/CD pipelines, automate security controls, and support secure cloud migrations or modernization initiatives.
  • Assess current cloud architectures, propose security improvements, review designs through a security lens, and serve as a subject-matter expert on cloud security tools,
    processes, and best practices.
  • Coordinate with configuration management teams to ensure hardware/software changes adhere to security protocols, maintain version control, and support documentation of the cyber terrain.
  • Develop, enforce, and maintain cloud security policies, standards, and automated guardrails to support secure CI/CD pipelines and infrastructure-as-code (IaC) practices (e.g., using Terraform, CloudFormation).
  • Monitor cloud environments for security incidents, investigate alerts, perform root-cause analysis, and coordinate incident response activities.
  • Identify emerging threats and recommend proactive improvements to cloud security posture, including automation of security controls and processes.
  • Provide guidance and training to engineering teams on secure cloud design patterns and best practices.
  • Ability to be on-site 5 days a week at our office in Playa Vista, CA.
Requirements:
  • Must be a U.S. citizen.
  • Education: Bachelor's degree in Cybersecurity, Information Assurance, Computer Science, or a related field (or 5+ years equivalent professional experience in cloud security engineering)
  • Experience: 5-9+ years in cloud security engineering, with hands-on work in AWS GovCloud, Azure, Google GCP, or multi-cloud environments.
  • Strong analytical, problem-solving, communication, and collaboration skills; ability to work in fast-paced, mission-critical environments.
    Technical Skills:
    • Deep knowledge of cloud platforms (AWS GovCloud, Azure Government, etc.), IAM/RBAC, encryption, network security, and cloud-native security services.
    • Familiarity with SIEM, vulnerability scanners, threat intelligence, and automation tools (e.g., Terraform, Python scripting).
    • Experience with compliance frameworks (NIST, FedRAMP, RMF) and tools like Azure Sentinel, NESSUS, BURP SUITE, Microsoft Defender, or AWS equivalents.
    • Deep understanding of network security, encryption, logging/monitoring, and container/Kubernetes security.
    • Experience with infrastructure-as-code, scripting (Python, PowerShell, etc.), and security automation tools.
  • Additional Certifications:
    • CISSP, AWS Certified Security-Specialty, AWS Certified Solutions Architect (Associate or Professional), Microsoft Certified: Security, Compliance & Identity, Security+, CEH, or CSSP related (e.g., CySA+, GCIH).

#LI-JC1

Similar Jobs

More Jobs at Apex

More Information Technology Jobs

Find similar Senior Cloud Security Engineer, AWS GovCloud jobs: