Назад
Company hidden
1 час назад

Security Engineer (AWS/Terraform)

220 000 - 260 000$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security Engineer (AWS/Terraform): Building and operationalizing cloud, platform, CI/CD, and application security for AI-native government software with an accent on AWS GovCloud, federal compliance, and secure software supply chains. Focus on translating NIST 800-53 controls into engineering implementations, automating continuous compliance, and designing hardened deployment pipelines for FedRAMP, CMMC, and DoD environments.

Location: Hybrid role based in New York City; candidates must reside in New York or be able to commute to the New York City office at least three times per week, Tuesday through Thursday.

Base salary: $220,000–$260,000 annually, plus equity.

Company

hirify.global builds AI-native software that helps local, state, and federal agencies modernize public services and replace legacy systems.

What you will do

  • Architect and operationalize security across infrastructure, platform, CI/CD, and application layers using AWS, including GovCloud, and Terraform.
  • Lead technical readiness for FedRAMP, CMMC, and DoD Impact Levels by translating NIST 800-53 controls into engineering implementations.
  • Own SSPs, POA&Ms, technical security policies, and the technical relationship with assessors, auditors, and federal security stakeholders.
  • Build continuous compliance and audit-readiness workflows integrated into the software delivery process.
  • Establish secure software supply chain practices including SBOMs, image signing, workload identity, and hardened deployment pipelines.
  • Promote a secure-by-default engineering culture and use AI-driven security tooling and hardened-image platforms to increase team impact.

Requirements

  • 5+ years of hands-on experience building and securing cloud-native platforms with AWS and Terraform.
  • Direct experience with federal authorization work involving FedRAMP, CMMC, DoD Impact Levels, or comparable regulated environments.
  • Deep familiarity with NIST 800-53 and the ability to turn controls into pragmatic engineering work.
  • Strong knowledge of software supply chain security, including SBOMs, image signing, workload identity, and secure CI/CD.
  • Experience working in an early-stage or fast-moving environment where security standards and processes must be established.
  • Ability to work from New York or commute to the New York City office at least three days per week.

Nice to have

  • Experience supporting federal SaaS, defense technology, or regulated infrastructure companies through accreditation.
  • Experience leading a company through its first federal authorization.
  • Hands-on experience with Chainguard, AI-powered security tooling, Second Front, or similar platforms.

Culture & Benefits

  • Fully covered medical, dental, and vision insurance for employees and dependents, plus life insurance and FSA options.
  • 401(k) with a 2% company match, paid parental leave, unlimited PTO with a two-week minimum, federal holidays, and a company-wide winter break.
  • Home office setup stipend, commuter benefit, expensed office lunches, and a company-provided laptop.
  • Covered gym membership or fitness reimbursement, utility stipend, professional development budget, recreation stipend, and pet care stipend.
  • Company offsites throughout the year.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →