AWS Cloud Security Engineer
Candidates must be U.S. citizens able to obtain and/or maintain a Department of Defense security clearance as a condition and continuation of employment.
Location: Stafford, Virginia (Hybrid)
Role Overview
We are seeking an AWS Cloud Security Engineer to support a mission-critical program for a federal government agency. This role involves designing, implementing, and maintaining a secure AWS cloud infrastructure for application development and operations. You will serve on the Security & Infrastructure team, responsible for AWS cloud environments spanning development, test, pre-production, and production.
Key Responsibilities
- Design, build, and maintain AWS infrastructure, including EC2, IAM, VPC networking, security groups, and AMI lifecycle management.
- Provision and manage infrastructure as code using CloudFormation.
- Implement and validate security settings and hardening across cloud infrastructure, operating system baselines, and application platforms.
- Provide AWS network and security support, including subnet design, security group configuration, and encryption management.
- Design and maintain least-privilege IAM roles and policies, and remediate findings from security tools like IAM Access Analyzer, Security Hub, and GuardDuty.
- Implement NIST SP 800-53 security controls within the cloud environment and contribute technical content to authorization packages.
- Support security assessments by producing evidence, responding to questions, and driving remediation activities.
- Collaborate with development and infrastructure teams to ensure stable, current, and available environments.
- Participate in Agile ceremonies, refine stories, and provide estimates for infrastructure and security work.
- Troubleshoot environment and pipeline issues, documenting the root cause and resolution.
Required Qualifications
- A minimum of 3 years of hands-on experience in AWS cloud engineering, including administering EC2, IAM, VPC, and AMIs.
- Experience supporting federal security compliance efforts, including NIST 800-53, the Risk Management Framework (RMF), and contributing to security documentation for an accredited system.
- Demonstrated experience with security settings implementation and system hardening.
- Proficiency in a scripting language such as PowerShell or Bash.
- Experience using or managing Git-based version control.
- A current Security+ certification or the ability to obtain one within 6 months of starting.
Preferred Qualifications
- Experience working with Kubernetes and container images.
- Experience with federal cloud security environments supporting mission-critical applications.
- System Administration experience.
Benefits
Everforth Apex offers a range of supplemental benefits, including medical, dental, vision, life, disability, and other insurance plans that offer an optional layer of financial protection. We offer an ESPP (employee stock purchase program) and a 401K program which allows you to contribute typically within 30 days of starting, with a company match after 12 months of tenure. Everforth Apex also offers a HSA (Health Savings Account on the HDHP plan), a SupportLinc Employee Assistance Program (EAP) with up to 8 free counseling sessions, a corporate discount savings program and other discounts. In terms of professional development, Everforth Apex hosts an on-demand training program, provides access to certification prep and a library of technical and leadership courses/books/seminars once you have 6+ months of tenure, and certification discounts and other perks to associations that include CompTIA and IIBA. Everforth Apex has a dedicated customer service team for our Consultants that can address questions around benefits and other resources, as well as a certified Career Coach. You can access a full list of our benefits, programs, support teams and resources within our 'Welcome Packet' as well, which an Everforth Apex team member can provide.