Principal Cloud Engineer

Space Telescope Science InstituteBaltimore, MD
$160,000 - $175,000Hybrid

About The Position

The Space Telescope Science Institute (STScI) is seeking a Principal AWS Cloud Cybersecurity Automation & Systems (CACS) Engineer to join their Cloud Center of Excellence team. This role is mission-critical, supporting NASA's flagship space telescope missions like the Hubble, James Webb, and Nancy Grace Roman Space Telescopes. The engineer will lead cloud security automation initiatives, applying platform engineering and Kubernetes practices to design, implement, and operate security controls, guardrails, and monitoring systems across AWS environments. The goal is to build a secure foundation for mission and science teams, owning solutions from concept to production. This position supports hybrid or fully remote work arrangements, with specific residency requirements (MD, DE, VA, PA, DC, or WV). U.S. Citizenship or Permanent Residency and ITAR clearance are required.

Requirements

  • Minimum of 10 years of experience in one or more of the following roles: Software Developer, System Development Engineer, Site Reliability Engineer, or DevOps Engineer.
  • Minimum of 7 years of experience as a Cloud Security Automation Engineer or Cloud DevSecOps Engineer.
  • Hands-on experience deploying and operating Amazon EKS in production.
  • Demonstrated experience implementing platform engineering practices, including internal developer platforms or self-service tooling.
  • Deep expertise in AWS cloud security and automation.
  • Expertise with infrastructure as code using CloudFormation, Terraform, or CDK.
  • Experience designing and operating automated incident response.
  • Strong grounding in DevOps principles and automated security testing within CI/CD.
  • Applied knowledge of cloud security best practices and control frameworks.
  • Proven ability to work independently and drive solutions to completion through active stakeholder engagement.

Nice To Haves

  • Experience with single sign-on platforms such as Okta, Auth0, or similar.
  • Experience with log management and dashboarding using Datadog, ELK, or similar platforms.
  • Experience implementing agentic AI or LLM-based automation in an engineering or security context.
  • Professional-level certifications such as AWS Certified DevOps Engineer – Professional, AWS Certified Solutions Architect – Professional, and a Kubernetes certification such as Certified Kubernetes Administrator (CKA) or Certified Kubernetes Security Specialist (CKS)

Responsibilities

  • Serve as the technical lead for cloud security automation, partnering with software engineers, Institute security engineers, and DevOps engineers to design and deliver secure cloud capabilities.
  • Take solutions from idea to production independently: identify the gaps, propose an approach, socialize it with stakeholders, and own delivery through implementation.
  • Design, deploy, and secure workloads on Amazon EKS, including cluster hardening, workload identity, admission control, and runtime protection.
  • Drive platform engineering implementation by building paved road tooling, reusable modules, and self-service capabilities so product teams can ship securely by default.
  • Build and maintain infrastructure as code using CloudFormation, Terraform, or CDK, with security controls and guardrails expressed as code.
  • Embed automated security testing and policy enforcement into CI/CD pipelines.
  • Build and operate automated incident response workflows spanning detection, triage, containment, and remediation.
  • Evaluate and implement agentic AI capabilities to automate security engineering and operational tasks, with appropriate guardrails and human review.
  • Collaborate across engineering, IT, and other security teams, and build relationships with internal customers to identify needs and increase the impact of the team's work.

Benefits

  • excellent and generous benefits package
  • tuition reimbursement
  • flexible work schedules
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service