About this opportunity
The Phoenix Group lists this Security Engineer opportunity in arlington, Virginia. Review the employer’s description below for duties, qualifications and application requirements.
Job description
Will assist in implementing and supporting cloud security protocols, infrastructure automation, and compliance programs across multiple cloud platforms. This position’s scope includes managing identity access, infrastructure as code, vulnerability management, monitoring, and incident response to ensure operational excellence and regulatory compliance.
Key Responsibilities
Monitor and verify the operational status of Zero Trust Network Access tools (e.g., Zscaler ZPA / Prowler).
Support secrets management workflows in HashiCorp Vault, including credential generation, secret updates, and automated rotation processes.
Review and confirm IAM policies, roles, and permissions align with least privilege principles under senior engineer oversight.
Execute, test, and troubleshoot Infrastructure as Code (IaC) modules using Terraform across cloud platforms (AWS, Azure, GCP).
Monitor and troubleshoot build and deployment pipelines in systems like GitHub Actions, GitLab CI, or Azure Pipelines.
Assist with container image security, building, and deployment for Kubernetes environments such as EKS, AKS, or GKE.
Support collection of audit evidence for FedRAMP Continuous Monitoring cycles, focusing on controls such as CM-2, CM-6, AU-2, and SC-12.
Maintain and optimize dashboards and metrics in Grafana and CloudWatch, ensuring alert configurations are accurate.
Perform low-severity system health checks and manage alert triaging to prevent alert fatigue
Support open telemetry operations for real-time application and system monitoring. Core
Qualifications & Requirements
1+ years of experience in DevOps, SRE or Security Engineering capacity
Proficiency in Linux command-line environment (Bash), managing system logs, permissions, and basic troubleshooting.
Foundational understanding of networking concepts (DNS, TCP/IP, HTTP/HTTPS, SSH, subnets, firewalls).
Basic exposure to cloud platforms (AWS preferred) and version control systems (Git, GitHub, GitLab).
Familiarity with scripting languages such as Python or Bash for automation.
Strong security awareness including principles like least privilege, multi-factor authentication, IAM, and encryption fundamentals.
Nice-to-Have Qualifications
Experience with Infrastructure as Code tools (Terraform, CloudFormation).
Familiarity with container technologies (Docker) and CI/CD pipelines (GitHub Actions, GitLab CI).
Knowledge of ticketing and monitoring tools (Jira, ServiceNow, CloudWatch, Grafana).
Awareness of federal security standards (FedRAMP, NIST 800-53, SOC 2).
#J-18808-Ljbffr
Worksite address
arlington, VA, 22201, US
Who can apply
Review the original listing for work authorization, qualifications and employer requirements.