Job Title:Â Cloud Security Engineer
Location:Â Pittsburgh, PA / Lake Mary, FL / New York, NY
Work Type: Hybrid
Employment Type: Contract (C2C)
Duration: Â 12+ Months
Visa Requirement: No OPT / CPTÂ
Â
Note: Must have skill Exp with FedRAMP & Azure/AWS
Â
About the Role:
Â
We are seeking a Cloud Security Engineer who drives the technical design and full-lifecycle integration of comprehensive security control frameworks. By leveraging a deep, architectural understanding of foundational risk models (e.g., NIST SP 800-53, CSF, ISO 27001), this architect translates rigorous compliance mandates into resilient, scalable cloud infrastructure. The holistic approach to boundary definition, automated enforcement, and zero-trust principles ensures that security is engineered organically into the environment, continuously satisfying complex third-party assessment criteria.
Key Responsibilities:
- Implement and enforce FedRAMP controls in cloud platforms
- Review existing security frameworks and close gaps between standards and implementation
- Deploy and validate security policies and rule sets
- Work with data protection and cryptography teams to enforce cloud security controls
- Ensure security controls are effective, auditable, and operational
- Identify issues like overprovisioning and underutilization from a security and governance perspective
Required Skills:
- Full-Lifecycle Engineering: Demonstrated experience in the end-to-end integration of rigorous control frameworks (e.g., NIST 800-53, ISO 27001, SOC 2, CMMC)-from initial gap analysis and architectural design through deployment, automated enforcement, and continuous monitoring.
- Control Translation: Proven ability to dissect complex regulatory catalogs and translate them into actionable, technical engineering requirements for AWS infrastructure and DevSecOps pipelines.
- Boundary & Scoping Expertise: Expertise in defining complex authorization boundaries, architecting secure enclaves, and implementing micro segmentation to isolate regulated data and reduce the overall audit footprint.
- Compensating Controls: Adept at designing and documenting robust compensating controls and operational workarounds when native technical enforcement of a framework requirement is unfeasible.
- Ability to work with multiple teams and drive controls into production
Learn more about this Employer on their Career Site
