Senior Cloud Security Engineer

Steampunk Inc — United States · Posted ~21 hours ago

Senior

Skills

AWS security cloud security architecture identity and access management vulnerability management data protection security monitoring cloud security controls cloud-native security third-party security solutions risk analysis security architecture AWS cloud security IAM

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

A senior cloud security professional is sought to design and maintain secure cloud architectures, implement security controls, manage identities and vulnerabilities, protect data, and continuously monitor cloud environments. The role requires strong hands-on AWS experience, familiarity with cloud-native and third-party security technologies, and strong analytical and collaboration skills.

Highlights

Hands-on senior cloud security role covering architecture, identity, vulnerability management, data protection, monitoring, and security controls, with opportunities to collaborate across technical teams and improve enterprise cloud security posture.

Description

As a Senior Cloud Security Engineer, you will work with our team and clients to design, implement, and maintain secure cloud environments and architectures. You will support cloud security across the system lifecycle, including security architecture, identity and access management, vulnerability management, data protection, continuous monitoring, and the implementation of cloud security controls. We are looking for an experienced cloud security professional with strong hands-on experience securing AWS environments and implementing cloud-native and third-party security solutions. The ideal candidate will bring strong analytical and problem-solving skills and the ability to collaborate across technical teams to identify risks, implement security controls, and continuously improve the security posture of cloud environments. Contributions Responsibilities Include Design and implement secure cloud architectures and technical solutions with security requirements incorporated throughout the system lifecycle. Identify and implement secure cloud-based solutions, including components supporting zero-trust architectures, identity and access management, and data protection. Implement and maintain identity and access management (IAM) controls, including authentication, authorization, and least-privilege access. Assess and harden cloud environments, configurations, authentication mechanisms, and authorization controls. Identify, assess, document, and track vulnerabilities and cloud security risks across systems and environments. Partner with cloud engineers, software engineers, DevSecOps engineers, cybersecurity teams, and other technical stakeholders to prioritize and remediate vulnerabilities and security weaknesses. Implement and support cloud security posture and application protection capabilities to identify misconfigurations, vulnerabilities, excessive permissions, and other cloud security risks. Monitor cloud environments for suspicious activity using cloud-native monitoring, SIEM, and other security solutions and investigate security events as appropriate. Conduct risk assessments, threat modeling, and security testing to identify and mitigate cloud security risks. Automate security processes, including vulnerability management, configuration assessment, and other cloud security activities. Support enterprise cloud security through infrastructure as code, including automated server and network configurations, large-scale deployments, monitoring, and testing. Evaluate infrastructure as code and cloud configurations to identify security risks and recommend appropriate remediation. Design and implement data protection and encryption mechanisms for data at rest and in transit. Document the as-is state of cloud environments, perform gap analyses, and produce artifacts that articulate options and recommendations. Evaluate technical changes and cloud configurations for potential security impacts. Provide technical guidance and mentorship to junior team members. Engineer and implement cloud security solutions and provide recommendations for continuous improvement. Present regular status updates and provide cross-training to other team members. Maintain awareness of evolving cloud vulnerabilities, threats, security technologies, and cloud security engineering practices. Qualifications Ability to obtain and maintain a U.S. government security clearance. Bachelor's degree and 10+ years of total experience. 5+ years of experience architecting, designing, developing, implementing, or securing cloud solutions. 5+ years of experience with cloud platforms, including AWS. Experience implementing cloud security architecture, controls, and security best practices in AWS environments. Experience with Cloud-Native Application Protection Platform (CNAPP) or Cloud Security Posture Management (CSPM) solutions. Experience with identity and access management (IAM), authentication, authorization, and least-privilege security principles in cloud environments. Experience identifying, assessing, tracking, and supporting remediation of cloud vulnerabilities and security misconfigurations. Experience conducting security monitoring, risk assessments, threat modeling, and security testing in cloud environments. Experience implementing or supporting continuous security monitoring and vulnerability management processes. Experience with infrastructure as code and orchestration. Experience analyzing technical security findings and identifying appropriate remediation or risk mitigation actions. Experience collaborating across cloud, DevSecOps, software engineering, and cybersecurity teams to implement and maintain security controls. Strong analytical, troubleshooting, problem-solving, communication, and collaboration skills. Current AWS certification. Preferred Experience with Wiz, Palo Alto Cortex, or similar cloud security platforms. Experience with Data Security Posture Management (DSPM) tools and practices. Certified Information Systems Security Professional (CISSP) or other relevant cybersecurity certification. Experience working within federal government or other highly regulated environments. Knowledge of federal cybersecurity requirements, security controls, and continuous monitoring practices. Experience documenting an as-is state of the environment, performing gap analyses, and producing artifacts that articulate options and recommendations. Experience with scripting in Bash, PowerShell, Python, Groovy, Ruby, or similar languages. Experience with automation and infrastructure-as-code tools such as Chef, Terraform, CloudFormation, or Ansible. About Steampunk Steampunk relies on several factors to determine salary, including but not limited to geographic location, contractual requirements, education, knowledge, skills, competencies, and experience. The projected compensation range for this position is $130,000 to $180,000. The estimate displayed represents a typical annual salary range for this position. Annual salary is just one aspect of Steampunk’s total compensation package for employees. Learn more about additional Steampunk benefits here. Identity Statement As part of the application process, you are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud. Steampunk is a Change Agent in the Federal contracting industry, bringing new thinking to clients in the Homeland, Federal Civilian, Health and DoD sectors. Through our Human-Centered delivery methodology, we are fundamentally changing the expectations our Federal clients have for true shared accountability in solving their toughest mission challenges. If you want to learn more about our story, visit http://www.steampunk.com . We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status, or any other characteristic protected by law. Steampunk participates in the E-Verify program.