Information Technology - Engineer, Systems Ld

Talteam

Reston, VA

JOB DETAILS
SKILLS
AWS Lambda, Administrative Skills, Agile Programming Methodologies, Amazon Elastic Compute Cloud (EC2), Amazon Simple Storage Service (S3), Amazon Web Services (AWS), Ansible, Applications Security, Architectural Analysis, Architectural Services, Artificial Intelligence (AI), Atlassian JIRA, Automation, Bash Scripting, Benchmarking, Best Practices, Business Processes, Capacity Management, Cloud Architecture, Cloud Computing, Cloud Storage, Communication Skills, Computer Science, Computer Security, Computer Software, Consulting, Continuous Deployment/Delivery, Continuous Integration, Corrective Action, Cost Control, Crucible, Cryptography, Customer Support/Service, Data Analysis, Design Patterns Programming Methodologies, DevOps, Disaster Recovery, Docker, Ecosystems, Engineering, Enterprise Applications, Enterprise Protection, Establish Priorities, Git, Go Programming Language (Golang), Groovy Programming Language, Healthcare, High Availability, Identify Issues, Information Technology & Information Systems, Infrastructure Software, Infrastructure as a Service (IaaS), Input/Output, Integration Testing, Internet Security, Internet Technology, Java, Jenkins, Leadership, Linux Administration, Linux Operating System, Machine Learning, Mentoring, Microservices, Middleware, Multiplatform/Cross-Platform, Network Configuration Management, Network Connectivity, Network Performance/Analysis, Network Security, Network Support, Operating Systems, Operational Audit, Operational Support, Operations Security (OPSEC), Performance Analysis, Performance Reviews, Performance Testing, Presentation/Verbal Skills, Product Support, Production Systems, Protective Services, Publications, Purchasing/Procurement, Python Programming/Scripting Language, Reliability Engineering, Requirements Management, Research Skills, Risk, Risk Management, Root Cause Analysis, Scalable System Development, Scripting (Scripting Languages), Scrum Project Management and Software Development, Security Analysis, Security Architecture, Security Attacks, Security Design, Security Infrastructure, Security Monitoring, Security Software, Security System Design, Software Administration, Software Design, Software Engineering, Software Patches, Subnet, Sustainability, System Integration (SI), System Operations, Systems Administration/Management, Systems Analysis, Systems Engineering, Systems Maintenance, Systems Scalability, Team Player, Technical Research, Technical Strategy, Technical/Engineering Design, Technology Analysis, Telemetry, Test Data, Testing, Time Management, Trend Analysis, Unix Shell Programming, Validation Testing, Web Client Plug-ins, Writing Skills
LOCATION
Reston, VA
POSTED
Today
This position is to remediate Indicators of misconfigurations (IOM's) and Indicators of attack (IOA's) reported by our Cloud Security Posture Management tool CrowdStrike. Defines, designs, develops, and engineers secure cloud platform solutions with a primary focus on the remediation of AWS cloud security vulnerabilities, compliance gaps, and platform risks. Performs vulnerability analysis, root-cause assessment, remediation planning, and engineering implementation across AWS services, infrastructure-as-code, operating systems, containers, and supporting platform components. Assesses architecture and current platform limitations, defines secure system specifications, and evaluates input/output processes and working parameters for cloud, infrastructure, and software compatibility. Coordinates remediation activities across Cloud Platform Engineering, Security, application teams, and infrastructure stakeholders to ensure vulnerabilities are prioritized, remediated, validated, and sustainably prevented. Defines system support requirements to include monitoring, capacity, staffing, patching/updating, automation, and security guardrails. Analyzes and resolves platform support deficiencies and conducts independent technical investigations in cloud security, systems design, and engineering remediation.

ESSENTIAL FUNCTIONS:
30% Leads hands-on remediation of AWS cloud security vulnerabilities, including findings related to IAM, network exposure, encryption, logging, patching, configuration drift, container security, and cloud service misconfiguration. Installs, tunes, upgrades, troubleshoots, and maintains cloud and systems platforms relevant to supported applications, including operating system administration, user access management, disaster recovery support, networking configuration, patching, and vulnerability remediation.

25% Develops and implements engineering solutions, automation, and guardrails to prevent recurring security vulnerabilities and system problems. Troubleshoots incidents, supports service recovery, performs root-cause analysis, and implements corrective actions that improve cloud security posture, reliability, and operational resilience.

20% Evaluates new and existing cloud services, systems, and security controls by performing in-depth testing, end-user reviews, vulnerability validation, remediation verification, and performance assessments. Researches cloud security tools, AWS-native capabilities, automation solutions, and related products to support recommendations and purchasing. Determines systems integration issues by evaluating components; developing and completing security, performance, and integration tests; analyzing test data; studying project requirements; analyzing user and stakeholder input; and developing secure automation and integration of business and platform processes.

15% Improves engineering and cloud security knowledge by attending educational workshops; reviewing professional publications; establishing personal networks; benchmarking state-of-the-art AWS security, platform engineering, and vulnerability management practices; and participating in professional societies.

10% Acts as a mentor for junior and senior team members, with emphasis on secure cloud engineering practices, vulnerability remediation, automation, infrastructure as code, and AWS platform standards.

Qualifications
To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

Education Level: Bachelor's Degree

Education Details: Information Technology, Computer Science, Cybersecurity, Engineering, or related technical field.

Experience: 8 years proven success overseeing the design, development, implementation, support, and secure operation of software systems, cloud platforms, infrastructure services, or enterprise applications.

In Lieu of Education
In lieu of a bachelor's degree, an additional 4 years of relevant work experience is required in addition to the required work experience.

Preferred Qualifications
Seeking an experienced and hands-on AWS Cloud Platform Engineer with strong cloud security, vulnerability remediation, infrastructure engineering, and automation experience. This resource will focus on remediating cloud security vulnerabilities across the AWS environment, strengthening platform guardrails, and improving the security posture of enterprise cloud services.

The AWS Cloud Platform Engineer will be responsible for analyzing security findings, designing and implementing remediation solutions, validating closure of vulnerabilities, and integrating preventive controls into the AWS platform. The role requires strong hands-on engineering capability, deep AWS platform knowledge, and the ability to collaborate with Security, Cloud Platform Engineering, application teams, architects, and operations teams to deliver scalable, reliable, secure, and compliant cloud solutions.

Summary:
Minimum of 10 years of IT experience, of which at least 5 years must be in AWS Cloud Platform engineering, administration, automation, or security remediation.
Strong hands-on AWS engineering experience with proven ability to remediate cloud security vulnerabilities and harden AWS environments.
Experience analyzing and remediating findings from cloud security, vulnerability management, configuration compliance, container security, and monitoring tools.
Strong experience with AWS security services and controls, including IAM, Organizations, SCPs, GuardDuty, Security Hub, Inspector, Config, CloudTrail, CloudWatch, KMS, Secrets Manager, WAF, VPC, Security Groups, NACLs, S3 security, EC2 hardening, Lambda security, and EKS security.
Strong leadership experience driving security remediation, cloud transformation, and platform engineering initiatives.
3-5 years of experience in a Site Reliability Engineering or cloud operations role.
Experience with SRE principles, operational resilience, and transformation.
3+ years of experience with containerization, Kubernetes, AWS EKS, DevOps toolchains, Ansible, Jenkins, Artifactory, Bitbucket, infrastructure as code, automated provisioning, release automation, and CI/CD.
Solid understanding of software engineering practices, including build, integration, test, release, deployment, and automation using Python.
Experience developing, challenging, and improving engineering solutions and practices in partnership with developers, architects, engineers, security teams, and customers.
Platform engineering lead with hands-on experience building robust middleware, cloud, and Linux-based environments.
Previous Linux system administration experience is required.
Must have strong hands-on knowledge of AWS platform and services, including but not limited to VPC, networking, Direct Connect, subnets, NACLs, Security Groups, EC2, S3, IAM, ELB, Lambda, CloudWatch, CloudTrail, AWS Config, GuardDuty, Inspector, Security Hub, KMS, Secrets Manager, WAF, and EKS.
Must have hands-on current implementation and production-level experience in AWS Cloud.
Hands-on experience with automation and infrastructure provisioning is required; the target state is infrastructure as code, policy as code, automated remediation, and repeatable security guardrails.
Must be familiar with Terraform automation, Ansible playbooks, Python code, and secure CI/CD practices.
Experience with AWS CloudFormation and CDK is required.
Must have hands-on experience writing Lambda functions, preferably in Python using Boto3, to support automation and remediation workflows.
Must be well versed in writing Linux Bash scripts.
Minimum of one AWS certification is required; AWS Security Specialty, Solutions Architect, SysOps Administrator, or DevOps Engineer certification is preferred.
Hands-on experience with containerization and Amazon EKS is a strong plus.
Strong understanding of DevOps toolchains, including Git/repo, Crucible, Jenkins, Bitbucket, Jira, Artifactory, and related tools.
Solid understanding and experience with CI/CD toolchains and secure software delivery practices.

Qualifications:
" 10+ years of overall IT experience, including hands-on development, systems engineering, cloud engineering, infrastructure operations, or security remediation background.
" Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Engineering, or related field; master's degree preferred.
" 5-10 years of experience in cloud engineering and automation, with a focus on AWS cloud services.
" Minimum of 8-10 years of IT experience, of which at least 5 years must be in AWS cloud automation, administration, platform engineering, or security remediation.
" 3-5 years of experience in a Site Reliability Engineering, cloud operations, or production engineering role.
" 3+ years of experience implementing containerization, Kubernetes, AWS EKS, cloud technologies, DevOps toolchains, Jenkins, Artifactory, Bitbucket, infrastructure as code, automated provisioning/release, and CI/CD patterns.
" Must be well versed in Terraform automation, Ansible playbooks, Python code, secure scripting, and policy-as-code concepts.
" In-depth knowledge of AWS services and solutions, including but not limited to EC2, S3, RDS, Lambda, VPC, IAM, CloudFormation, CloudWatch, CloudTrail, Config, GuardDuty, Inspector, Security Hub, KMS, Secrets Manager, WAF, and EKS.
" Strong understanding of cloud architecture principles, security design patterns, vulnerability remediation practices, and best practices for building scalable, resilient, secure, and compliant cloud environments.
" Proficiency in infrastructure as code tools such as Terraform, AWS CloudFormation, or AWS CDK.
" Exposure to artificial intelligence patterns, machine learning, and engineering of AWS solutions is preferred, including knowledge of Amazon Kendra, SageMaker, Lambda, Bedrock, and retrieval-augmented generation models.
" Excellent communication, collaboration, and leadership skills, with the ability to effectively interact with technical and non-technical stakeholders.
" Minimum of one AWS certification is required; AWS Certified Security Specialty, Solutions Architect, SysOps Administrator, or DevOps Engineer certification is preferred.
" Experience working in an Agile/Scrum environment preferred.
" Solid understanding of software coding techniques and experience across the full software engineering lifecycle, including build, integration, test, release, deployment, and automation leveraging Python.
" Hands-on experience with CI/CD pipelines, containerization technologies, Docker, Kubernetes, serverless computing, and secure software delivery is a plus.
" Experience developing and challenging engineering solutions and practices while collaborating across developers, architects, security engineers, platform engineers, and infrastructure teams.

Roles & Responsibilities:
" Lead hands-on remediation of AWS cloud security vulnerabilities, misconfigurations, compliance gaps, and platform risks across production and non-production environments.
" Review security findings from AWS-native and enterprise security tools, determine remediation approach, implement fixes, and validate successful closure.
" Communicate architectural decisions, remediation plans, goals, strategies, and short-term trade-offs versus long-term commitments, risk reduction, and cost impacts.
" Engage in and improve the end-to-end lifecycle of cloud services, starting from inception and design through deployment, operations, monitoring, and continuous security improvement.
" Establish automation capabilities leveraging AWS-native services, infrastructure as code, policy as code, and CI/CD pipelines to improve developer experience and reduce recurring vulnerabilities.
" Support activities including system design consulting, secure platform engineering, software platforms and frameworks, capacity planning, launch reviews, and operational readiness reviews.
" Troubleshoot difficult cloud security, infrastructure, and application platform issues and engage customers and stakeholders to drive timely remediation.
" Learn and apply new AWS services, security capabilities, and engineering practices as required.
" Improve system scalability, sustainability, reliability, and security through automation, repeatable patterns, and engineering standards.
" Support enterprise cloud transformation, migration, modernization, and security posture improvement efforts.
" Guide customers on cloud-native design, secure architecture patterns, AWS security controls, and platform guardrails.
" Provide consultation on technology infrastructure planning, security remediation, and engineering for assigned systems; assess the implications of technology strategies on infrastructure capabilities and risk posture.
" Establish strategies to migrate legacy applications to secure, cloud-native patterns, including microservices hosted on AWS Cloud.
" Leverage cloud-native architecture components including containers, immutable infrastructure, microservices, service mesh, serverless capabilities, and managed AWS services to build highly available, fault-tolerant, and secure applications.
" Conduct research on global technology, cloud security, and platform engineering trends and their applicability to client's products in support of internal development teams and business initiatives.
" Promote modern application design, engineering best practices, secure-by-design patterns, vulnerability mitigation, and lifecycle risk management.
" Monitor and manage stability, availability, performance, and security of enterprise systems and platforms across IT domains.
o Analyze systems, network, storage, cloud, and security telemetry to identify problems, trends, vulnerabilities, and opportunities for improvement.
" Automate end-to-end processes to maintain, patch, upgrade, harden, and secure the AWS cloud ecosystem.
" Make data-driven recommendations and decisions that improve the overall efficacy, efficiency, security, and reliability of software delivery and cloud platform capabilities.
" Mentor peers and engage across teams to socialize solutions, improve security practices, and increase engineering maturity.

Strong skills are desired in each of the following areas:
Cloud Security and Vulnerability Remediation: AWS security services, vulnerability management, configuration compliance, security guardrails, threat detection, IAM hardening, encryption, logging, monitoring, patching, and secure cloud engineering.
Development: Experience programming with one or more languages, including Python, Java, Groovy, or Go.
IaC Tools for Platform Automation: Strong skills and experience in at least one of the following: Ansible, Terraform, AWS CloudFormation, or AWS CDK.
Containers: Docker or other OCI-certified containers is a plus.
Container Orchestration Platform: Experience with Kubernetes, AWS EKS, or AWS ECS is a plus.
CNI Plugins: Calico, Flannel, Weave Net, or similar technologies.
Service Mesh: Istio, AWS App Mesh, OpenShift Service Mesh, or similar technologies.
Container Security Tools: Twistlock, Sysdig, Aqua, Prisma Cloud, or similar tools is a plus.
Platform Monitoring, Observability, & Performance Tools: Nginx, New Relic, AppDynamics, Datadog, Thanos, Jaeger, LogDNA, CloudWatch, CloudTrail, AWS Config, and related observability tools.
DevOps Tools: Git/Repo, Crucible, Bitbucket, Jira, Ansible, Puppet, Jenkins, ArgoCD, Bamboo, Maven, Artifactory, Nexus, and related tools.

Other Required Skills:
" Understanding of cloud-native architecture and secure-by-design engineering principles.
" Linux, shell scripting, and general administration skills.
" Network, security, plugins, and storage skills.
" AWS skills: EC2, S3, EBS, EFS, IAM, VPC, Lambda, CloudTrail, CloudWatch, Config, GuardDuty, Inspector, Security Hub, KMS, Secrets Manager, WAF, and EKS.
" Cloud, security, and DevOps certifications, including AWS certification.

Knowledge, Skills, and Abilities (KSAs)
" Knowledge of programming languages, scripting, automation, cloud security, vulnerability remediation, and web-based technologies.
" Ability to collaborate across teams to solve technical, operational, and security problems.
" Expert - Excellent communication skills, both written and verbal.
" Expert - The incumbent is required to immediately disclose any debarment, exclusion, or other event that makes them ineligible to perform work directly or indirectly on Federal health care programs.
" Must be able to effectively work in a fast-paced environment with frequently changing priorities, deadlines, and workloads that can be variable for long periods of time.
" Must be able to meet established deadlines and handle multiple customer service demands from internal and external customers, within set expectations for service excellence.
" Must be able to effectively communicate and provide positive customer service to every internal and external customer, including customers who may be demanding or otherwise challenging.

Licenses/Certifications
AWS Cloud certification, minimum of one, is required.
AWS Certified Security Specialty, AWS Certified Solutions Architect, AWS Certified SysOps Administrator, or AWS Certified DevOps Engineer is preferred.


**Talteam Inc. is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or protected veteran status and will not be discriminated against on the basis of disability.**

About the Company

T

Talteam