Cloud Security Engineer @BizFirst
All Others
Salary unspecified
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted 1wk ago

[Hiring] Cloud Security Engineer @BizFirst

1wk ago - BizFirst is hiring a remote Cloud Security Engineer. πŸ’Έ Salary: unspecified πŸ“Location: USA

Role Description

This is a remote position.

Job Title: Cloud Security Engineer

Level: Senior (7+ years in cybersecurity or cloud engineering, including 3+ years securing AWS environments)

Openings: Multiple

Security Clearance: U.S. citizenship required. Must be able to obtain and maintain a CBP Public Trust background investigation. An existing DHS Public Trust (CBP, ICE, USCIS, CISA, or another DHS component) is preferred; other federal clearances, including Secret or Top Secret, will be reviewed and may require additional processing.

Work Type: Remote: East Coast working hours, with travel approximately once per quarter; candidates in the Washington, DC area preferred

Job Type: Full-time

Start Date: Immediate. Start follows a favorable suitability determination and completion of customer onboarding.

BizFirst is assisting our client with recruiting skilled and experienced Cloud Security Engineers. This position supports a four-year U.S. Customs and Border Protection (CBP) program to move the agency's applications to the cloud; our client is the prime contractor and incumbent. CBP has set a goal of moving all 276 of its applications to the cloud by January 2028 while advancing a zero trust architecture. Cloud Security Engineers secure those environments, build security into delivery pipelines, and keep systems in line with federal controls such as NIST.

What will you do:

  • Secure the AWS environments that host CBP mission applications.
  • Implement and operate cloud security controls.
  • Build security checks into delivery pipelines.
  • Manage vulnerabilities.
  • Support the Authority to Operate (ATO) and continuous monitoring process.
  • Work with platform engineers, developers, and CBP security staff to make security proactive.

Responsibilities:

  • Design and implement security controls for AWS environments, including IAM, network segmentation, encryption and key management (KMS), and logging.
  • Configure and operate AWS security services, including Security Hub, GuardDuty, Config, CloudTrail, Inspector, and WAF.
  • Integrate security into CI/CD pipelines: static and dynamic code analysis, container image scanning, and infrastructure-as-code scanning.
  • Run vulnerability management: scan, prioritize, and track findings to remediation through POA&Ms.
  • Support ATO and continuous monitoring: map controls to NIST SP 800-53 and DHS 4300A, gather evidence, and update system security plans.
  • Harden systems, containers, and Kubernetes clusters to DISA STIGs and CIS Benchmarks.
  • Support zero trust architecture work, including identity-based access, micro-segmentation, and least privilege.
  • Detect and respond to security events using SIEM tools such as Splunk; support incident response and root cause analysis.
  • Automate security checks and remediation with Python, AWS Lambda, or policy as code.
  • Review cloud architectures and changes for security risk and advise engineering teams.

Qualifications

  • U.S. citizenship.
  • Able to obtain and maintain a CBP Public Trust background investigation.
  • At least seven (7) years of experience in cybersecurity, cloud, or systems engineering, including at least three (3) years securing AWS environments.
  • Hands-on experience with AWS IAM, VPC security, KMS, and AWS native security services.
  • Working knowledge of NIST SP 800-53, the Risk Management Framework (RMF), and federal ATO processes.
  • Experience with vulnerability scanning tools (Tenable/Nessus, Qualys, or Prisma Cloud) and SIEM platforms such as Splunk.
  • Experience securing containers and Kubernetes.
  • Scripting in Python or Bash; infrastructure as code with Terraform.
  • Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or a related field.
  • Able to work remotely on East Coast hours and travel approximately once per quarter.

Desired Skills

  • CISSP, CCSP, or AWS Certified Security Specialty.
  • Experience with DHS 4300A, Continuous Diagnostics and Mitigation (CDM), and FedRAMP.
  • Experience with AWS GovCloud (US).
  • Experience supporting DHS or CBP systems.
  • A current DHS Public Trust (CBP, ICE, USCIS, CISA, or another DHS component).
Before You Apply
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Cloud Security Engineer @BizFirst
All Others
Salary unspecified
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted 1wk ago
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
Γ—
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews

⚑ 127,023+ remote jobs, refreshed hourly

πŸ”” Real-time alerts: Apply first, direct to employer

πŸ›‘οΈ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later