×
Register Here to Apply for Jobs or Post Jobs. X

Sr AWS Cloud Security Engineer

Job in Fort Belvoir, Fairfax County, Virginia, 22060, USA
Listing for: Defense Engineering Inc.
Full Time position
Listed on 2026-09-21
Job specializations:
  • IT/Tech
    AWS, Cybersecurity, Cloud Computing: Infrastructure & Operations, Systems Engineer
Salary/Wage Range or Industry Benchmark: 180000 - 240000 USD Yearly USD 180000.00 240000.00 YEAR
Job Description & How to Apply Below
Position: 000 – Sr AWS Cloud Security Engineer

We are seeking a highly skilled Lead AWS Cloud Security Engineer with a deep background in AWS Gov Cloud (US) regions and U.S. Department of Defense (DoD) compliance frameworks. In this role, you will be responsible for designing, building, and managing secure, resilient, and fully compliant AWS Landing Zones that align with DISA’s Secure Cloud Computing Architecture (SCCA) guidelines.

The ideal candidate will have extensive hands‑on experience deploying the Virtual Data Center Security Stack (VDSS) and Virtual Data Center Managed Services (VDMS). You will possess advanced expertise in multi‑account governance, including the authoring, testing, and continuous enforcement of restrictive Service Control Policies (SCPs). This position is crucial to enabling our mission partners to deploy critical DoD Impact Level 4 (IL4) and Impact Level 5 (IL5) workloads safely into the cloud.

Key Responsibilities 1. SCCA Landing Zone Architecture & Engineering
  • VDSS Implementation: Design, deploy, and maintain the Virtual Data Center Security Stack (VDSS) to protect mission applications. Implement secure network boundary controls, application‑aware firewalls, intrusion detection/prevention systems (IDS/IPS), and perimeter defenses.
  • VDMS Management: Standardize and manage host security and shared management services under the Virtual Data Center Managed Services (VDMS) framework, including directory services, vulnerability scanning, host‑based security, patching, and configuration governance.
  • Landing Zone Automation: Utilize the AWS Landing Zone Accelerator (LZA) or custom Control Tower implementations to automate the deployment of multi‑account SCCA architectures.
  • TCCM Enforcement: Operate as or support the Trusted Cloud Credential Manager (TCCM) role, implementing strict Role‑Based Access Control (RBAC) and ensuring least‑privileged IAM policies.
2. AWS Organizations & Governance
  • Service Control Policies (SCPs): Architect, write, and manage highly restrictive Service Control Policies (SCPs) at the AWS Organization and Organizational Unit (OU) level. Prevent unauthorized service usage, enforce geographical region locks (restricting actions to AWS Gov Cloud), and deny modification of critical security and logging resources.
  • Compliance & Drift Guarding: Establish continuous automated monitoring to detect and remediate drift from SCCA compliance baselines using native AWS governance capabilities.
3. Dev Sec Ops  & Infrastructure as Code (IaC)
  • Draft all cloud infrastructure using secure, modular Infrastructure as Code (IaC) (primarily Terraform or AWS Cloud Formation).
  • Maintain Infrastructure as Code in secure Git repositories and integrate automated security scanning (e.g., tfsec, Checkov) into CI/CD pipelines.
4. Integration & Security Operations
  • Integrate third‑party security appliances (e.g., Palo Alto, Fortinet) within VDSS transit environments where appropriate.
  • Configure and integrate native DoD security tooling, including Host Based Security System (HBSS),
    Assured Compliance Assessment Solution (ACAS), and CSSP security operations.
AWS Technical Stack & Services Utilized

An AWS SCCA Engineer is expected to have mastery over the following AWS Gov Cloud services:

  • Governance & Multi‑Account Architecture: AWS Organizations, Service Control Policies (SCPs), AWS Control Tower, AWS Landing Zone Accelerator (LZA).
  • Network Security (VDSS): AWS Transit Gateway (central transit hub), AWS Network Firewall, AWS WAF (Web Application Firewall), AWS Shield, Route 53 Resolver (including DNS Firewall), VPC Flow Logs, Application and Network Load Balancers (ALB/NLB).
  • Host Security, Configuration & Patch Management (VDMS): AWS Systems Manager (SSM) (Patch Manager, Session Manager, Run Command, State Manager), AWS Config, AWS Security…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary