This Cloud Security Engineer plays a central role in protecting sensitive intelligence community cloud infrastructure, spending each day designing and enforcing security architectures across AWS environments that handle classified workloads. Working hybrid out of Herndon, Virginia, the engineer hardens cloud-native deployments by writing infrastructure-as-code in Terraform, securing containerized workloads running on Kubernetes, and embedding security controls directly into CI/CD pipelines so that compliance and threat mitigation are built into every release cycle rather than bolted on afterward. Python scripting drives automation across vulnerability scanning, policy enforcement, and incident response workflows. The role demands someone comfortable translating intelligence community security requirements into practical cloud configurations, collaborating with DevSecOps teams, and staying ahead of evolving threats targeting cloud-native systems. Candidates must bring at least five years of hands-on cloud security experience and hold an active Top Secret/SCI clearance with polygraph — no exceptions — as the work directly supports missions where security gaps carry real national security consequences.
What you'll do
- Design and implement security architectures, IAM policies, and guardrails across AWS cloud environments supporting classified intelligence workloads
- Develop and maintain Terraform modules to provision and enforce compliant, repeatable infrastructure-as-code configurations
- Integrate automated security scanning, policy enforcement, and vulnerability detection tools into CI/CD pipelines
- Harden Kubernetes cluster configurations, enforce pod security standards, and monitor containerized workloads for anomalous behavior
- Write Python scripts to automate security event triage, log analysis, and compliance reporting across cloud services
- Conduct threat modeling and security architecture reviews for new capabilities prior to production deployment
- Collaborate with DevOps engineers and program security officers to remediate findings and maintain continuous ATO posture
Required skills
- AWS
- cloud security
- Terraform
- Kubernetes
- CI/CD
- Python