Cloud Security Engineer
Location: Bethesda, MD (Hybrid; On-site as Required)
Clearance: Tier 2 Public Trust (Required)
Employment Type: Full-Time
Position Summary
Digital Global Connectors (DGC) is seeking an experienced Cloud Security Engineer to support a Federal information security program. The Cloud Security Engineer is responsible for designing, implementing, configuring, securing, and maintaining cloud-based infrastructure and services while ensuring compliance with Federal cybersecurity requirements and industry best practices.
This position provides technical expertise in securing cloud environments, implementing cloud-native security controls, protecting cloud workloads and data, supporting cloud migrations, and integrating cloud security into enterprise cybersecurity operations. The Cloud Security Engineer collaborates with Security Architects, Security Engineers, ISSOs, System Owners, Cloud Administrators, Network Engineers, and program leadership to develop secure, scalable, and resilient cloud environments.
The successful candidate will possess extensive experience implementing Microsoft Azure, Microsoft 365, Amazon Web Services (AWS), and hybrid cloud security solutions within complex enterprise environments.
Essential Duties and Responsibilities:
Cloud Security Engineering
- Design, implement, configure, and maintain secure cloud environments.
- Develop cloud security architectures supporting enterprise business and mission requirements.
- Implement cloud-native security services and security automation.
- Configure cloud identity, access management, encryption, and logging capabilities.
- Support cloud modernization and migration initiatives.
- Ensure cloud environments comply with Federal cybersecurity requirements.
Cloud Infrastructure Security
- Secure Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS) environments.
- Implement secure networking within cloud environments.
- Configure cloud firewalls, network security groups, private networking, and secure connectivity.
- Support secure cloud storage and data protection.
- Implement secure backup and disaster recovery capabilities.
- Monitor cloud infrastructure for security risks and configuration drift.
Identity and Access Management
- Implement cloud Identity and Access Management (IAM) solutions.
- Configure Microsoft Entra ID, Conditional Access, Multi-Factor Authentication (MFA), Privileged Identity Management (PIM), and Privileged Access Management (PAM).
- Implement least-privilege access models.
- Review identity security configurations and recommend improvements.
- Support secure identity federation and authentication services.
Cloud Security Monitoring
- Configure cloud security monitoring and logging capabilities.
- Integrate cloud telemetry into Security Information and Event Management (SIEM) platforms.
- Support cloud detection and response capabilities.
- Monitor cloud environments for suspicious activity.
- Investigate cloud security alerts and coordinate remediation activities.
- Support continuous monitoring initiatives across hybrid environments.
Vulnerability Management
- Perform vulnerability assessments within cloud environments.
- Identify cloud security misconfigurations.
- Coordinate remediation of vulnerabilities affecting cloud resources.
- Validate successful implementation of corrective actions.
- Support secure configuration baselines for cloud services.
- Assist with cloud compliance assessments and reporting.
Security Tool Administration
Implement, configure, and support technologies including:
- Microsoft Defender for Cloud
- Microsoft Defender XDR
- Microsoft Defender for Endpoint
- Microsoft Sentinel
- Microsoft Entra ID
- Microsoft Intune
- Azure Policy
- Azure Key Vault
- Azure Monitor
- Microsoft Purview
- AWS Identity and Access Management (IAM)
- AWS Security Hub
- AWS GuardDuty
- AWS Inspector
- AWS CloudTrail
- AWS Config
- Security Information and Event Management (SIEM)
Support integration of cloud security technologies with enterprise cybersecurity operations.
Risk Management Framework (RMF) Support
- Implement technical security controls supporting NIST SP 800-53.
- Support Authorization to Operate (ATO) activities for cloud-hosted systems.
- Assist ISSOs with development and maintenance of cloud security documentation.
- Support Security Control Assessments involving cloud technologies.
- Maintain evidence supporting continuous monitoring activities.
- Recommend technical solutions that improve cloud security posture.
Documentation and Reporting
Develop and maintain:
- Cloud Security Architectures
- Cloud Configuration Standards
- Cloud Security Implementation Guides
- Technical Design Documents
- Standard Operating Procedures
- Cloud Security Metrics
- Compliance Reports
- Security Assessment Documentation
- Executive Status Reports
- Cloud Security Roadmaps
Ensure documentation remains technically accurate, current, and aligned with organizational standards.
Collaboration
- Coordinate with Security Architects, Security Engineers, ISSOs, Cloud Administrators, Network Engineers, System Owners, and Government stakeholders.
- Participate in cloud architecture reviews and technical working groups.
- Support cloud technology implementations and modernization initiatives.
- Provide technical guidance to engineering teams.
- Assist with troubleshooting complex cloud security issues.
Continuous Improvement
- Monitor emerging cloud security technologies and Federal cybersecurity guidance.
- Recommend improvements to cloud security architecture and engineering processes.
- Support automation initiatives utilizing Infrastructure as Code (IaC) and policy-based security management.
- Evaluate new cloud security capabilities and technologies.
- Maintain professional certifications and technical expertise.
Minimum Qualifications
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Information Systems, Engineering, or a related discipline.
- Minimum five (5) years of experience implementing or supporting cloud security technologies.
- Experience securing Microsoft Azure, Microsoft 365, Amazon Web Services (AWS), or hybrid cloud environments.
- Experience implementing cloud identity, monitoring, and security controls.
- Familiarity with NIST SP 800-53, the Risk Management Framework (RMF), and Federal cybersecurity requirements.
- Experience supporting enterprise cloud environments utilizing Infrastructure as Code (IaC) and cloud automation tools.
- Strong analytical, troubleshooting, documentation, and communication skills.
- U.S. Citizenship required.
- Ability to obtain and maintain a Tier 2 Public Trust.
Preferred Qualifications
- Master's degree in Cybersecurity, Information Assurance, Computer Science, Engineering, or a related discipline.
- Experience supporting a Federal civilian agency.
- Experience supporting FedRAMP-authorized cloud environments.
- Experience implementing Zero Trust principles within cloud environments.
- Microsoft Certified: Azure Security Engineer Associate (AZ-500)
- Microsoft Certified: Azure Administrator Associate (AZ-104)
- AWS Certified Security ā Specialty
- AWS Certified Solutions Architect ā Associate or Professional
- Certified Cloud Security Professional (CCSP)
- Certified Information Systems Security Professional (CISSP) (preferred)
Knowledge, Skills, and Abilities
- Cloud Security Engineering
- Microsoft Azure
- Microsoft 365 Security
- Amazon Web Services (AWS)
- Hybrid Cloud Security
- Microsoft Defender for Cloud
- Microsoft Defender XDR
- Microsoft Sentinel
- Microsoft Entra ID
- Microsoft Intune
- Azure Policy
- Azure Key Vault
- Azure Monitor
- Microsoft Purview
- AWS Security Hub
- AWS GuardDuty
- AWS Inspector
- AWS CloudTrail
- AWS Config
- Identity and Access Management (IAM)
- Infrastructure as Code (IaC)
- Security Information and Event Management (SIEM)
- Zero Trust Principles
- NIST Risk Management Framework (RMF)
- NIST SP 800-53
- Federal Information Security Modernization Act (FISMA)
- FedRAMP
- Technical Documentation
- Microsoft Office Suite
- ServiceNow
- Jira
Security Requirements
- Ability to successfully obtain and maintain a Tier 2 Public Trust investigation.
- Compliance with all applicable Federal security, privacy, ethics, and information assurance training requirements before receiving system access.
- Ability to support cloud operations, scheduled maintenance windows, continuity of operations (COOP), emergency response activities, cloud modernization initiatives, and surge support as required.
- Must maintain strict confidentiality while handling cloud security configurations, architecture documentation, identity information, system logs, and Federal information systems.
- Ability to design, implement, and maintain secure cloud environments while collaborating with Government stakeholders, technical teams, and program leadership to strengthen cloud security, improve operational resilience, and support organizational mission objectives.
Ā
Learn more about this Employer on their Career Site
