SonicJobs Logo
Left arrow iconBack to search

Cloud Security Engineer

San R&D Business Solutions LLC
Posted 6 days ago, valid for 4 days
Location

New York, NY 10008, US

Salary

Competitive

Contract type

Full Time

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

Sonic Summary

info
  • The job title is Cloud Security Engineer, located in Pittsburgh, PA, Lake Mary, FL, or New York, NY.
  • Candidates must have over 12 years of experience and will work in a hybrid model on a contract basis for 12+ months.
  • The role requires expertise in FedRAMP and Azure/AWS, focusing on the integration of security control frameworks.
  • Key responsibilities include implementing FedRAMP controls, reviewing security frameworks, and ensuring effective security controls.
  • The position does not specify a salary, but candidates should possess strong skills in full-lifecycle engineering and control translation.

Job Title: Cloud Security Engineer

Location: Pittsburgh, PA / Lake Mary, FL / New York, NY

Experience: 12+ years

Work Type: Hybrid

Employment Type: Contract (C2C)

Duration:  12+ Months

Visa Requirement: No OPT / CPT 

 

Note: Must have skill Exp with FedRAMP & Azure/AWS

 

About the Role:

 

We are seeking a Cloud Security Engineer who drives the technical design and full-lifecycle integration of comprehensive security control frameworks. By leveraging a deep, architectural understanding of foundational risk models (e.g., NIST SP 800-53, CSF, ISO 27001), this architect translates rigorous compliance mandates into resilient, scalable cloud infrastructure. The holistic approach to boundary definition, automated enforcement, and zero-trust principles ensures that security is engineered organically into the environment, continuously satisfying complex third-party assessment criteria.


Key Responsibilities:

  • Implement and enforce FedRAMP controls in cloud platforms
  • Review existing security frameworks and close gaps between standards and implementation
  • Deploy and validate security policies and rule sets
  • Work with data protection and cryptography teams to enforce cloud security controls
  • Ensure security controls are effective, auditable, and operational
  • Identify issues like overprovisioning and underutilization from a security and governance perspective

Required Skills:

  • Full-Lifecycle Engineering: Demonstrated experience in the end-to-end integration of rigorous control frameworks (e.g., NIST 800-53, ISO 27001, SOC 2, CMMC)-from initial gap analysis and architectural design through deployment, automated enforcement, and continuous monitoring.
  • Control Translation: Proven ability to dissect complex regulatory catalogs and translate them into actionable, technical engineering requirements for AWS infrastructure and DevSecOps pipelines.
  • Boundary & Scoping Expertise: Expertise in defining complex authorization boundaries, architecting secure enclaves, and implementing micro segmentation to isolate regulated data and reduce the overall audit footprint.
  • Compensating Controls: Adept at designing and documenting robust compensating controls and operational workarounds when native technical enforcement of a framework requirement is unfeasible.
  • Ability to work with multiple teams and drive controls into production






Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.