Cloud Security Engineer

SteampunkMcLean, VA
$110,000 - $155,000

About The Position

Steampunk is seeking a Cloud Security Engineer to join our growing DevSecOps practice. In this role, you will deliver features supporting the development, testing, and monitoring of secure cloud architectures for cloud migration, optimization, and deployment. We are looking for candidates with expertise in cloud platform services, cybersecurity, and DevOps practices such as infrastructure as code and configuration management automation. You will be responsible for identifying and implementing secure cloud solutions, including zero-trust architectures, identity and access management policies, and data privacy measures. A key aspect of this role involves understanding stakeholder needs to optimize solutions that balance security with usability. You will also monitor cloud environments for suspicious activities using cloud-native monitoring or SIEM solutions, investigate security incidents, and analyze the risk of infrastructure as code written by others. Ensuring system safety and security against cybersecurity threats through risk assessment, threat modeling, and compliance with industry standards (e.g., NIST, ISO 27011, HIPPA, FISMA) is crucial. You will identify technical problems, perform root cause analysis, and develop updates and fixes. Automation of security processes like vulnerability and patch management is expected. Collaboration with software developers and DevSecOps engineers to ensure adherence to established security processes is vital. You will support enterprise cloud security through infrastructure as code, including automated server/network configurations, large-scale software deployments, and monitoring/testing. Ensuring effective design and implementation of data protection and encryption mechanisms for data at rest and in transit is a core responsibility. You will document the current state of the environment, conduct gap analyses, and produce artifacts outlining options and recommendations. Identifying, analyzing, and resolving infrastructure vulnerabilities and application deployment issues will be part of your duties. This role involves acting as an individual contributor and mentoring junior team members. You will engineer and implement solutions, provide recommendations for continuous improvement, present regular status updates, and conduct cross-training for team members.

Requirements

  • Ability to obtain a U.S. government Security Clearance
  • Bachelor's degree in an IT field OR Bachelor's degree in a non-IT field and 2 years related IT experience
  • 5+ years of total experience
  • 3 years of experience architecting, designing, developing, and implementing cloud solutions
  • 3 years of experience with one or more clouds (i.e. AWS, Azure, or GCP)
  • 3 years of experience with Git SCM providers such as GitHub, GitLab, Bitbucket
  • 3 years of experience with systems development in an Agile environment
  • 3 years of experience implementing infrastructure as code and orchestration
  • 3 years of experience providing conducting monitoring, risk assessment, threat modeling and security testing in cloud environments
  • 3 years of experience documenting POAMs, SSPs, and A&A support documentation
  • Must have and maintain an active cloud or security related certification

Nice To Haves

  • AWS Certified Security Specialty
  • AWS Certified Solution Solution Architect Associate
  • Microsoft Certified Azure Administrator Associate
  • Certified Information Systems Security Professional (CISSP)
  • Excellent written and verbal communication skills
  • Excellent interpersonal and collaborative skills
  • Experience with documenting an as-is state of the environment, perform a gap analysis, and produce artifacts that articulate options and recommendations
  • Experience with scripting in Concourse, Bash, PowerShell, Python, Groovy, or Ruby
  • Experience with automation tools, including Pivotal, Chef, Terraform, CloudFormation, or Ansible

Responsibilities

  • Identify and implement the most secure cloud-based solutions for the customer including components for zero-trust architectures, identity and access management policy, and data privacy.
  • Understand the needs of stakeholders and optimize solutions that marry security with usability.
  • Monitor cloud environments for suspicious activities with cloud native monitoring or SIEM solutions and investigate security incidents where appropriate.
  • Examine infrastructure as code written by others and analyzing risk.
  • Ensure that systems are safe and secure against cybersecurity threats through risk assessment, threat modeling, and compliance with industry standards (e.g. NIST, ISO 27011, HIPPA, FISMA, etc.).
  • Identify technical problems, perform root cause analysis, and develop updates and ‘fixes’.
  • Automate security processes such as vulnerability management and patch management.
  • Work with software developers and DevSecOps engineers to ensure that development follows established security processes and works as intended.
  • Support enterprise cloud security through infrastructure as code including any activities around automated server or network configurations, large-scale software deployments, and monitoring and testing.
  • Ensure effective design and implementation of data protection and encryption mechanisms for data at rest and in transit.
  • Document as-is state of the environment, perform a gap analysis, and produce artifacts that articulate options and recommendations.
  • Identify, analyze, and resolve infrastructure vulnerabilities and application deployment issues.
  • Act as an individual contributor and mentor more junior team members.
  • Engineer and implement solutions and provide recommendations for continuous improvement for the services provided.
  • Present regular status updates and provide cross training to other team members.

Benefits

  • employee-owned company
  • startup mindset
  • time-tested approaches tailored for the federal government
  • disrupting the status quo
  • setting the pace in the ecosystem of government contractors
  • repurposing tried-and-true methodologies
  • empowering our people to find creative solutions to intractable problems
  • environment in which to grow and thrive is outside our comfort zone
  • human-centered design makes for an excellent one
  • effective teams are powered by diverse perspectives, backgrounds, and experiences
  • equal opportunity employer committed to promoting diversity of race, gender, sexual orientation, religion, ethnicity, national origin, disability status, and protected veteran status
  • participate in the E-Verify program
  • additional Steampunk benefits here
  • investing in our employees to enable them to do the greatest work of their careers
  • rewarding them for outstanding contributions to our growth
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service