×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

Cloud Security Engineer – FedRAMP & AI-Driven Security

Job in Sterling, Loudoun County, Virginia, 22170, USA
Listing for: Pegasystems
Full Time position
Listed on 2026-07-19
Job specializations:
  • IT/Tech
    Cybersecurity
Salary/Wage Range or Industry Benchmark: 86700 - 129600 USD Yearly USD 86700.00 129600.00 YEAR
Job Description & How to Apply Below

Search All Jobs

Cloud Security Engineer

Job Category:
Engineering & Cloud

Location:

US
- Virginia
- Sterling

  • Apply now
  • Share Share via Facebook Share via X Share via Linked In Share via Email Copying... Copied!
Meet Our Team:

This team is part of Pega’s Cloud Cybersecurity organization within the Cloud Cybersecurity Operations tribe. We help build and operate the security controls, automation, and response capabilities that protect Pega's cloud environments, including FedRAMP-regulated government infrastructure, commercial AWS, and multi-cloud platforms. We work across IAM, vulnerability management, compliance automation, SOAR response actions, and AI-driven security tooling. Engineers on this team own their domains end-to-end: design, build, operate, and iterate.

Due to the nature of the role's work with Fed Ramp, US Citizenship is required

Picture Yourself At Pega:

You'll be a part owner of Pega's Fed Ramp/cloud environment, responsible for both day-to-day operational security and sprint-based feature delivery. You'll work alongside peers delivering AI-driven remediation pipelines, identity automation, and cloud security tooling, and are expected to contribute to that innovation work alongside your responsibilities.

This is an engineering role. You write code, build automation, operate regulated infrastructure, and ship features, not just process tickets.

What You'll Do At Pega:

Access Governance & Identity Operations (30%)

  • Own Okta administration for PCFG and Commercial environments: MFA resets, account provisioning, Okta Verify troubleshooting, policy enforcement
  • Manage IAM roles, permission boundaries, deployment entitlements, and access reviews across PCFG accounts (Cloud Ops, Jenkins, deployment pipelines)
  • Build and maintain entitlement automation workflows for joiner/mover/leaver processes
  • Support SailPoint quarterly certifications and access request workflows; contribute to AI-assisted certification automation
Vulnerability Scanning & Remediation (25%)

  • Operate Nessus/Tenable and Netsparker scanning across PCFG RnD and PCFG Prod
  • Respond to audit scan requests (UKCE, SOC, FedRAMP assessors) with findings and evidence
  • Track and ensure zero high-severity findings outstanding beyond 30 days
Compliance Patching & BAU (25%)

  • Execute FedRAMP Control Plane patching cycle every sprint — mandatory compliance obligation, non-negotiable
  • Execute PCFG RnD OS automated patching and validate Commercial environment patches (SailPoint, Ping Castle)
  • Maintain patch compliance metrics; escalate blockers before sprint close
  • Contribute to SSM Patch Manager automation to reduce manual patching overhead over time
Cloud Infrastructure & Automation Engineering (20%)

  • Build infrastructure automation:
    Control Tower account provisioning, PCFG account lifecycle, Cloud Formation role deployment
  • Develop SSM Patch Manager alerting and role infrastructure
  • Respond to ad-hoc infrastructure requests: IAM policy changes, Global Accelerator, Lambda roles, Bedrock model enablement
  • Contribute to team-wide AI-driven remediation features — SOAR response actions, AWS Config automation, and AI intake tooling
What You've Accomplished:

  • 3+ years in cloud security engineering or a closely adjacent role; hands-on with AWS (IAM, Cloud Formation, SSM, Inspector, Config, Guard Duty)
  • Experience operating in a FedRAMP or similarly regulated environment, you understand what compliance-driven delivery looks like
  • Proficient with identity platforms:
    Okta administration, SailPoint or equivalent IGA tooling
  • Comfortable writing automation:
    Python, shell, Cloud Formation/Terraform, you don't wait for someone else to build the script
  • Familiar with vulnerability scanning tools (Nessus/Tenable, Netsparker, or AWS Inspector)
  • You operate well in a team that splits time between BAU obligations and feature delivery, context-switching is part of the job
  • Exposure to SOAR platforms (Chronicle Sec Ops, Siemplify, or similar) is a plus
  • Experience with Git Hub-based CI/CD pipelines,you're comfortable with PR-gated workflows, Git Hub Actions, and treating infrastructure and security content as code that gets reviewed before it ships
  • You use AI tools (Copilot, ChatGPT, or similar) as part of how you…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary