Cloud Security Engineer
Listed on 2026-07-13
-
IT/Tech
Cybersecurity, Cloud Computing: Infrastructure & Operations, Systems Engineer, Network Security
About East Bay Systems (Formerly DANASTAR Professional Services)
East Bay Systems is a cybersecurity and information technology consulting firm supporting Federal civilian agencies in delivering secure, resilient, and compliant enterprise systems. We specialize in Cybersecurity Program Management, Security Engineering, Governance, Risk & Compliance (GRC), Security Operations Center (SOC) operations, Cloud Security, and Continuous Monitoring.
We are seeking a Senior Cloud Security Engineer to serve as the organization’s technical lead for cloud security architecture, engineering, infrastructure protection, and cloud compliance across Azure, AWS, and hybrid environments.
Position SummaryThe Senior Cloud Security Engineer is responsible for designing, implementing, securing, and continuously improving enterprise cloud infrastructure supporting Federal information systems. This position serves as the technical authority for cloud security architecture, cloud identity, cloud networking, infrastructure hardening, security monitoring, vulnerability management, and cloud governance.
The engineer works closely with Cloud Engineers, Security Engineers, Dev Sec Ops , SOC analysts, GRC specialists, and Federal stakeholders to ensure cloud platforms are secure, resilient, continuously monitored, and compliant with FISMA, RMF, FedRAMP, Zero Trust Architecture, and OMB cybersecurity requirements.
This position focuses on securing the cloud platforms and infrastructure that host enterprise applications. Application security, secure software development, and CI/CD pipeline security are performed by the Dev Sec Ops Engineer.
Cloud Security Architecture- Design and implement secure Azure, AWS, and hybrid cloud architectures.
- Develop cloud security reference architectures, engineering standards, and implementation guidance.
- Support enterprise cloud adoption initiatives and secure cloud migrations.
- Design secure Landing Zones, subscription/account architectures, and cloud governance models.
- Review cloud solution architectures for compliance with Federal cybersecurity requirements.
- Implement Zero Trust principles within cloud environments.
- Secure cloud infrastructure, including virtual networks, compute, storage, databases, platform services, and cloud-native resources.
- Implement and maintain security controls for Azure and AWS services.
- Configure and maintain Network Security Groups (NSGs), AWS Security Groups, firewalls, Web Application Firewalls (WAFs), Application Gateways, load balancers, VPNs, Express Route, Direct Connect, Private Endpoints, and cloud networking components.
- Develop and maintain secure cloud configuration baselines and hardening standards.
- Perform cloud security architecture reviews and recommend improvements to reduce attack surface.
- Design and implement secure cloud identity architectures.
- Administer Microsoft Entra , cloud IAM services, Privileged Identity Management (PIM), Conditional Access, managed identities, and role-based access control (RBAC).
- Develop least-privilege access models and identity governance standards.
- Support identity federation, authentication, authorization, and privileged access management.
- Design and implement cloud security monitoring architectures.
- Identify and enable cloud platform logs required to support Continuous Monitoring (ISCM), threat detection, incident response, and forensic investigations.
- Ensure Azure, AWS, and hybrid infrastructure generates and forwards required security logs to enterprise monitoring platforms.
- Manage infrastructure logging, including cloud activity logs, identity logs, network flow logs, firewall logs, storage logs, platform diagnostics, and cloud service audit logs.
- Collaborate with the SOC to integrate cloud telemetry into enterprise SIEM and detection engineering processes.
- Define cloud log retention, protection, integrity, and archival requirements in accordance with Federal policies.
- Establish and maintain secure infrastructure configuration baselines.
- Develop and maintain Ports, Protocols, and Services (PPS) baselines for cloud infrastructure components, virtual networks, platform services, and cloud-hosted resources.
- Validate approved network communications, segmentation, trust relationships, ingress and egress rules, and service exposure.
- Review firewall rules, routing, DNS configurations, and network security controls to minimize attack surface.
- Ensure infrastructure configurations comply with Zero Trust Architecture and least functionality principles.
- Implement and manage Cloud Security Posture Management (CSPM) and Cloud Workload Protection Platform (CWPP) capabilities.
- Secure containers, Kubernetes clusters, serverless services, storage platforms, databases, and cloud-native services from an infrastructure perspective.
- Implement cloud vulnerability management, configuration compliance monitoring, and security policy…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).