Sr Cloud Security Engineer
Aws Cloud
Aws Cloud Security
Cloud Network Security
Cloud Platforms
Cloud Security
Cloud Security Architecture
Cybersecurity Tools
DevSecOps
Engineer
Firewall Security
Identity and Access Management
Information Security
InfoSec
Network Security Engineering
Security
Security Automation
Security Compliance
Security Configuration Management
Security Engineer
Security Operations
Web Application Firewall
Job Description
GDIT is seeking a Senior Cloud Security Engineer to design, implement, operate, and continuously improve security infrastructure across on-premises data centers and AWS environments. The position is hands-on, spanning security architecture, implementation, security automation, networking and firewall capabilities, and incident response support.
Responsibilities
- Design and implement security controls for AWS multi-account and hybrid-cloud environments.
- Deploy and manage AWS security services, including Network Firewall, WAF, Shield, Security Groups and NACLs, GuardDuty, Security Hub, CloudTrail, and AWS Config.
- Own identity and encryption controls using IAM/Identity Center and KMS, while managing core network components such as VPC and Transit Gateway.
- Design secure connectivity, segmentation, and security boundaries between AWS and on-premises environments.
- Design, deploy, manage, and optimize Palo Alto Networks next-generation firewalls, including security policies, NAT, routing, VPN, application controls, threat prevention, and URL filtering.
- Manage firewall high availability, upgrades, lifecycle, capacity, and ongoing policy optimization.
- Build secure, resilient architectures across AWS and on-premises infrastructure using defense-in-depth and Zero Trust principles.
- Modernize environments to use Infrastructure as Code, including Terraform.
- Automate security operations, compliance reporting, configuration management, and policy enforcement through APIs, scripting, DevSecOps tooling, and AI-assisted engineering tools.
- Support security controls and evidence mapping aligned with NIST 800-53/800-171, FedRAMP, and FISMA.
- Evaluate existing security architectures and recommend improvements in security, resiliency, scalability, performance, and operational efficiency.
- Troubleshoot complex cloud, network, firewall, and application connectivity issues.
- Support security incidents, production outages, and root-cause analysis.
- Create and maintain monitoring, logging, alerting, dashboards, runbooks, and engineering standards.
- Perform performance tuning, capacity planning, and security infrastructure lifecycle management.
- Participate in on-call or escalation support as required.
Requirements
- Bachelor's degree and 5+ years of hands-on cloud security engineering experience, or 8+ years of cloud security engineering experience in lieu of degree.
- Demonstrated experience designing, deploying, managing, and troubleshooting AWS security services and Palo Alto Networks next-generation firewalls.
- Experience securing hybrid on-premises and AWS environments.
- Experience with Infrastructure as Code, scripting, and security automation.
- Strong understanding of networking and security fundamentals, including TCP/IP, DNS, HTTP/HTTPS, network segmentation, VPNs, TLS/PKI, encryption, IAM, Zero Trust, and threat detection/prevention.
- Experience troubleshooting complex security and network issues.
- Ability to obtain and maintain a Public Trust.
Core Technology Areas
- Amazon Web Services (AWS), including AWS Network Firewall, AWS WAF, AWS Shield, GuardDuty, Security Hub, CloudTrail, and AWS Config
- AWS identity and encryption controls: IAM/Identity Center, KMS
- AWS networking: VPC, Transit Gateway, Security Groups and NACLs
- Palo Alto Networks and Palo Alto Networks next-generation firewalls
- Infrastructure as Code: Terraform
- Automation and tooling: APIs, scripting, DevSecOps tooling, AI-assisted engineering tools
- Framework alignment: NIST 800-53, NIST 800-171, FedRAMP, FISMA
- Fundamentals: TCP/IP, DNS, HTTP/HTTPS, VPNs, TLS/PKI, IAM, Zero Trust
Location and Work Model
Rockville, Maryland (Hybrid Workplace). The role is mostly remote, with a requirement to be within commuting distance of Rockville for occasional onsite needs.
Clearance and Authorization
- Clearance level: None
- Public Trust: NACI (T1)
Additional Information
- Requisition type: Regular
- Years of experience: 5+ years of related experience (may vary based on technical training, certification(s), or degree)
- Travel required: Less than 10%
- Salary range: USD 124,093 - 149,500 per year
Your Impact
Own your opportunity to be on the frontlines of health innovation.