Cloud Security Engineer
Listed on 2026-05-12
-
IT/Tech
Cybersecurity, Systems Engineer, Cloud Computing
This role is contingent upon winning the award
The Health and Services Sector at Leidos currently has an opening for a Cloud Security Engineer to work in the Seaside, CA area. This is an exciting opportunity to use your experience supporting the Defense Testing and Assessment Center (DTAC) Manpower Personnel Testing Analysis (MPTA) mission.
In this mission, we deliver advanced scientific, technical, and IT solutions that enable the development, delivery, and continuous improvement of DoW testing and assessment systems, including the cloud-based CAT-ASVAB platform and associated language testing systems. Our team supports secure, scalable cloud environments that process sensitive personnel data and power mission‑critical applications used across the Department of Defense.
As a Cloud Security Engineer, you will play a critical role in safeguarding cloud infrastructure, applications, and data by implementing robust cybersecurity controls aligned with DoW standards. You will support Risk Management Framework (RMF) activities, continuous monitoring, and system authorization processes while ensuring compliance with NIST, DISA, and DoW cybersecurity requirements. This role directly contributes to protecting the integrity, availability, and confidentiality of systems that support military recruiting, assessment, and readiness initiatives.
The ideal candidate will thrive in a dynamic environment focused on innovation, Dev Sec Ops , and cloud modernization, helping DTAC maintain secure and resilient systems that support critical national defense missions.
Primary Responsibilities- Design, implement, and maintain security architectures for cloud‑based systems supporting DoW testing platforms, including web‑based and cloud‑based applications (e.g., CAT‑ASVAB systems).
- Ensure compliance with DoW cybersecurity policies, including RMF (Risk Management Framework), NIST SP 800‑53 controls, and DISA Cloud Security Requirements Guide (SRG).
- Support the full lifecycle of system authorization (ATO), including development of System Security Plans (SSPs), POA&Ms, security assessments, and continuous monitoring activities.
- Implement and enforce Security Technical Implementation Guides (STIGs) and secure configuration baselines across cloud environments.
- Monitor cloud environments for vulnerabilities, threats, and incidents; coordinate incident response and reporting in accordance with DoW requirements.
- Engineer and maintain secure cloud infrastructure solutions compliant with FedRAMP and DISA Impact Level (IL) requirements (IL2‑IL5 as applicable).
- Implement Zero Trust, Dev Sec Ops , and continuous monitoring strategies aligned with DoW CIO modernization guidance.
- Perform security assessments, code scanning, vulnerability remediation, and risk mitigation activities for cloud‑hosted applications.
- Collaborate with software engineers, system administrators, and data teams to integrate security into system design, development, and deployment processes.
- Maintain documentation, security artifacts, and compliance evidence within systems such as eMASS.
- Ensure protection of Controlled Unclassified Information (CUI) and Personally Identifiable Information (PII) in cloud environments.
- Bachelor’s degree (BS/BA) or Master’s degree in Cybersecurity, Information Technology, Computer Science, or related field.
- Minimum 10 years of experience designing, implementing, and managing cloud security solutions and cybersecurity programs.
- Demonstrated experience with DoW RMF
, ATO processes, and NIST 800‑series frameworks. - Hands‑on experience securing cloud environments (e.g., AWS, Azure, or DoW‑approved cloud platforms) in compliance with DISA SRG and FedRAMP requirements.
- Experience implementing STIGs
, vulnerability management, and continuous monitoring programs. - Strong knowledge of network security, encryption, identity and access management (IAM), and Zero Trust architectures
. - Experience supporting Dev Sec Ops pipelines and secure software development practices
. - Ability to obtain and maintain required DoW background investigation (Tier 3 or higher) and meet IT access requirements.
- U.S. Citizenship required.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).