Cyber Security Engineer – Senior / Cloud DoS CSS

OneZero Solutions•Washington, DC
•Remote

About The Position

The Senior Cloud Security Engineer owns cloud security engineering for DT/EA/CST's cloud-based and hybrid authorization boundaries. The engineer operates and extends the Wiz cloud security platform, applies Department cloud and zero-trust overlays, documents controls inherited from cloud service providers and DT enterprise services, supports cryptographic key management activities, and produces the cloud evidence the ISSO team needs to obtain and maintain ATOs.

Requirements

  • Eight (8)+ years of cybersecurity or systems engineering experience, including three (3)+ years securing federal workloads in AWS GovCloud, Azure Government, or equivalent.
  • Hands-on experience with a CNAPP/CSPM platform (Wiz strongly preferred; Prisma Cloud, Defender for Cloud, or equivalent considered).
  • Working knowledge of NIST SP 800-53 Rev. 5 control implementation in cloud environments and FedRAMP inheritance models.
  • Active, final SECRET security clearance; U.S. citizenship.
  • DoD 8140/8570 IAT Level III or IAM Level II baseline certification (e.g., CISSP, CASP+, CCSP, CISM) or ability to obtain within 6 months.
  • Experience producing authorization evidence (diagrams, configuration exports, scan reports) for ISSOs and assessors.

Nice To Haves

  • CCSP, AWS Certified Security – Specialty, or Azure Security Engineer Associate; Wiz certification.
  • Department of State or other federal civilian cloud authorization experience.
  • Experience with Terraform/CloudFormation security, Kubernetes/container security, and CI/CD pipeline integration.
  • Experience with cryptographic key management services (AWS KMS, Azure Key Vault, HSMs) and FIPS 140-2/140-3 validated modules.

Responsibilities

  • Engineer, operate, and maintain the Wiz platform for cloud-based consular systems: account/subscription onboarding, asset grouping and tagging per CA configuration standards, policy tuning, integrations, and dashboards.
  • Support agent deployment, vulnerability and compliance scanning, data ingest and sharing, pipeline, and other integration efforts for cloud workloads.
  • Apply Department and CA cloud-security and zero-trust overlays; identify and document controls inherited from CSPs and DT enterprise services in each system's Inherited Controls Matrix and SSP(RMF Step 2).
  • Support cryptographic key management and encryption key lifecycle activities for cloud and hybrid systems.
  • Develop and maintain cloud architecture, network, and data-flow diagrams and evidence for System Boundary & Data Flow Packages and the Evidence Index(RMF Steps 1 and 3).
  • Review cloud vulnerability and compliance scan results within 5 business days of scan completion; drive critical and high findings to closure within Department and BOD timelines; provide closure evidence to ISSOs for POA&M management(RMF Step 6).
  • Perform Security Impact Analysis on cloud infrastructure and configuration changes submitted through CA change management; participate in CCB/ECM.
  • Demonstrate cloud control implementations during Security Control Review Meetings and provide screenshots, logs, and configuration evidence to the SCA(RMF Step 4).
  • Support infrastructure-as-code and container image security checks in DevSecOps pipelines and ensure results are captured as SSP evidence(RMF Step 3).
  • Coordinate with cloud system operations teams and CSPs to validate remediation and maintain the accredited security posture of cloud systems.

Benefits

  • health, dental, vision, and life insurance
  • a 401(k) with company matching
  • paid time off and holidays
  • an employee referral program
  • educational assistance
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service