waypointjobs

Defense Engineering Inc.

000 – Sr AWS Cloud Security Engineer

northern, KY

Check who can apply and the requirements below before continuing.

Availability awaiting confirmation

We are waiting for a fresh update from the source. This page preserves the last received job details; current availability is not confirmed.

Job description

We are seeking a highly skilled Lead AWS Cloud Security Engineer with a deep background in AWS GovCloud (US) regions and U.S. Department of Defense (DoD) compliance frameworks. In this role, you will be responsible for designing, building, and managing secure, resilient, and fully compliant AWS Landing Zones that align with DISA’s Secure Cloud Computing Architecture (SCCA) guidelines.

The ideal candidate will have extensive hands‑on experience deploying the Virtual Data Center Security Stack (VDSS) and Virtual Data Center Managed Services (VDMS) . You will possess advanced expertise in multi‑account governance, including the authoring, testing, and continuous enforcement of restrictive Service Control Policies (SCPs) . This position is crucial to enabling our mission partners to deploy critical DoD Impact Level 4 (IL4) and Impact Level 5 (IL5) workloads safely into the cloud.

Key Responsibilities

1. SCCA Landing Zone Architecture & Engineering

VDSS Implementation: Design, deploy, and maintain the Virtual Data Center Security Stack (VDSS) to protect mission applications. Implement secure network boundary controls, application‑aware firewalls, intrusion detection/prevention systems (IDS/IPS), and perimeter defenses.

VDMS Management: Standardize and manage host security and shared management services under the Virtual Data Center Managed Services (VDMS) framework, including directory services, vulnerability scanning, host‑based security, patching, and configuration governance.

Landing Zone Automation: Utilize the AWS Landing Zone Accelerator (LZA) or custom Control Tower implementations to automate the deployment of multi‑account SCCA architectures.

TCCM Enforcement: Operate as or support the Trusted Cloud Credential Manager (TCCM) role, implementing strict Role‑Based Access Control (RBAC) and ensuring least‑privileged IAM policies.

2. AWS Organizations & Governance

Service Control Policies (SCPs): Architect, write, and manage highly restrictive Service Control Policies (SCPs) at the AWS Organization and Organizational Unit (OU) level. Prevent unauthorized service usage, enforce geographical region locks (restricting actions to AWS GovCloud), and deny modification of critical security and logging resources.

Compliance & Drift Guarding: Establish continuous automated monitoring to detect and remediate drift from SCCA compliance baselines using native AWS governance capabilities.

3. DevSecOps & Infrastructure as Code (IaC)

Draft all cloud infrastructure using secure, modular Infrastructure as Code (IaC) (primarily Terraform or AWS CloudFormation).

Maintain Infrastructure as Code in secure Git repositories and integrate automated security scanning (e.g., tfsec, Checkov) into CI/CD pipelines.

4. Integration & Security Operations

Integrate third‑party security appliances (e.g., Palo Alto, Fortinet) within VDSS transit environments where appropriate.

Configure and integrate native DoD security tooling, including Host Based Security System (HBSS) , Assured Compliance Assessment Solution (ACAS) , and CSSP security operations.

AWS Technical Stack & Services Utilized

An AWS SCCA Engineer is expected to have mastery over the following AWS GovCloud services:

Governance & Multi‑Account Architecture: AWS Organizations, Service Control Policies (SCPs), AWS Control Tower, AWS Landing Zone Accelerator (LZA).

Network Security (VDSS): AWS Transit Gateway (central transit hub), AWS Network Firewall, AWS WAF (Web Application Firewall), AWS Shield, Route 53 Resolver (including DNS Firewall), VPC Flow Logs, Application and Network Load Balancers (ALB/NLB).

Host Security, Configuration & Patch Management (VDMS): AWS Systems Manager (SSM) (Patch Manager, Session Manager, Run Command, State Manager), AWS Config, AWS Security Hub, Amazon Inspector, AWS Audit Manager.

Identity & Access Management (TCCM): AWS Identity and Access Management (IAM), AWS IAM Identity Center (SAML 2.0 integration for CAC / multi‑factor authentication), AWS Directory Service (Managed Microsoft AD).

Secrets & Cryptography: AWS Key Management Service (KMS), AWS CloudHSM (enforcing FIPS 140‑2/3 cryptographic boundaries).

Centralized Logging & Audit (Immutable Logging Sinks): AWS CloudTrail, Amazon CloudWatch, Amazon S3 (configured with Object Lock and bucket policies for compliance‑grade log retention).

Threat Detection & Incident Response: Amazon GuardDuty.

Required Qualifications

Security Clearance: Active U.S. Government Secret clearance (Top Secret/SCI preferred) due to handling DoD IL4/IL5 systems and data.

Education & Experience: Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or equivalent experience, combined with 5+ years of dedicated AWS engineering and security experience.

Compliance Expertise: Direct, demonstrable experience implementing the DISA Cloud Computing Security Requirements Guide (CC SRG) and building SCCA compliant networks (VDSS/VDMS/CAP).

AWS GovCloud Experience: Strong background deploying workloads exclusively within the AWS GovCloud (US-East/US-West)

SCP Mastery: Extensive experience designing, troubleshooting, and managing nested SCPs in complex organizational environments.

DoD 8570/8140 Certification: Must possess a baseline certification meeting IAT Level III or IAM Level III (e.g., CISSP, CASP+, CISM, or Security+ CE with relevant AWS specialty certifications).

Infrastructure as Code: Advanced proficiency in writing and maintaining Terraform or CloudFormation templates in highly regulated environments.

Preferred Qualifications

AWS Certified Security – Specialty, AWS Certified Solutions Architect – Professional, or AWS Certified DevOps Engineer – Professional.

Experience configuring SAML 2.0 federation with DoD identity providers (IdAPs) for Common Access Card (CAC) / PIV authentication.

Experience working alongside a Cyber Security Service Provider (CSSP) for authorization and ATO processes.

#J-18808-Ljbffr

Who can apply

Review the original listing for work authorization, qualifications and employer requirements.

Explore related searches

Current related jobs

Kohler

WhatJobs

Engineer, New Product Integration

kohler, WI

Salary not specified

Engineer, New Product Integration Work Mode: Onsite Location: Onsite, four days per week - Kohler, WI Opportunity This is mo…

Listing review due 2026-10-08View job

Hobbs Brook Real Estate

WhatJobs

Commercial Facilities Engineer

waltham, MA

$30.88 to $38.61 per hour

Job Description: Hobbs Brook Real Estate LLC is an innovative commercial real estate leader with a portfolio of forward-thinking, sustainable pr…

Listing review due 2026-10-08View job

Avantor

WhatJobs

Process Engineer

carpinteria, CA

See pay details in description

The Opportunity: NuSil (apart of Avantor) is seeking a Process Engineer to be responsible for all phases of silicone products manufacturing …

Listing review due 2026-10-08View job

Choctaw Global

WhatJobs

Network and Systems Engineer

Caddo, OK

Salary not specified

Why Join Choctaw Global At Choctaw Global, your contribution as a Network and Systems Engineer makes an impact. As an organization rooted in serv…

Listing review due 2026-10-08View job

Choctaw Global

WhatJobs

Network and Systems Engineer

Milburn, OK

Salary not specified

Why Join Choctaw Global At Choctaw Global, your contribution as a Network and Systems Engineer makes an impact. As an organization rooted in serv…

Listing review due 2026-10-08View job

Choctaw Global

WhatJobs

Network and Systems Engineer

Hendrix, OK

Salary not specified

Why Join Choctaw Global At Choctaw Global, your contribution as a Network and Systems Engineer makes an impact. As an organization rooted in serv…

Listing review due 2026-10-08View job