FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in designing and implementing security architecture for AWS workloads, with a strong focus on FedRAMP compliance and Infrastructure as Code security controls. Proficient in managing AWS security services, vulnerability management, and incident response within federal environments.
Highest-signal resume keywords
AWS Security ServicesFedRAMP ComplianceInfrastructure as CodeVulnerability ManagementIncident Response
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
AWS IAMAWS GuardDutyAWS Security HubAWS ConfigAWS CloudTrailAWS KMSAWS WAFAWS MacieAWS InspectorTerraform
Tools & Technologies
SIEMSplunkAWS CloudWatchOpenSearchPythonBash
Certifications & Qualifications
AWS Certified Security – SpecialtyAWS Certified Solutions Architect – ProfessionalCISSPCISMSecurity+
Industry Keywords
FedRAMP ModerateNIST SP 800-53Zero Trust ArchitectureVPC DesignCompliance Boundaries
Tech Stack
Tools & technologiesAWSAzureCloudCyber SecurityPythonSplunkTerraform.NET
About the role
Key responsibilities & impact- Design and implement security architecture for AWS workloads aligned with FedRAMP Moderate baseline controls
- Build and maintain security guardrails using AWS-native services
- Implement and manage Infrastructure as Code security controls with policy as code
- Support System Security Plans, ATO activities, and POA&M remediation
- Perform continuous monitoring, vulnerability scanning, patch management tracking, and monthly/annual assessment support
- Configure and maintain centralized logging, SIEM integration, and audit trail retention per FedRAMP/NIST requirements
- Implement least-privilege IAM policies, service control policies, and cross-account access controls
- Manage encryption at rest and in transit per FIPS 140-2/140-3 requirements where applicable
- Respond to security incidents, perform root cause analysis, and support cloud-specific incident response playbooks
- Collaborate with DevOps/Platform teams to embed security into CI/CD pipelines
- Maintain documentation for control implementation statements, architecture diagrams, and audit evidence
- Support boundary definition and system categorization activities as required
Requirements
What you’ll need- US citizenship required
- Ability to obtain and maintain a Top-Secret eligible clearance
- Minimum 8 years work experience with BS/BA in computer science, or 10 years work experience with an AA/AS degree in Information Systems, or a related field (or equivalent experience)
- 5+ years of hands-on AWS engineering experience, with 3+ years specifically in cloud security roles
- Demonstrated experience working within a FedRAMP Moderate or FedRAMP High, DoD IL4/IL5, or equivalent federal compliance environment
- Experience supporting or maintaining an SSP and RMF processes
- Experience with AWS GovCloud (US), AWS Commercial, or equivalent federal AWS environments
- Strong hands-on expertise with AWS security services: IAM, GuardDuty, Security Hub, AWS Config, CloudTrail, KMS, WAF, Macie, Inspector, and Systems Manager
- Solid understanding of NIST SP 800-53 Rev 5 control families (AC, AU, CM, IA, SC, SI, etc.) and the ability to map implementations to specific controls
- 3+ years of experience with Infrastructure as Code (Terraform and/or CloudFormation), including security scanning and policy-as-code tools
- Networking security fundamentals: VPC design, security groups, NACLs, PrivateLink, Transit Gateway, and network segmentation for compliance boundaries
- Experience with vulnerability management tools (AWS Inspector or similar) and remediation tracking
- Experience implementing Zero Trust Architecture (ZTA) in AWS
- Familiarity with SIEM/log aggregation tools (Splunk, AWS CloudWatch, OpenSearch, or similar) for security event monitoring
- Scripting ability in Python or Bash for automating compliance checks and remediation
- Understanding of encryption standards relevant to federal systems (FIPS 140-2/140-3, TLS 1.2+)
- One of the following certifications: AWS Certified Security – Specialty, AWS Certified Solutions Architect – Professional (with a security focus), CISSP, CISM, or Security+ (with strong AWS hands-on experience)
- Preferred: Direct experience supporting a Peraton program or similar federal integrator
- Preferred: Familiarity with server and systems hardening software
- Preferred: Experience with container security (ECS/EKS), including image scanning (ECR scanning) and runtime protection
- Preferred: Experience with AWS Control Tower and multi-account landing zone security governance
- Preferred: Experience automating compliance evidence collection for continuous ATO (cATO)
- Preferred: Prior experience with change management processes in a regulated/audited environment
- Preferred: Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related field
- Preferred: Active security clearance
- Preferred: Experience with AWS AI services (Amazon Bedrock)
- Preferred: Experience with hybrid/multi-cloud architecture, including Azure
- Preferred: Experience with Microsoft .NET
- Preferred: Experience supporting ATO/continuous monitoring processes
- Preferred: Familiarity with DevSecOps pipelines
- Preferred: Familiarity with AI security and governance frameworks, national security/defense/critical infrastructure missions, and supporting federal agencies or large GovCon programs
Benefits
Comp & perks- Potential eligibility for overtime
- Potential eligibility for shift differential
- Potential eligibility for a discretionary bonus
