Senior Security & Infrastructure Engineer

New
J
JobgetherCloud Security, GovTech
Based in the United StatesFull-TimeSenior
Salary195,000 - 220,000 USD per year
Apply NowOpens the employer's application page

Job Details

Required Skills
AWSCI/CDTerraform

Requirements

  • Proven experience completing a FedRAMP authorization, whether through an Agency or JAB pathway, at Moderate level or above.
  • Deep hands-on experience with AWS.
  • Strong infrastructure-as-code expertise, particularly with Terraform or comparable tooling.
  • Ability to operate comfortably across both security engineering and compliance, including writing control narratives, developing evidence, and implementing the underlying infrastructure.
  • Experience with security and compliance frameworks such as SOC 2, StateRAMP, or TX-RAMP.
  • Familiarity with continuous monitoring platforms and security observability practices.
  • Experience with threat modeling, security architecture, infrastructure hardening, logging, detection, secrets management, network segmentation, and incident response.
  • Strong understanding of secure CI/CD practices and the ability to integrate security controls into developer workflows.
  • Excellent communication and collaboration skills.
  • Strong ownership mindset and willingness to work hands-on across both strategic initiatives and detailed implementation work.
  • Comfortable working in an early-stage, evolving environment.

Responsibilities

  • Own the security and compliance posture of AWS infrastructure, including the authorization boundary, control implementation, KSI evidence, continuous monitoring, and supporting automation.
  • Drive FedRAMP authorization activities in partnership with the compliance lead, including machine-readable evidence management, control implementation, third-party assessment coordination, and preparation for authorization and marketplace listing.
  • Harden and modernize production infrastructure through infrastructure-as-code, network segmentation, secrets management, logging, detection, monitoring, and incident response improvements.
  • Build security and compliance controls directly into CI/CD pipelines and developer workflows, minimizing manual review requirements and preventing compliance processes from becoming delivery bottlenecks.
  • Establish and maintain security guardrails, infrastructure standards, and automated controls that support both developer productivity and regulatory requirements.
  • Partner closely with engineering teams to integrate security considerations into architecture, system design, development, and deployment decisions.
  • Support continuous monitoring, threat modeling, incident response, and ongoing improvements to the organization’s security posture.
  • Translate compliance requirements into practical engineering implementations, ensuring that technical controls and their corresponding documentation remain aligned.
  • Collaborate with internal and external compliance, infrastructure, and security partners throughout assessments and authorization activities.
  • Identify opportunities to automate repetitive security and compliance processes and improve the reliability, scalability, and efficiency of security operations.
View Full Description & ApplyYou'll be redirected to the employer's site
195,000 - 220,000 USD per year
Apply Now