Cloud Infrastructure Security Engineer
Playa Vista, CAAll locationsPlaya Vista, CALos Angeles, California, United States Hybrid
$120,000–$170,000 a yearJobFig found this opening at its original source and checks that it remains available.
About the role
We are seeking a Cloud Infrastructure Security Engineer to design, implement, maintain, and optimize secure cloud environments supporting U.S. government, DoD, and intelligence community missions. This role plays a critical part in protecting classified and sensitive data in AWS, Azure, and hybrid/multi-cloud infrastructures while ensuring full compliance with federal standards such as NIST 800-53, FedRAMP, RMF, and DoD Impact Levels (IL-4/IL-5). The right candidate will bring hands-on experience securing cloud platforms in regulated environments. This role will help the organization meet industry standards such as SOC2, ISO 27001, PCI-DSS, GDPR/CCPA, or other relevant compliance frameworks.
What you'll bring
- Must be a U.S. citizen.
- Bachelor’s degree in Cybersecurity, Information Assurance, Computer Science, or a related field (or 5+ years equivalent professional experience in cloud security engineering)
- 5–9+ years in cloud security engineering, with hands-on work in AWS GovCloud, Azure, Google GCP, or multi-cloud environments.
- Strong analytical, problem-solving, communication, and collaboration skills
- ability to work in fast-paced, mission-critical environments.
- Deep knowledge of cloud platforms (AWS GovCloud, Azure Government, etc.), IAM/RBAC, encryption, network security, and cloud-native security services.
- Familiarity with SIEM, vulnerability scanners, threat intelligence, and automation tools (e.g., Terraform, Python scripting).
- Experience with compliance frameworks (NIST, FedRAMP, RMF) and tools like Azure Sentinel, NESSUS, BURP SUITE, Microsoft Defender, or AWS equivalents.
- Deep understanding of network security, encryption, logging/monitoring, and container/Kubernetes security.
- Experience with infrastructure-as-code, scripting (Python, PowerShell, etc.), and security automation tools.
- CISSP, AWS Certified Security-Specialty, AWS Certified Solutions Architect (Associate or Professional), Microsoft Certified: Security, Compliance & Identity, Security+, CEH, or CSSP related (e.g., CySA+, GCIH).