This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
The Cloud Security Engineer I supports security control implementation, monitoring, and maintenance across customer-facing systems in regulated environments contributing to compliance sustainment, vulnerability remediation, system hardening, and security tooling under the guidance of senior personnel, with an expectation of growing technical depth in cloud security and secure engineering practices over time
Job Responsibility
Support implementation and maintenance of technical security controls across applications and infrastructure
Assist with security configuration of systems, services, containers, and cloud resources
Support validation of security controls and evidence collection activities
Participate in system hardening activities aligned with established security baselines and standards
Support compliance sustainment activities through artifact preparation, documentation updates, and evidence gathering
Support ISSO activities related to SSP maintenance, control implementation evidence, and POA&M tracking
Assist with preparation for audits, assessments, and security reviews
Support control testing and remediation tracking activities
Assist with vulnerability identification, triage, and remediation coordination
Support review of scan findings (e.g., STIG, ACAS/Nessus, container, and code scanning results)
Work with engineering and DevOps teams to track and verify corrective actions
Support patching and remediation validation activities
Support DevOps and security personnel in monitoring security-related logging, alerting, and audit data
Assist with investigation and documentation of security events or control anomalies
Support access control, auditability, and least-privilege implementation practices
Contribute to incident response and operational support activities as assigned
Support ISSO-led security review activities for application and infrastructure changes
Support secure configuration reviews for deployments and environment changes
Assist engineering teams in incorporating security requirements into delivery activities
Identify and escalate security concerns early in the change lifecycle
Requirements
1–3 years of experience supporting cybersecurity, cloud security, DevSecOps, system administration, or security engineering activities
Familiarity with security frameworks and compliance standards such as NIST RMF, STIGs, or FedRAMP concepts
Exposure to vulnerability management, security scanning, and remediation processes
Familiarity with Linux or Windows administration, networking fundamentals, and identity/access management concepts
Exposure to cloud-based environments, preferably AWS or AWS GovCloud
Eligibility for a security clearance and ability to operate within a regulated environment
Nice to have
Familiarity with scripting or automation technologies (e.g., Bash, Python, or similar)
Exposure to containers, CI/CD security, or infrastructure-as-code concepts (e.g., Terraform)
Familiarity with security logging and monitoring tools
Experience with ACAS / Nessus and STIG compliance support
Experience with Splunk, CloudWatch, or similar security logging tools
Familiarity with Terraform or infrastructure-as-code concepts