Назад
Company hidden
5 дней назад

Sr. Cloud Security Engineer - FedRamp

Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Sr. Cloud Security Engineer - FedRamp (Multi-Cloud Security): Designing and maintaining security controls across AWS, Azure, GCP, and OCI with an accent on infrastructure automation, system hardening, and DevSecOps pipeline security. Focus on securing Kubernetes and Linux environments, integrating SAST/DAST/SCA tools, managing secrets, and supporting FedRAMP and other compliance audits.

Location: United States (Remote), Dallas preferred

Company

hirify.global provides mobile threat defense and machine learning-based protection against device, network, phishing, application, and malware attacks across iOS, Android, and Windows devices.

What you will do

  • Design, implement, and manage security controls across AWS, Azure, GCP, and OCI environments.
  • Automate secure infrastructure deployment with Terraform and/or CloudFormation.
  • Apply CIS Level 2 and DISA STIG hardening standards across Linux systems and Kubernetes clusters.
  • Configure and optimize Prisma Cloud, Orca, Google SecOps, Palo Alto firewalls, and WAF solutions.
  • Integrate SAST, DAST, and SCA tools into CI/CD pipelines and manage secrets and key rotation.
  • Conduct threat modeling, support incident response and on-call operations, and prepare audit evidence and technical reports.

Requirements

  • 8+ years of progressive IT experience, including at least 5 years in cloud security engineering.
  • Expertise in Terraform and/or CloudFormation and practical security experience with at least three major cloud providers.
  • Strong Linux administration and Kubernetes security experience.
  • Hands-on experience with at least two advanced security platforms, plus WAF and DevSecOps implementation experience.
  • Experience with secret management solutions such as HashiCorp Vault or AWS Secrets Manager.
  • Excellent written and verbal communication skills and the ability to work independently with ownership of critical responsibilities.

Nice to have

  • Experience in highly regulated environments such as FedRAMP, DoD, or financial sectors.
  • Experience implementing ISO 27001 and SOC 2 controls.
  • Formal threat modeling and risk analysis experience.
  • Experience in both large enterprise and fast-paced startup or technology environments.
  • Relevant certifications such as CISSP, CCSP, or cloud security specializations.

Culture & Benefits

  • Remote work within the United States.
  • Rotating on-call participation for security incidents and operational issues.
  • Autonomous work with opportunities to identify improvements and drive security projects to completion.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →