Cybersecurity Engineer - Cloud
SAIC is a trusted leader in delivering advanced command and control capabilities across the Department of the Air Force, bringing deep expertise in how cutting-edge technologies are engineered, secured, and delivered. At the center of this mission, the Common Mission Control Center (CMCC) unifies data, sensors, mission applications, cloud-based services, and emerging AI-enabled automation to give warfighters a decisive edge—turning complex, multidomain information into fast, clear, and actionable decisions.
About the role
The Cybersecurity Engineer (Cloud) secures and accredits CMCC’s multi-tenant cloud environments (Dev, Integration, Test). The role implements JSIG/NIST/STIG baselines, engineers secure multi-classification cloud designs, validates Capability Provider and External cyber artifacts, and ensures all required evidence is provided to the Infrastructure TO for Baseline updates. This position develops RMF/ATO packages for cloud environments, partners closely with DSOP, Platform, CE, and Cloud SMEs, and contributes hands-on effort to early DSOP/cloud design and environment build-out.
Responsibilities
- Build and secure multi-tenant CMCC cloud environments.
- Implement JSIG, NIST SP 800-53, STIG, and MLS/MILS baselines across Dev/Integration/Test cloud enclaves.
- Own RMF/ATO packages for cloud environments, producing SSP, POA&M, and full RMF evidence.
- Validate STIG, ACAS/Nessus, SAST/DAST, and container-security outputs prior to environment promotion.
- Perform functional validation of CP/External cyber artifacts; coordinate delivery of validated evidence to Infrastructure TO.
- Maintain cloud-aligned continuous monitoring, including audit logs, cloud telemetry, and Prometheus/Grafana security metrics.
- Support Cloud + DSOP joint early design efforts; collaborate to integrate pipeline-aware cloud security.
- Validate IaC/CaC baselines (Terraform, Ansible, Helm) for secure, consistent cloud deployments and promotion gates.
- Provide cyber recommendations during CCB promotion evaluations.
Requirements
- Bachelor’s degree and nine (9) years or more experience; Master’s and seven (7) years or more experience; PhD or JD and four (4) years or more experience.
- Proven experience securing multi-classification cloud environments.
- Hands-on experience performing STIG review/hardening, validating ACAS/Nessus outputs, and adjudicating SAST/DAST results.
- Experience maintaining RMF/ATO artifacts (SSP, POA&M, continuous monitoring evidence).
- Familiarity with Jira/Xacta workflows for RMF and vulnerability tracking.
- DoD 8140 aligned certifications: CISSP, CCSP, CASP+, or equivalent.
Qualifications
- Experience architecting and securing hybrid cloud and MLS/MILS cross-domain environments.
- Prior support to SCA assessments (finding remediation, documentation, assessor coordination).
- Knowledge of secure DevSecOps pipeline integration, including image signing, SBOM/SCA, and environment gate validation.
- Experience with advanced cyber assessment, scanning, and STIG automation tools.
- Experience with cloud IaC/CaC security tooling (Terraform, Ansible, Helm, Argo CD).
- Familiarity with Zero Trust architecture, container hardening, and cloud security automation platforms.
- Strong documentation and communication skills aligned with RMF evidence and CMCC governance.
Pay
Target salary range $160,001 - $200,000. The estimate displayed represents the typical salary range for this position based on experience and other factors.
Schedule
- Full-Time
- Day Shift
- Hybrid (ORA_HYBRID)
- Travel: Yes - 10% of the time