- Company Name
- LightFeather
- Job Title
- Cloud Security Engineer
- Job Description
-
Job title: Cloud Security Engineer
Role Summary:
Design, implement, and secure multi‑cloud (AWS, Azure, GCP) architectures at scale, embedding DevSecOps practices into development lifecycles. Lead threat modeling, secure coding guidance, and automation of security controls across commercial, GovCloud, and DoD IL6 environments.
Expactations:
- Secure infrastructure across multiple accounts or subscriptions, ensuring compliance with CIS, NIST 800‑53, FedRAMP, and other frameworks.
- Deliver automated guardrails, CI/CD security scans, and incident response tooling for high‑volume cloud workloads.
- Collaborate with architects, engineers, auditors, and stakeholders to achieve authorization to operate (ATO) and other compliance milestones.
- Mentor a team of security and platform engineers, driving adoption of secure practices in agile DevSecOps teams.
Key Responsibilities:
- Architect and deploy secure cloud environments (Commercial, GovCloud, IL6).
- Define and enforce security baselines (CIS, NIST, FedRAMP).
- Conduct architecture reviews, threat modeling, and provide secure design guidance.
- Build and maintain Terraform IaC modules for hundreds of accounts/projects.
- Integrate CI/CD pipelines with SAST, DAST, IaC scanning, and container security tools.
- Develop automated remediation pipelines and guardrails.
- Support ATO processes, documentation, and stakeholder reporting.
- Implement centralized logging, monitoring, and incident response across multi‑cloud stacks.
- Lead a team of security/platform engineers on cloud security and automation practices.
- Act as subject matter expert for stakeholders, architects, and engineering leads.
Required Skills:
- 5+ years cloud security experience (AWS, Azure, GCP, Oracle).
- Advanced hands‑on experience securing and automating multi‑cloud environments.
- Native cloud security tools: Security Hub, GuardDuty, Defender for Cloud, SCC, etc.
- IaC expertise: Terraform, CloudFormation, ARM/Bicep.
- CI/CD platforms: GitLab, GitHub Actions, etc.
- Proficiency in at least one programming/scripting language (Python, Go, PowerShell, Bash).
- Deep understanding of IAM/RBAC, KMS/Key Vault, networking, encryption.
- Familiarity with application security standards (OWASP ASVS/Top 10, CWE 25).
- Experience aligning controls with NIST 800‑53, FedRAMP, CIS Benchmarks.
- Proven track record embedding security in Agile/DevSecOps pipelines.
- Strong communication, stakeholder management, and leadership.
Required Education & Certifications:
- Bachelor’s degree in computer science or related technical field (or equivalent experience).
- Certifications desired: AWS Certified Security – Specialty, Azure Security Engineer Associate, Google Professional Cloud Security Engineer, OSCP, CISSP.
Alexandria, United states
On site
Mid level
18-11-2025