Job Requirements
Reston, VA Joint Base Anacostia Bolling, DC
Top Secret/SCI Polygraph not specified
Mid Level Career (5+ yrs experience)
Salary not specified
Join Premium to unlock estimated salaries
Job Description
Position Summary
We are seeking an experienced AWS Cloud Security / IAM Engineer to design, implement, automate, and secure cloud infrastructure within a Federal AWS environment.
This is not a traditional enterprise IAM role centered on administering large Okta, SailPoint, Ping, or CyberArk environments. The position is primarily focused on securing the AWS operating platform, with AWS Identity and Access Management (IAM) serving as a critical component of the overall cloud security architecture.
The ideal candidate is a hands-on AWS engineer who has experience building and securing AWS environments, implementing least-privilege access, automating infrastructure and security controls, and integrating security into DevSecOps and CI/CD workflows.
Key Responsibilities
Design, implement, and maintain secure AWS cloud infrastructure supporting Federal workloads.
Design and manage AWS IAM roles, policies, permissions, and access controls using least-privilege principles.
Implement secure authentication and authorization patterns for users, workloads, applications, and AWS services.
Support multi-account AWS environments, including cross-account access and centralized security controls.
Implement and maintain AWS Organizations, organizational units (OUs), and Service Control Policies (SCPs) where applicable.
Design IAM permissions boundaries, role-based access controls, and workload/service roles.
Review IAM policies and remediate excessive, unused, or improperly configured permissions.
Automate cloud infrastructure and security configuration using Terraform, CloudFormation, Ansible, or similar Infrastructure as Code technologies.
Integrate AWS infrastructure and security controls into CI/CD and DevSecOps pipelines.
Develop automation using Python, Bash, PowerShell, AWS CLI, or Boto3.
Configure, monitor, and remediate findings from AWS-native security services such as Security Hub, GuardDuty, CloudTrail, AWS Config, Inspector, IAM Access Analyzer, KMS, and Secrets Manager.
Secure AWS networking and infrastructure components including VPCs, security groups, EC2, S3, Lambda, and related AWS services.
Support containerized workloads and Amazon EKS/Kubernetes environments where applicable.
Implement security controls consistent with Zero Trust and least-privilege principles.
Support cloud security hardening, vulnerability remediation, logging, monitoring, and continuous compliance.
Work closely with cloud engineering, DevSecOps, cybersecurity, and application teams to integrate security throughout the cloud environment.
Support Federal security requirements and frameworks such as NIST 800-53, RMF, FedRAMP, DISA STIGs, and FISMA, as applicable.
AWS specifically recommends federation/temporary credentials, IAM roles for workloads, MFA, least privilege, IAM Access Analyzer, and multi-account permissions guardrails, making these good IAM competencies to emphasize.
Required Qualifications
8+ years of experience in cloud engineering, cybersecurity engineering, DevSecOps, systems engineering, or related infrastructure roles.
Strong hands-on experience with Amazon Web Services (AWS).
Demonstrated experience securing production AWS environments.
Hands-on experience with AWS IAM, including:
IAM roles
IAM policies
Least-privilege access
Cross-account access
Role-based access
Workload/service identities
Experience with AWS infrastructure services such as EC2, VPC, S3, Lambda, Security Groups, Route 53, or similar services.
Experience with Infrastructure as Code using Terraform and/or CloudFormation.
Experience with CI/CD pipelines and DevSecOps practices.
Experience automating infrastructure or security tasks using Python, Bash, PowerShell, AWS CLI, or similar scripting technologies.
Understanding of cloud security concepts including Zero Trust, least privilege, encryption, logging, monitoring, and vulnerability management.
Experience supporting secure or regulated environments.
Preferred Qualifications
AWS GovCloud experience.
AWS Organizations and Service Control Policies (SCPs).
IAM Identity Center.
IAM Access Analyzer.
AWS Security Hub.
Amazon GuardDuty.
AWS Config.
AWS CloudTrail.
Amazon Inspector.
AWS KMS.
AWS Secrets Manager.
Amazon EKS/Kubernetes and Docker.
GitLab CI/CD, Jenkins, or GitHub Actions.
Ansible.
Experience with NIST 800-53, RMF, FedRAMP, DISA STIGs, or similar Federal security frameworks.
AWS certifications such as:
AWS Certified Security – Specialty
AWS Certified Solutions Architect
AWS Certified DevOps Engineer
Security certifications such as CISSP, Security+, CASP+/SecurityX, or equivalent.
We are seeking an experienced AWS Cloud Security / IAM Engineer to design, implement, automate, and secure cloud infrastructure within a Federal AWS environment.
This is not a traditional enterprise IAM role centered on administering large Okta, SailPoint, Ping, or CyberArk environments. The position is primarily focused on securing the AWS operating platform, with AWS Identity and Access Management (IAM) serving as a critical component of the overall cloud security architecture.
The ideal candidate is a hands-on AWS engineer who has experience building and securing AWS environments, implementing least-privilege access, automating infrastructure and security controls, and integrating security into DevSecOps and CI/CD workflows.
Key Responsibilities
Design, implement, and maintain secure AWS cloud infrastructure supporting Federal workloads.
Design and manage AWS IAM roles, policies, permissions, and access controls using least-privilege principles.
Implement secure authentication and authorization patterns for users, workloads, applications, and AWS services.
Support multi-account AWS environments, including cross-account access and centralized security controls.
Implement and maintain AWS Organizations, organizational units (OUs), and Service Control Policies (SCPs) where applicable.
Design IAM permissions boundaries, role-based access controls, and workload/service roles.
Review IAM policies and remediate excessive, unused, or improperly configured permissions.
Automate cloud infrastructure and security configuration using Terraform, CloudFormation, Ansible, or similar Infrastructure as Code technologies.
Integrate AWS infrastructure and security controls into CI/CD and DevSecOps pipelines.
Develop automation using Python, Bash, PowerShell, AWS CLI, or Boto3.
Configure, monitor, and remediate findings from AWS-native security services such as Security Hub, GuardDuty, CloudTrail, AWS Config, Inspector, IAM Access Analyzer, KMS, and Secrets Manager.
Secure AWS networking and infrastructure components including VPCs, security groups, EC2, S3, Lambda, and related AWS services.
Support containerized workloads and Amazon EKS/Kubernetes environments where applicable.
Implement security controls consistent with Zero Trust and least-privilege principles.
Support cloud security hardening, vulnerability remediation, logging, monitoring, and continuous compliance.
Work closely with cloud engineering, DevSecOps, cybersecurity, and application teams to integrate security throughout the cloud environment.
Support Federal security requirements and frameworks such as NIST 800-53, RMF, FedRAMP, DISA STIGs, and FISMA, as applicable.
AWS specifically recommends federation/temporary credentials, IAM roles for workloads, MFA, least privilege, IAM Access Analyzer, and multi-account permissions guardrails, making these good IAM competencies to emphasize.
Required Qualifications
8+ years of experience in cloud engineering, cybersecurity engineering, DevSecOps, systems engineering, or related infrastructure roles.
Strong hands-on experience with Amazon Web Services (AWS).
Demonstrated experience securing production AWS environments.
Hands-on experience with AWS IAM, including:
IAM roles
IAM policies
Least-privilege access
Cross-account access
Role-based access
Workload/service identities
Experience with AWS infrastructure services such as EC2, VPC, S3, Lambda, Security Groups, Route 53, or similar services.
Experience with Infrastructure as Code using Terraform and/or CloudFormation.
Experience with CI/CD pipelines and DevSecOps practices.
Experience automating infrastructure or security tasks using Python, Bash, PowerShell, AWS CLI, or similar scripting technologies.
Understanding of cloud security concepts including Zero Trust, least privilege, encryption, logging, monitoring, and vulnerability management.
Experience supporting secure or regulated environments.
Preferred Qualifications
AWS GovCloud experience.
AWS Organizations and Service Control Policies (SCPs).
IAM Identity Center.
IAM Access Analyzer.
AWS Security Hub.
Amazon GuardDuty.
AWS Config.
AWS CloudTrail.
Amazon Inspector.
AWS KMS.
AWS Secrets Manager.
Amazon EKS/Kubernetes and Docker.
GitLab CI/CD, Jenkins, or GitHub Actions.
Ansible.
Experience with NIST 800-53, RMF, FedRAMP, DISA STIGs, or similar Federal security frameworks.
AWS certifications such as:
AWS Certified Security – Specialty
AWS Certified Solutions Architect
AWS Certified DevOps Engineer
Security certifications such as CISSP, Security+, CASP+/SecurityX, or equivalent.
group id: 90838916