Senior Security & Infrastructure Engineer
New
J
JobgetherCloud Security, GovTech
Based in the United StatesFull-TimeSenior
Salary195,000 - 220,000 USD per year
Apply NowOpens the employer's application page
Job Details
- Required Skills
- AWSCI/CDTerraform
Requirements
- Proven experience completing a FedRAMP authorization, whether through an Agency or JAB pathway, at Moderate level or above.
- Deep hands-on experience with AWS.
- Strong infrastructure-as-code expertise, particularly with Terraform or comparable tooling.
- Ability to operate comfortably across both security engineering and compliance, including writing control narratives, developing evidence, and implementing the underlying infrastructure.
- Experience with security and compliance frameworks such as SOC 2, StateRAMP, or TX-RAMP.
- Familiarity with continuous monitoring platforms and security observability practices.
- Experience with threat modeling, security architecture, infrastructure hardening, logging, detection, secrets management, network segmentation, and incident response.
- Strong understanding of secure CI/CD practices and the ability to integrate security controls into developer workflows.
- Excellent communication and collaboration skills.
- Strong ownership mindset and willingness to work hands-on across both strategic initiatives and detailed implementation work.
- Comfortable working in an early-stage, evolving environment.
Responsibilities
- Own the security and compliance posture of AWS infrastructure, including the authorization boundary, control implementation, KSI evidence, continuous monitoring, and supporting automation.
- Drive FedRAMP authorization activities in partnership with the compliance lead, including machine-readable evidence management, control implementation, third-party assessment coordination, and preparation for authorization and marketplace listing.
- Harden and modernize production infrastructure through infrastructure-as-code, network segmentation, secrets management, logging, detection, monitoring, and incident response improvements.
- Build security and compliance controls directly into CI/CD pipelines and developer workflows, minimizing manual review requirements and preventing compliance processes from becoming delivery bottlenecks.
- Establish and maintain security guardrails, infrastructure standards, and automated controls that support both developer productivity and regulatory requirements.
- Partner closely with engineering teams to integrate security considerations into architecture, system design, development, and deployment decisions.
- Support continuous monitoring, threat modeling, incident response, and ongoing improvements to the organization’s security posture.
- Translate compliance requirements into practical engineering implementations, ensuring that technical controls and their corresponding documentation remain aligned.
- Collaborate with internal and external compliance, infrastructure, and security partners throughout assessments and authorization activities.
- Identify opportunities to automate repetitive security and compliance processes and improve the reliability, scalability, and efficiency of security operations.
View Full Description & ApplyYou'll be redirected to the employer's site