Skip to main content
Posted 20 July, 2026

Cloud Security Engineer

Leo Technologies
Palm Beach, FL, US Full Time

Job Description

hackajob is collaborating with Leo Technologies to connect them with exceptional professionals for this role.

\n

Cloud Security Engineer
\n Palm Beach

\n

Description

\n

\n

Role

\n

We're a SaaS company running on AWS GovCloud (US), maintaining SOC 2 Type 2 attestation and actively
\n pursuing FedRAMP High authorization. This is the dedicated owner of cloud security within our InfoSec team —
\n embedded day-to-day with a ~40-person engineering org spanning Product, Platform, Application/SDET, DevOps,
\n and ML/AI.
\n You'll be the person who makes our AWS environment both demonstrably compliant and genuinely secure:
\n translating NIST 800-53 controls into engineering reality, generating the evidence that satisfies a 3PAO, and
\n partnering with builders so the secure path is the easy path — not a gate they route around.
\n What you'll own
\n • AWS GovCloud security posture end to end: IAM and identity federation, account/OU structure, network
\n segmentation (VPC, security groups, Transit Gateway), encryption and KMS/CMK key management,
\n CloudTrail/Config logging, and workload protection.
\n • Technical ownership of cloud-relevant controls for FedRAMP High (NIST 800-53 Rev 5 High baseline, ~400+
\n controls) and SOC 2 Type 2 Trust Services Criteria — mapping controls to implemented safeguards and
\n keeping them operating effectively across audit periods.
\n • Continuous Monitoring (ConMon): vulnerability scanning, monthly POA&M management, deviation
\n requests, and the evidence pipeline that stands up to 3PAO assessment and annual SOC 2 windows.
\n • Security automation in CI/CD: IaC scanning, policy-as-code guardrails, and hardened baselines so ~40
\n engineers ship securely by default.
\n • Detection & response: tuning GuardDuty, Security Hub, Config rules, Inspector, and SIEM integration;
\n supporting incident response and forensics in a GovCloud boundary.
\n • Boundary & landing zone partnership: working with Platform and DevOps on the authorization boundary
\n definition, secure landing zones, and baseline hardening (CIS/DISA STIG).
\n • Cross-team advisory: guiding ML/AI teams on securing data pipelines and model infrastructure, and serving
\n as cloud security SME during audits, agency reviews, and customer security questionnaires.
\n What we're looking for
\n • 5–8+ years in cloud security, with hands-on depth in AWS (GovCloud experience a strong plus).
\n • Direct experience implementing and evidencing security controls against a compliance framework —
\n FedRAMP (Moderate or High) strongly preferred, or demonstrable NIST 800-53 work.
\n • Solid grasp of SOC 2 Trust Services Criteria and what Type 2 (operating effectiveness over a period) demands
\n beyond Type 1.
\n • Infrastructure-as-code fluency (Terraform and/or CloudFormation) and policy-as-code (OPA/Conftest,
\n Sentinel, or similar).
\n • Practical IAM, KMS/encryption, network security, and container/Kubernetes (EKS) security experience.
\n • Comfort scripting and automating (Python, Go, or similar) rather than living in the console.
\n • Ability to influence engineers without formal authority — clear communication and a partnership mindset.
\n Nice to have
\n • Prior participation in a FedRAMP authorization from readiness through ATO (agency-sponsored or FedRAMP
\n Board).
\n • CNAPP/CSPM tooling (Wiz, Prisma Cloud, Orca, etc.).
\n • GovCloud-specific familiarity: service availability differences, US-persons account vetting, ITAR/EAR data
\n handling.
\n • Relevant certifications: AWS Security Specialty, CCSP, CISSP.
\n • Experience securing ML/AI or data-intensive workloads.
\n Eligibility
\n • Due to FedRAMP High requirements and the nature of federal data in scope, this role is open to U.S. citizens
\n only. (Confirm the specific legal basis — e.g., ITAR or contract clause — with counsel before posting.)
\n • Must be able to pass a background check.