Cloud Security Engineer
Listed on 2026-07-26
-
IT/Tech
Cybersecurity
Cloud Security Engineer
Job Category:
Engineering & Cloud
Location:
US
- Virginia
- Sterling
Meet Our Team:
This team is part of Pega’s Cloud Cybersecurity organization within the Cloud Cybersecurity Operations tribe. We help build and operate the security controls, automation, and response capabilities that protect Pega's cloud environments, including FedRAMP-regulated government infrastructure, commercial AWS, and multi-cloud platforms. We work across IAM, vulnerability management, compliance automation, SOAR response actions, and AI-driven security tooling. Engineers on this team own their domains end-to-end: design, build, operate, and iterate.
Due to the nature of the role's work with Fed Ramp, US Citizenship is required
Picture Yourself at Pega:
You'll be a part owner of Pega's Fed Ramp/cloud environment, responsible for both day-to-day operational security and sprint-based feature delivery. You'll work alongside peers delivering AI-driven remediation pipelines, identity automation, and cloud security tooling, and are expected to contribute to that innovation work alongside your responsibilities.
This is an engineering role. You write code, build automation, operate regulated infrastructure, and ship features, not just process tickets.
What You'll Do at Pega:
Access Governance & Identity Operations (30%)
- Own Okta administration for PCFG and Commercial environments: MFA resets, account provisioning, Okta Verify troubleshooting, policy enforcement
- Manage IAM roles, permission boundaries, deployment entitlements, and access reviews across PCFG accounts (Cloud Ops, Jenkins, deployment pipelines)
- Build and maintain entitlement automation workflows for joiner/mover/leaver processes
- Support SailPoint quarterly certifications and access request workflows; contribute to AI-assisted certification automation
Vulnerability Scanning & Remediation (25%)
- Operate Nessus/Tenable and Netsparker scanning across PCFG RnD and PCFG Prod
- Respond to audit scan requests (UKCE, SOC, FedRAMP assessors) with findings and evidence
- Track and ensure zero high-severity findings outstanding beyond 30 days
Compliance Patching & BAU (25%)
- Execute FedRAMP Control Plane patching cycle every sprint — mandatory compliance obligation, non-negotiable
- Execute PCFG RnD OS automated patching and validate Commercial environment patches (SailPoint, Ping Castle)
- Maintain patch compliance metrics; elevate blockers before sprint close
- Contribute to SSM Patch Manager automation to reduce manual patching overhead over time
Cloud Infrastructure & Automation Engineering (20%)
- Build infrastructure automation:
Control Tower account provisioning, PCFG account lifecycle, Cloud Formation role deployment - Develop SSM Patch Manager alerting and role infrastructure
- Respond to ad-hoc infrastructure requests: IAM policy changes, Global Accelerator, Lambda roles, Bedrock model enablement
- Contribute to team-wide AI-driven remediation features — SOAR response actions, AWS Config automation, and AI intake tooling
What You've Accomplished:
- 3+ years in cloud security engineering or a closely adjacent role; hands‑on with AWS (IAM, Cloud Formation, SSM, Inspector, Config, Guard Duty)
- Experience operating in a FedRAMP or similarly regulated environment, you understand what compliance‑driven delivery looks like
- Proficient with identity platforms:
Okta administration, SailPoint or equivalent IGA tooling - Comfortable writing automation:
Python, shell, Cloud Formation/Terraform, you don't wait for someone else to build the script - Familiar with vulnerability scanning tools (Nessus/Tenable, Netsparker, or AWS Inspector)
- You operate well in a team that splits time between BAU obligations and feature delivery, context‑switching is part of the job
- Exposure to SOAR platforms (Chronicle Sec Ops, Siemplify, or similar) is a plus
- Experience with Git Hub‑based CI/CD pipelines, you're comfortable with PR‑gated workflows, Git Hub Actions, and treating infrastructure and security content as code that gets reviewed before it ships
- You use AI tools (Copilot, ChatGPT, or similar) as part of how you build, scaffolding automation, generating test cases, accelerating repetitive engineering work and you know how to…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).