Cloud Security Engineer
Job Description
hackajob is collaborating with Leo Technologies to connect them with exceptional professionals for this role.
\nCloud Security Engineer
\n Palm Beach
Description
\n\n
Role
\nWe're a SaaS company running on AWS GovCloud (US), maintaining SOC 2 Type 2 attestation and actively
\n pursuing FedRAMP High authorization. This is the dedicated owner of cloud security within our InfoSec team —
\n embedded day-to-day with a ~40-person engineering org spanning Product, Platform, Application/SDET, DevOps,
\n and ML/AI.
\n You'll be the person who makes our AWS environment both demonstrably compliant and genuinely secure:
\n translating NIST 800-53 controls into engineering reality, generating the evidence that satisfies a 3PAO, and
\n partnering with builders so the secure path is the easy path — not a gate they route around.
\n What you'll own
\n • AWS GovCloud security posture end to end: IAM and identity federation, account/OU structure, network
\n segmentation (VPC, security groups, Transit Gateway), encryption and KMS/CMK key management,
\n CloudTrail/Config logging, and workload protection.
\n • Technical ownership of cloud-relevant controls for FedRAMP High (NIST 800-53 Rev 5 High baseline, ~400+
\n controls) and SOC 2 Type 2 Trust Services Criteria — mapping controls to implemented safeguards and
\n keeping them operating effectively across audit periods.
\n • Continuous Monitoring (ConMon): vulnerability scanning, monthly POA&M management, deviation
\n requests, and the evidence pipeline that stands up to 3PAO assessment and annual SOC 2 windows.
\n • Security automation in CI/CD: IaC scanning, policy-as-code guardrails, and hardened baselines so ~40
\n engineers ship securely by default.
\n • Detection & response: tuning GuardDuty, Security Hub, Config rules, Inspector, and SIEM integration;
\n supporting incident response and forensics in a GovCloud boundary.
\n • Boundary & landing zone partnership: working with Platform and DevOps on the authorization boundary
\n definition, secure landing zones, and baseline hardening (CIS/DISA STIG).
\n • Cross-team advisory: guiding ML/AI teams on securing data pipelines and model infrastructure, and serving
\n as cloud security SME during audits, agency reviews, and customer security questionnaires.
\n What we're looking for
\n • 5–8+ years in cloud security, with hands-on depth in AWS (GovCloud experience a strong plus).
\n • Direct experience implementing and evidencing security controls against a compliance framework —
\n FedRAMP (Moderate or High) strongly preferred, or demonstrable NIST 800-53 work.
\n • Solid grasp of SOC 2 Trust Services Criteria and what Type 2 (operating effectiveness over a period) demands
\n beyond Type 1.
\n • Infrastructure-as-code fluency (Terraform and/or CloudFormation) and policy-as-code (OPA/Conftest,
\n Sentinel, or similar).
\n • Practical IAM, KMS/encryption, network security, and container/Kubernetes (EKS) security experience.
\n • Comfort scripting and automating (Python, Go, or similar) rather than living in the console.
\n • Ability to influence engineers without formal authority — clear communication and a partnership mindset.
\n Nice to have
\n • Prior participation in a FedRAMP authorization from readiness through ATO (agency-sponsored or FedRAMP
\n Board).
\n • CNAPP/CSPM tooling (Wiz, Prisma Cloud, Orca, etc.).
\n • GovCloud-specific familiarity: service availability differences, US-persons account vetting, ITAR/EAR data
\n handling.
\n • Relevant certifications: AWS Security Specialty, CCSP, CISSP.
\n • Experience securing ML/AI or data-intensive workloads.
\n Eligibility
\n • Due to FedRAMP High requirements and the nature of federal data in scope, this role is open to U.S. citizens
\n only. (Confirm the specific legal basis — e.g., ITAR or contract clause — with counsel before posting.)
\n • Must be able to pass a background check.
