Summary
The client is seeking a hands-on Cloud Security Engineer to support AWS security and compliance in a FedRAMP Moderate environment. The role owns AWS security configuration, access control enforcement, finding remediation, vulnerability management, and production of 3PAO-ready evidence while working alongside infrastructure engineers.
Responsibilities
- Configure, harden, and operate core AWS security services including IAM, IAM Identity Center, CloudTrail, AWS Config, Security Hub, KMS, and centralized logging and monitoring
- Enforce MFA, remediate excessive or stale access, and drive vulnerability management through to closure
- Map NIST SP 800-53 Rev 5 controls (FedRAMP Moderate) to concrete AWS evidence a 3PAO will accept—configurations, exports, and screenshots—and produce that evidence correctly the first time
- Triage and close Security Hub, Config, and assessment findings; maintain continuous monitoring artifacts
- Work self-directed from a Jira backlog alongside infrastructure engineers with minimal ramp time
Skills
- Hands-on cloud security engineering experience on AWS; GovCloud experience strongly preferred
- Working fluency in IAM / IAM Identity Center, CloudTrail, Config, Security Hub, KMS, and logging/monitoring configuration
- FedRAMP Moderate (NIST 800-53 Rev 5) experience: able to read a control, identify what a 3PAO will accept as passing evidence, and produce it
- Technical first, compliance-literate second. Representative work includes MFA enforcement, vulnerability management, and access control cleanup
- Comfortable working independently off a backlog, embedded with infrastructure engineering
- Prior 3PAO assessment support or FedRAMP readiness engagement
- Continuous monitoring ownership in an authorized or in-process environment
- Experience with a compliance automation platform such as Anitian
Qualifications
Must Haves
- Hands-on cloud security engineering experience on AWS; GovCloud experience strongly preferred
- Working fluency in IAM / IAM Identity Center, CloudTrail, Config, Security Hub, KMS, and logging/monitoring configuration
- FedRAMP Moderate (NIST 800-53 Rev 5) experience: able to read a control, identify what a 3PAO will accept as passing evidence, and produce it
- Technical first, compliance-literate second. Representative work includes MFA enforcement, vulnerability management, and access control cleanup
- Comfortable working independently off a backlog, embedded with infrastructure engineering
Nice to Haves
- Prior 3PAO assessment support or FedRAMP readiness engagement
- Continuous monitoring ownership in an authorized or in-process environment
- Experience with a compliance automation platform such as Anitian
Benefits