CLOUD SECURITY ENGINEER
AWS • GovCloud • FedRAMP Moderate
Position Overview
Our Client is seeking a hands-on Cloud Security Engineer to own AWS security configuration, evidence production, and finding remediation in a FedRAMP Moderate environment. This is a technical-first role embedded with infrastructure engineering. The successful candidate remediates gaps, enforces access controls, and produces 3PAO-ready evidence—not policy documents.
Key Responsibilities- Configure, harden, and operate core AWS security services including IAM, IAM Identity Center, CloudTrail, AWS Config, Security Hub, KMS, and centralized logging and monitoring.
- Enforce MFA, remediate excessive or stale access, and drive vulnerability management through to closure.
- Map NIST SP 800-53 Rev 5 controls (FedRAMP Moderate) to concrete AWS evidence a 3PAO will accept—configurations, exports, and screenshots—and produce that evidence correctly the first time.
- Triage and close Security Hub, Config, and assessment findings; maintain continuous monitoring artifacts.
- Work self-directed from a Jira backlog alongside infrastructure engineers with minimal ramp time.
Required Qualifications- Hands-on cloud security engineering experience on AWS; GovCloud experience strongly preferred.
- Working fluency in IAM / IAM Identity Center, CloudTrail, Config, Security Hub, KMS, and logging/monitoring configuration.
- FedRAMP Moderate (NIST 800-53 Rev 5) experience: able to read a control, identify what a 3PAO will accept as passing evidence, and produce it.
- Technical first, compliance-literate second. Representative work includes MFA enforcement, vulnerability management, and access control cleanup.
- Comfortable working independently off a backlog, embedded with infrastructure engineering.
Preferred Qualifications- Prior 3PAO assessment support or FedRAMP readiness engagement.
- Continuous monitoring ownership in an authorized or in-process environment.
- Experience with a compliance automation platform such as Anitian.
About This Role
This is not a GRC-only or advisory position. Candidates who have not personally configured the AWS services listed above, and packaged 3PAO-ready evidence will not be a fit.