Subject Matter Expert - Cloud Security Engineer

Blake Willson GroupArlington, VA
1d$140,000 - $170,000Remote

About The Position

In this position as a Cloud Security Engineer, you will support the implementation, monitoring, and continuous assessment of security controls within AWS environments supporting federal systems. You will focus on cloud-native security tooling, continuous monitoring operations, and evidence collection to support FedRAMP and ATO requirements. In this position, you will also: Implement and manage AWS security services, including GuardDuty, Security Hub, Amazon Inspector, and AWS Config, to support cloud security monitoring and compliance. Configure and maintain centralized logging and audit capabilities, including CloudTrail, VPC Flow Logs, and DNS logs, to support security analysis and investigations. Design and maintain automated continuous monitoring pipelines across AWS accounts, aggregating findings into centralized dashboards and reporting repositories. Analyze security data to identify control deficiencies, misconfigurations, vulnerabilities, and emerging risks impacting system authorization. Collect, validate, and map technical evidence from security tools and configurations to FedRAMP and NIST SP 800-53 controls for ATO packages and assessments. Support development of Continuous Monitoring (ConMon) deliverables, including vulnerability reporting, POA&M inputs, and remediation tracking through closure. Investigate and analyze security alerts from SIEM platforms and AWS-native tools, correlating logs to determine root cause, scope, and impact. Collaborate with system, engineering, and ISSO teams to remediate findings, harden configurations, and support Rapid ATO and assessment activities.

Requirements

  • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, Information Security, Computer Engineering, Business, or a related field.
  • 5 years of IT experience, including hands-on experience with cloud-native architectures and AWS services.
  • 3 years of experience designing, implementing, and executing security controls and monitoring strategies in AWS.
  • 3 years of experience supporting compliance and regulatory requirements in cloud environments, including FedRAMP and NIST SP 800-53
  • Active possession of one of the following certifications: CISA, CRISC, CISSP, or CAP.

Nice To Haves

  • Experience using Infrastructure-as-Code (IaC), including CloudFormation, to deploy and manage secure AWS environments.
  • Hands-on experience with security and monitoring tools such as Splunk, Nessus, Tenable Security Center, and enterprise firewall technologies (e.g., Palo Alto, Imperva, Fortinet).
  • Experience supporting federal ATO or continuous monitoring programs.
  • Experience automating compliance evidence collection and reporting.
  • Strong documentation and technical communication skills.

Responsibilities

  • Implement and manage AWS security services, including GuardDuty, Security Hub, Amazon Inspector, and AWS Config, to support cloud security monitoring and compliance.
  • Configure and maintain centralized logging and audit capabilities, including CloudTrail, VPC Flow Logs, and DNS logs, to support security analysis and investigations.
  • Design and maintain automated continuous monitoring pipelines across AWS accounts, aggregating findings into centralized dashboards and reporting repositories.
  • Analyze security data to identify control deficiencies, misconfigurations, vulnerabilities, and emerging risks impacting system authorization.
  • Collect, validate, and map technical evidence from security tools and configurations to FedRAMP and NIST SP 800-53 controls for ATO packages and assessments.
  • Support development of Continuous Monitoring (ConMon) deliverables, including vulnerability reporting, POA&M inputs, and remediation tracking through closure.
  • Investigate and analyze security alerts from SIEM platforms and AWS-native tools, correlating logs to determine root cause, scope, and impact.
  • Collaborate with system, engineering, and ISSO teams to remediate findings, harden configurations, and support Rapid ATO and assessment activities.

Benefits

  • major medical benefits such as dental and vision coverage
  • a 401(k)-contribution plan
  • holiday and personal time off
  • professional development training & certification benefits
  • health & wellness subsidies
  • paid time off for community service
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service