About this opportunity
ecsfederal lists this Cloud Security Engineer opportunity in virginia, Minnesota. Review the employer’s description below for duties, qualifications and application requirements.
Job description
Everforth ECS is seeking aCloud Security Engineer to work in ourArlington, VA office/remote .
We’relooking for a security engineer who understands vulnerability management as an end-to-end discipline. Not just scanning, but contextualizing findings, eliminatingfalse positives, and driving remediation outcomes across engineering,developmentand platform teams. You have hands-on experience operating security tooling across AWS and Azure, you can perform architecture reviews and deliver actionable guidance, andyou’recomfortable supporting ATO processes and continuous monitoring under RMF. You work well without heavy direction, you know how to prioritize risk in complex environments, and you can translate technical findings into clear reporting for both technical and executive audiences.You arecomfortablegiving technicalpresentations toleadership,thatresultsinunderstanding and acceptance.You arefamiliar withArtificial IntelligenceGPT prompting.
What You’ll Do
Own vulnerability triage, validation, prioritization, and remediation tracking across cloud, on-prem, and application environments
Conduct authenticated and unauthenticated scans of web applications, APIs, servers, databases, and network devices
Perform risk-based analysis of findings including false positive validation, asset context evaluation, and remediation verification
Partner with platform, cloud, and application teams to drive sustainable remediation outcomes
Implement, operate, and tune CSPM tools, vulnerability scanners, and application security tooling across AWS, Azure, and GCP
Perform security architecture and design reviews covering IAM, encryption, logging, monitoring, and network controls
Support static, dynamic, container, and dependency scanning and help dev teams understand and fix what’s found
Perform secure configuration reviews against DISA STIGs and other security baselines
Automate vulnerability validation, remediation tracking, and control validation using Python, Bash, PowerShell, and Terraform
Manage certificate lifecycle including inventory, renewal tracking, and deployment coordination
Support ATO activities, POA&M management, and RMF Step 6 continuous monitoring
Build and maintain runbooks, technical reports, executive dashboards, and risk summaries
Assist during security audits and incident response investigations involving vulnerable systems
Protypeandprovide training on new tools and solutions.
Salary: $140,000 - $170,000
General Description of Benefits
Must have US citizenship.
Ability to pass a Public Trust investigation.
Bachelor's degree in a related field.
7 years of overall IT experience, with at least 3 years focused specifically on cloud security or vulnerability management
CISSP, CISA, CISM, or relevant cloud provider certifications required
Hands-on scripting experience in Python, Bash, or PowerShell
Familiarity with compliance frameworks including SOC 2, CIS, NIST, or ISO 27001
Understanding of CVEs, CWEs, CVSS scoring, and how to apply them in practice
Experience generating AIGPT prompts the product the expected output
#J-18808-Ljbffr
Worksite address
virginia, MN, 55792, US
Who can apply
Review the original listing for work authorization, qualifications and employer requirements.