What are the responsibilities and job description for the Cloud / Automation Engineer (Security-Focused) position at Global TechPro, LLC?
Cloud / Automation Engineer (Security-Focused)
DevOps Practice | Full-Time | Active Secret Clearance Required | Hybrid
We are seeking a Cloud/Automation Engineer with deep, hands-on security engineering experience across AWS, Kubernetes/EKS, CI/CD pipelines, and Infrastructure-as-Code. This role is ideal for engineers who can own cloud security end-to-end, not just implement controls. You will design secure architectures, troubleshoot complex security failures, and ensure our cloud and on-prem DevOps platforms meet strict compliance and audit requirements. You will work across cloud and on-prem environments, supporting CI/CD automation, infrastructure provisioning, container platforms, and security automation. This position requires strong technical depth, especially in pipeline security, IAM architecture, Kubernetes/EKS security, and IaC security.
Key Responsibilities
Cloud & Platform Security (Primary Focus)
- Architect and enforce secure AWS cloud environments, including IAM policy design, permission boundaries, workload hardening, encryption standards, and secure networking.
- Own security posture for EKS and OpenShift clusters, including RBAC, Pod Security Standards, network policies, admission controllers, secrets management, and runtime security.
- Implement and maintain automated security monitoring using CloudTrail, CloudWatch, GuardDuty, Security Hub, and SIEM integrations.
- Troubleshoot complex cloud security issues such as IAM failures, denied resource creation, broken trust relationships, and misconfigured policies.
CI/CD Pipeline Security
- Build and secure CI/CD pipelines (GitLab, Jenkins) with hardened runners, least‐privilege IAM roles, encrypted secrets, artifact signing, SBOM generation, and vulnerability scanning.
- Diagnose and resolve pipeline security failures including secret injection errors, policy violations, and container image security issues.
- Ensure pipelines meet compliance requirements (CIS, NIST 800‐53, FedRAMP) through automated checks and policy-as-code enforcement.
Infrastructure-as-Code Security
- Develop secure Terraform and Ansible modules with encrypted state, IAM provisioning, compliance guardrails, and automated drift detection.
- Implement policy-as-code frameworks (OPA, Sentinel, Checkov) to enforce security baselines across cloud and on-prem infrastructure.
- Troubleshoot IaC security failures and implement durable fixes.
Security Automation & Compliance
- Build automated workflows for vulnerability scanning, secrets rotation, compliance validation, and configuration drift detection.
- Support audit readiness by documenting security controls, remediation steps, and root-cause analyses.
- Ensure all cloud and on-prem environments adhere to FedRAMP, NIST 800‐53, and enterprise security standards.
DevOps & Platform Engineering
- Support containerized workload deployments on EKS and OpenShift.
- Build and maintain CI/CD pipelines and automation across cloud and on-prem environments.
- Participate in cross-team DevOps initiatives, knowledge sharing, and platform improvements.
- Troubleshoot deployment failures, monitoring gaps, and security automation issues across all supported platforms.
Required Qualifications
- Active Secret Clearance
- 5 years of hands-on experience in Cloud Engineering, DevOps, or Cloud Security
- Strong experience securing AWS environments (IAM, VPC, EC2/EKS, S3, CloudTrail, GuardDuty)
- Hands-on Kubernetes/EKS security experience (RBAC, PSP/PSS, network policies, admission controllers)
- Strong CI/CD pipeline security experience (GitLab CI, Jenkins)
- Proficiency with Terraform and/or Ansible, including secure IaC patterns
- Experience with container security, image scanning, and runtime protection
- Strong troubleshooting skills for security failures across cloud, CI/CD, IaC, and Kubernetes
- Scripting experience (Python, Bash, or similar)
Preferred Qualifications
- Experience with OpenShift security controls
- Experience with compliance frameworks (FedRAMP, NIST 800‐53, CIS Benchmarks)
- Experience with policy-as-code (OPA, Sentinel, Checkov)
- Experience with SIEM tools (Splunk, ELK, Datadog)
- AWS Security or Solutions Architect certification
- CKA or similar Kubernetes certification