What are the responsibilities and job description for the Cloud Security Engineer position at Improvix Technologies?
Job Title: Cloud Security Engineer
Location: Washington, DC (Onsite)
Clearance Required: Secret
Overview
We are seeking a Cloud Security Engineer to help design, implement, and maintain secure cloud environments across AWS, Azure, and GCP. The ideal candidate will have hands-on experience with cloud security tools, infrastructure automation, and DevSecOps practices. This role involves working closely with platform engineers, developers, and compliance teams to embed security into cloud solutions and ensure alignment with industry standards and regulatory requirements.
Key Responsibilities
Cloud Security Implementation
- Deploy and configure security controls across AWS, Azure, and GCP environments.
- Apply security baselines (CIS Benchmarks, NIST 800-53, FedRAMP) and assist with compliance alignment.
- Support secure architecture reviews and provide guidance on best practices for cloud workloads.
Automation & DevSecOps
- Develop and maintain Infrastructure as Code (Terraform, CloudFormation, or similar) for security configurations.
- Integrate security scanning tools (SAST, DAST, IaC scanning, container security) into CI/CD pipelines.
- Assist in building automated guardrails and remediation workflows.
Security Monitoring & Compliance
- Implement centralized logging and monitoring for cloud environments.
- Support compliance efforts by embedding security controls into cloud deployments and preparing evidence for audits.
- Participate in incident response and vulnerability remediation activities.
Collaboration
- Work with cloud engineers, developers, and compliance teams to ensure security objectives are met.
- Act as a resource for cloud security best practices within project teams.
Required Qualifications
- Bachelor’s degree in Computer Science or related field, or equivalent experience.
- 3–5 years of experience in cybersecurity or cloud engineering, with at least 2 years focused on cloud security.
- Hands-on experience with at least one major cloud provider (AWS, Azure, or GCP).
- Familiarity with cloud-native security tools (e.g., AWS Security Hub, Azure Defender, Google SCC).
- Experience with Infrastructure as Code (Terraform, CloudFormation, or similar).
- Basic scripting skills (Python, PowerShell, or Bash).
- Understanding of IAM, encryption, networking, and key management in cloud environments.
- Knowledge of security frameworks such as NIST, CIS, or FedRAMP.
Preferred Qualifications
- Experience with CI/CD security integration and DevSecOps practices.
- Exposure to container security and Kubernetes hardening.
- Certifications such as AWS Certified Security – Specialty, Azure Security Engineer Associate, or Google Professional Cloud Security Engineer.
- Familiarity with zero trust principles and enterprise identity platforms.