AWS Cloud Engineer

CDIT

  • Norfolk, Virginia
  • 30+ days ago

    Highlights

    The engineer will translate Navy mission requirements intowell-architected, automated, and repeatable cloud solutions in AWS GovCloud(US), and will mentor mid-level engineers on infrastructure-as-code, resilience,and secure DevSecOps practices. Architect networking (VPC, Transit Gateway, DirectConnect, PrivateLink), identity (IAM, IAM Identity Center, federation with DoDidentity providers), and data-protection controls (KMS, S3 encryption, Macie).

    Numbers & Facts

    LocationNorfolk, Virginia

    Description

    The AWS Cloud Engineer (Expert)will lead the architecture, engineering, and operational stewardship ofAWS-based infrastructure supporting the NMMES program in Norfolk, VA. The roleowns the cloud foundation on which NMMES applications, data pipelines, andAI/ML workloads are built, with a strong emphasis on security, cost efficiency,and compliance with DoD Cloud Computing Security Requirements Guide (SRG)Impact Levels.

    This is a senior, hands-onengineering role. The engineer will translate Navy mission requirements intowell-architected, automated, and repeatable cloud solutions in AWS GovCloud(US), and will mentor mid-level engineers on infrastructure-as-code, resilience,and secure DevSecOps practices.

    Key Responsibilities

    Design and implement multi-account AWS GovCloudenvironments using AWS Organizations, Control Tower patterns, landing zones,and account-vending automation.

    Author and maintain infrastructure-as-code usingTerraform and/or AWS CloudFormation/CDK; enforce change control throughGit-based workflows.

    Architect networking (VPC, Transit Gateway, DirectConnect, PrivateLink), identity (IAM, IAM Identity Center, federation with DoDidentity providers), and data-protection controls (KMS, S3 encryption, Macie).

    Build and operate CI/CD pipelines (CodePipeline,CodeBuild, GitHub Actions, GitLab CI) supporting containerized and serverlessworkloads.

    Implement observability using CloudWatch, X-Ray, andthird-party tooling (e.g., Splunk, Datadog) to meet Navy monitoring and auditrequirements.

    Support the Assessment & Authorization (A&A) /RMF process: produce architecture diagrams, control implementation statements,and evidence artifacts aligned to NIST SP 800-53 and DoD SRG.

    Optimize cost and performance through right-sizing,reserved capacity / Savings Plans, and workload placement analysis.

    Lead incident response and root-cause analysis forcloud-hosted workloads; drive continuous improvement of runbooks and automatedremediation.

    Partner with the AI, data, and application teams toensure their workloads land on a compliant, resilient, and cost-effectiveplatform.

    Required Qualifications

    7+ years of professional IT experience, with 5+ yearsdesigning and operating production AWS environments.

    Demonstrated expertise across core AWS services: VPC,EC2, S3, IAM, KMS, RDS, Lambda, ECS/EKS, CloudWatch, and CloudTrail.

    Strong infrastructure-as-code skills with Terraform(preferred) and/or CloudFormation/CDK.

    Proven experience in AWS GovCloud (US) or anotherregulated cloud environment (FedRAMP High, DoD IL4/IL5).

    Practical scripting proficiency in Python, Bash, orPowerShell for automation and tooling.

    Working knowledge of DoD RMF, NIST SP 800-53, and DoDCloud Computing SRG.

    Experience with containerization (Docker) andorchestration (ECS, EKS, or Kubernetes).

    Active DoD Secret clearance at time of hire.

    Preferred Qualifications

    Prior experience supporting Navy, NAVSEA, Marine Corps,or other DoD programs in Norfolk / Hampton Roads.

    Familiarity with Platform One, Iron Bank, or other DoDDevSecOps reference implementations.

    Experience integrating with DoD PKI, CAC-basedauthentication, and ICAM services.

    Multi-cloud exposure (Azure Government, OracleGovernment Cloud).

    TS/SCI clearance.

    Education

    Bachelor’s degree in ComputerScience, Information Systems, Engineering, or a related technical field.Additional years of directly relevant experience may substitute for the degreein accordance with contract labor-category definitions.

    Certifications

    DoD 8570 / 8140 IAT Level II baseline certification(Security+ CE minimum); IAT Level III (CISSP, CASP+, or CCSP) required forprivileged access to accredited systems.

    AWS Certified Solutions Architect – Associate(minimum).

    Preferred

    AWS Certified Solutions Architect – Professional

    AWS Certified DevOps Engineer – Professional

    AWS Certified Security – Specialty

    HashiCorp Certified: Terraform Associate

    Certified Kubernetes Administrator (CKA)

    Similar Jobs

    See more jobs