Location: Pittsburgh PA / Lake Mary FL / New York NY
Experience: 12 years
Work Type: Hybrid
Employment Type: Contract (C2C)
Duration: 12 Months
Visa Requirement: No OPT / CPT
Note: Must have skill Exp with FedRAMP & Azure/AWS
About the Role:
We are seeking a Cloud Security Engineer who drives the technical design and full-lifecycle integration of comprehensive security control frameworks. By leveraging a deep architectural understanding of foundational risk models (e.g. NIST SP 800-53 CSF ISO 27001) this architect translates rigorous compliance mandates into resilient scalable cloud infrastructure. The holistic approach to boundary definition automated enforcement and zero-trust principles ensures that security is engineered organically into the environment continuously satisfying complex third-party assessment criteria.
Key Responsibilities:
Implement and enforce FedRAMP controls in cloud platforms
Review existing security frameworks and close gaps between standards and implementation
Deploy and validate security policies and rule sets
Work with data protection and cryptography teams to enforce cloud security controls
Ensure security controls are effective auditable and operational
Identify issues like overprovisioning and underutilization from a security and governance perspective
Required Skills:
Full-Lifecycle Engineering: Demonstrated experience in the end-to-end integration of rigorous control frameworks (e.g. NIST 800-53 ISO 27001 SOC 2 CMMC)-from initial gap analysis and architectural design through deployment automated enforcement and continuous monitoring.
Control Translation: Proven ability to dissect complex regulatory catalogs and translate them into actionable technical engineering requirements for AWS infrastructure and DevSecOps pipelines.
Boundary & Scoping Expertise: Expertise in defining complex authorization boundaries architecting secure enclaves and implementing micro segmentation to isolate regulated data and reduce the overall audit footprint.
Compensating Controls: Adept at designing and documenting robust compensating controls and operational workarounds when native technical enforcement of a framework requirement is unfeasible.
Ability to work with multiple teams and drive controls into production
Job Title: Cloud Security EngineerLocation: Pittsburgh PA / Lake Mary FL / New York NYExperience: 12 yearsWork Type: HybridEmployment Type: Contract (C2C)Duration: 12 MonthsVisa Requirement: No OPT / CPT Note: Must have skill Exp with FedRAMP & Azure/AWS About the Role: We are seeking a Cloud Secu...
Job Title: Cloud Security Engineer
Location: Pittsburgh PA / Lake Mary FL / New York NY
Experience: 12 years
Work Type: Hybrid
Employment Type: Contract (C2C)
Duration: 12 Months
Visa Requirement: No OPT / CPT
Note: Must have skill Exp with FedRAMP & Azure/AWS
About the Role:
We are seeking a Cloud Security Engineer who drives the technical design and full-lifecycle integration of comprehensive security control frameworks. By leveraging a deep architectural understanding of foundational risk models (e.g. NIST SP 800-53 CSF ISO 27001) this architect translates rigorous compliance mandates into resilient scalable cloud infrastructure. The holistic approach to boundary definition automated enforcement and zero-trust principles ensures that security is engineered organically into the environment continuously satisfying complex third-party assessment criteria.
Key Responsibilities:
Implement and enforce FedRAMP controls in cloud platforms
Review existing security frameworks and close gaps between standards and implementation
Deploy and validate security policies and rule sets
Work with data protection and cryptography teams to enforce cloud security controls
Ensure security controls are effective auditable and operational
Identify issues like overprovisioning and underutilization from a security and governance perspective
Required Skills:
Full-Lifecycle Engineering: Demonstrated experience in the end-to-end integration of rigorous control frameworks (e.g. NIST 800-53 ISO 27001 SOC 2 CMMC)-from initial gap analysis and architectural design through deployment automated enforcement and continuous monitoring.
Control Translation: Proven ability to dissect complex regulatory catalogs and translate them into actionable technical engineering requirements for AWS infrastructure and DevSecOps pipelines.
Boundary & Scoping Expertise: Expertise in defining complex authorization boundaries architecting secure enclaves and implementing micro segmentation to isolate regulated data and reduce the overall audit footprint.
Compensating Controls: Adept at designing and documenting robust compensating controls and operational workarounds when native technical enforcement of a framework requirement is unfeasible.
Ability to work with multiple teams and drive controls into production