Cloud Security Engineer
- Onsite
- All infrastructure & security jobs
- Full Time
- AnaVation Job Opportunities
About the role
Description of Task to be Performed:
AnaVation is seeking a Cloud Security Engineer to support one of our cybersecurity programs in our San Antonio office. In this position, the right candidate will lead zero trust engineering, interoperability, and modern security capability development across the Government enterprise. The Cloud Security Engineer will manage security systems and tools for cloud technologies, investigate and enhance existing cloud structures, and drives issue identification/resolution, integration, gap assessment, and continuous improvement, while providing flexible reach-back across the Government’s Cyber Assessment Roadmap.
Position Responsibilities: This position sets the engineering direction for the Government’s zero trust and cloud security modernization, translating roadmap objectives into deployed, measurable capability.
Responsibilities include:
- Lead zero trust engineering and interoperability initiatives, future-proofing implementations as tools and requirements evolve.
- Design, implement, and maintain AWS cloud architecture using Terraform (including custom modules) and Ansible.
- Administer relevant cloud infrastructure-level consoles (e.g., AWS) and secure cloud services and accounts; apply advanced networking, VPC, peering, and subnet design.
- Support the SIEM, SOAR, Incident Management System (IMS), and Incident Response Team (IRT) roadmap, engineering, and integration.
- Architect logging, monitoring, and telemetry, coordinating delivery with the Cyber Security Service Provider (CSSP).
- Advance security automation and automated evidence collection to increase inheritance and continuous monitoring maturity.
- Provide flexible SME support and reach-back across DevSecOps automation, supply chain security, enterprise vulnerability management, and AI.
- Provide updates to the Cyber Assessment Roadmap; create/maintain documentation and brief technical and non-technical stakeholders.
- Collaborate with ISSMs, ISSEs, Value Stream engineers, COT, CPT, and Government stakeholders using tools like git.
- Support Zero Trust enforcement, cloud security controls, and Infrastructure as Code security across mission environments.
- Maintain and validate A&A control evidence in eMASS (control implementation, SIAs, SRCs, POA&Ms) supporting continuous monitoring and cATO readiness.
- Architect and integrate an enterprise SIEM ingesting logs from AWS (VPC, EKS, CloudTrail), Okta, Istio, GitLab, and host logs (systemd, audit), with dashboards for runtime monitoring, defense, and forensics.
- Enforce Zero Trust through ICAM integration and micro-segmentation validation and manage enterprise security tooling.
Required Qualifications:
- Clearance: U.S. Citizen, current TS/SCI; current CI Polygraph
- Education: Bachelor's degree in Cybersecurity, Computer Science, Cloud Computing, IT, or related technical field.
- Certification: DoD 8140/8570 IAT Level II and an AWS certification.
- Location: Full-time on-site in San Antonio, TX.
- Experience and knowledge:
- Subject Matter Expert: provides technical and management leadership on major tasks; domain and expert technical knowledge; decisions may have critical project impact; may lead others.
- Highly experienced with AWS; advanced networking, VPC, peering, and subnet experience.
- GitLab CI experience; Terraform experience including writing custom modules and collaboration at scale; Ansible experience.
- Proficient in Linux; SRE experience for a mid-to-large enterprise system.
- Designing, implementing, and maintaining AWS cloud architecture; creating/maintaining implementation documentation.
- Experience supporting RMF, ATO, cATO, and continuous monitoring; SIEM and security automation (familiarity with SOAR/IMS).
- Minimum years of experience - 10 years of relevant experience.
Preferred Qualifications:
- Clearance: Active TS/SCI
- Education: Advanced degree in a related technical field.
- Certification: AWS Certified Security - Specialty, CCSP, CISSP, CKS, or CKA.
- Experience and Knowledge:
- General cloud architecture experience with Azure or GCP (a plus, not required); experience with Kubernetes and Docker.
- Knowledge of SQL databases and coding skills (Java, Python, Go, C++); microservices architectures.
- Security framework experience (RMF, DISA STIG, CIS Benchmarks); software engineering background.
- Experience engineering SOAR/IMS and supporting Incident Response Teams (IRT); applying AI/ML to security automation.
- Experience supporting P1 or software factory environments (Iron Bank, Big Bang); IL4/IL5/IL6 cloud environments.
- Generous cost sharing for medical insurance for the employee and dependents
- 100% company paid dental insurance for employees and dependents
- 100% company paid long-term and short-term disability insurance
- 100% company paid vision insurance for employees and dependents
- 401k plan with generous match and 100% immediate vesting
- Competitive Pay
- Generous paid leave and holiday package
- Tuition and training reimbursement
- Life and AD&D Insurance
Description as published by AnaVation.