Role: Cloud Cyber Security Engineer Location: Remote Duration: 12 Months Contract Long Term Contract Employment Type: Contract Clearance: Must be able to obtain/maintain required government suitability Clearance.
Required skills/Level of Experience :
5+ years of AWS cloud security engineering experience, including IAM, Security Hub, GuardDuty, AWS Config, CloudTrail, KMS/CloudHSM, Control Tower, and Service Control Policies. FedRAMP High or AWS GovCloud experience required.
5+ years of vulnerability management experience using Tenable Nessus or equivalent, including CVE triage, POA&M management, and remediation within federal SLA timelines.
5+ years securing CI/CD pipelines with SonarQube, Trivy, Grype, IaC scanning, secrets detection, and DAST in GitLab CI or Jenkins.
4+ years with Terraform and Ansible, hardened AMIs, and DISA STIG or CIS benchmark implementation.
5+ years with Splunk or equivalent SIEM, log analysis, threat correlation, alert tuning, and JSON logging at 500 GB/day scale.
3+ years with CrowdStrike Falcon or equivalent EDR.
5+ years executing NIST SP 800-53 Rev. 5 and FISMA/FedRAMP controls.
Nice to have skills:
4+ years securing containers and Kubernetes environments on AWS EKS, Red Hat OpenShift, or ROSA, including image signing and Harbor private registry administration.
3+ year generating and managing SBOMs using CycloneDX and Syft, with FIPS 140-3 signing supported by HSM-backed keys.
5+ years operating DLP solutions in federal cloud environments, including AWS Macie, endpoint DLP, and network DLP.
5+ years managing AWS Backup and immutable recovery capabilities, including cross-Region replication, Vault Lock configuration, and recovery testing.
1+ year using AIOps security triage tools for automated correlation, anomaly detection, and change-risk scoring in security operations workflows.
1+ year producing OSCAL evidence and integrating it with RegScale.
4+ years implementing Zero Trust network controls, including microsegmentation, VPC security groups, and phishing-resistant MFA.