Job Title: Cloud Security Engineer
Location: Pittsburgh PA / Lake Mary FL / New York NY
Experience: 12 years
Work Type: Hybrid
Employment Type: Contract (C2C)
Duration: 12 Months
Visa Requirement: No OPT / CPT
Note: Must have skill Exp with FedRAMP & Azure/AWS
About the Role:
We are seeking a Cloud Security Engineer who drives the technical design and full-lifecycle integration of comprehensive security control frameworks. By leveraging a deep architectural understanding of foundational risk models (e.g. NIST SP 800-53 CSF ISO 27001) this architect translates rigorous compliance mandates into resilient scalable cloud infrastructure. The holistic approach to boundary definition automated enforcement and zero-trust principles ensures that security is engineered organically into the environment continuously satisfying complex third-party assessment criteria.
Key Responsibilities:
- Implement and enforce FedRAMP controls in cloud platforms
- Review existing security frameworks and close gaps between standards and implementation
- Deploy and validate security policies and rule sets
- Work with data protection and cryptography teams to enforce cloud security controls
- Ensure security controls are effective auditable and operational
- Identify issues like overprovisioning and underutilization from a security and governance perspective
Required Skills:
- Full-Lifecycle Engineering: Demonstrated experience in the end-to-end integration of rigorous control frameworks (e.g. NIST 800-53 ISO 27001 SOC 2 CMMC)-from initial gap analysis and architectural design through deployment automated enforcement and continuous monitoring.
- Control Translation: Proven ability to dissect complex regulatory catalogs and translate them into actionable technical engineering requirements for AWS infrastructure and DevSecOps pipelines.
- Boundary & Scoping Expertise: Expertise in defining complex authorization boundaries architecting secure enclaves and implementing micro segmentation to isolate regulated data and reduce the overall audit footprint.
- Compensating Controls: Adept at designing and documenting robust compensating controls and operational workarounds when native technical enforcement of a framework requirement is unfeasible.
- Ability to work with multiple teams and drive controls into production
Job Title: Cloud Security EngineerLocation: Pittsburgh PA / Lake Mary FL / New York NYExperience: 12 yearsWork Type: HybridEmployment Type: Contract (C2C)Duration: 12 MonthsVisa Requirement: No OPT / CPT Note: Must have skill Exp with FedRAMP & Azure/AWS About the Role: We are seeking a Cloud Secu...
Job Title: Cloud Security Engineer
Location: Pittsburgh PA / Lake Mary FL / New York NY
Experience: 12 years
Work Type: Hybrid
Employment Type: Contract (C2C)
Duration: 12 Months
Visa Requirement: No OPT / CPT
Note: Must have skill Exp with FedRAMP & Azure/AWS
About the Role:
We are seeking a Cloud Security Engineer who drives the technical design and full-lifecycle integration of comprehensive security control frameworks. By leveraging a deep architectural understanding of foundational risk models (e.g. NIST SP 800-53 CSF ISO 27001) this architect translates rigorous compliance mandates into resilient scalable cloud infrastructure. The holistic approach to boundary definition automated enforcement and zero-trust principles ensures that security is engineered organically into the environment continuously satisfying complex third-party assessment criteria.
Key Responsibilities:
- Implement and enforce FedRAMP controls in cloud platforms
- Review existing security frameworks and close gaps between standards and implementation
- Deploy and validate security policies and rule sets
- Work with data protection and cryptography teams to enforce cloud security controls
- Ensure security controls are effective auditable and operational
- Identify issues like overprovisioning and underutilization from a security and governance perspective
Required Skills:
- Full-Lifecycle Engineering: Demonstrated experience in the end-to-end integration of rigorous control frameworks (e.g. NIST 800-53 ISO 27001 SOC 2 CMMC)-from initial gap analysis and architectural design through deployment automated enforcement and continuous monitoring.
- Control Translation: Proven ability to dissect complex regulatory catalogs and translate them into actionable technical engineering requirements for AWS infrastructure and DevSecOps pipelines.
- Boundary & Scoping Expertise: Expertise in defining complex authorization boundaries architecting secure enclaves and implementing micro segmentation to isolate regulated data and reduce the overall audit footprint.
- Compensating Controls: Adept at designing and documenting robust compensating controls and operational workarounds when native technical enforcement of a framework requirement is unfeasible.
- Ability to work with multiple teams and drive controls into production
View more
View less