Search

Cloud Security Engineer

PublishedPublished: 6/14/2022
Real Estate

Job Description

Job Description

Job Title: Cloud Security Engineer

Location: Pittsburgh, PA / Lake Mary, FL / New York, NY

Experience: 12+ years

Work Type: Hybrid

Employment Type: Contract (C2C)

Duration: 12+ Months

Visa Requirement: No OPT / CPT


Note: Must have skill Exp with FedRAMP & Azure/AWS


About the Role:


We are seeking a Cloud Security Engineer who drives the technical design and full-lifecycle integration of comprehensive security control frameworks. By leveraging a deep, architectural understanding of foundational risk models (e.g., NIST SP 800-53, CSF, ISO 27001), this architect translates rigorous compliance mandates into resilient, scalable cloud infrastructure. The holistic approach to boundary definition, automated enforcement, and zero-trust principles ensures that security is engineered organically into the environment, continuously satisfying complex third-party assessment criteria.


Key Responsibilities:

  • Implement and enforce FedRAMP controls in cloud platforms
  • Review existing security frameworks and close gaps between standards and implementation
  • Deploy and validate security policies and rule sets
  • Work with data protection and cryptography teams to enforce cloud security controls
  • Ensure security controls are effective, auditable, and operational
  • Identify issues like overprovisioning and underutilization from a security and governance perspective

Required Skills:

  • Full-Lifecycle Engineering: Demonstrated experience in the end-to-end integration of rigorous control frameworks (e.g., NIST 800-53, ISO 27001, SOC 2, CMMC)-from initial gap analysis and architectural design through deployment, automated enforcement, and continuous monitoring.
  • Control Translation: Proven ability to dissect complex regulatory catalogs and translate them into actionable, technical engineering requirements for AWS infrastructure and DevSecOps pipelines.
  • Boundary & Scoping Expertise: Expertise in defining complex authorization boundaries, architecting secure enclaves, and implementing micro segmentation to isolate regulated data and reduce the overall audit footprint.
  • Compensating Controls: Adept at designing and documenting robust compensating controls and operational workarounds when native technical enforcement of a framework requirement is unfeasible.
  • Ability to work with multiple teams and drive controls into production



Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...