What Cloud Security Specialist Jobs are in the United States?
Showing 5000+ Cloud Security Specialist jobs in the United States
Job Description
This role is a core contributor to the design and implementation of secure cloud architectures across our multi-cloud environments (GCP primary; AWS/Azure supporting) and cloud-adjacent SaaS services. As a staff-level architect, you will focus on applying established security patterns, implementing guardrails, and partnering with engineering teams to ensure cloud workloads meet regulatory, audit, and customer assurance requirements typical of a healthcare payments organization (e.g., PCI DSS, HIPAA/HITECH, HITRUST, SOC 2, SOX, and aligned NIST controls).
You will work under the guidance of security engineering leadership, helping translate standards into practical implementations, improving cloud security posture, and enabling secure-by-design delivery.
**WHAT YOU'LL DO**
**Cloud security design & implementation**
Contribute to and maintain cloud security reference architectures, standards, and implementation patterns for IaaS, PaaS, containers/Kubernetes, and serverless workloads.
Partner with engineering and platform teams to apply approved security patterns in new and existing cloud workloads.
**Landing zone & governance support**
Help implement and operate secure cloud landing zone controls including account/project structures, network segmentation, IAM boundaries, logging, and policy guardrails.
Support infrastructure-as-code and policy-as-code implementations aligned with defined standards.
**Identity & access management**
Implement least-privilege IAM for workforce and workload identities.
Support MFA, conditional access, secrets management, and privileged access patterns designed by senior architects.
**Data protection**
Apply encryption, key management, tokenization, and data handling standards for sensitive data including payment and healthcare data.
Assist with data classification, retention, and secure deletion controls in cloud platforms.
**Security-by-design in engineering**
Participate in threat modeling and security design reviews for cloud services and applications.
Help integrate DevSecOps and SDLC security controls into CI/CD pipelines using established tooling and patterns.
**Detection & response readiness**
Ensure required cloud audit logs, telemetry, and security signals are enabled and flowing to centralized monitoring.
Partner with Security Operations to improve visibility, detection coverage, and incident readiness in cloud environments.
**Vulnerability & configuration management**
Help define and maintain cloud hardening baselines, container/image standards, and configuration compliance controls.
Work with engineering teams to remediate recurring or systemic cloud security findings.
**Third-party & SaaS security**
Support reviews of cloud-connected vendors and SaaS integrations against established security requirements.
Assist in defining and validating compensating controls and monitoring expectations.
**Audit & evidence support**
Partner with GRC and audit teams to map technical cloud controls to compliance frameworks.
Support evidence collection, control validation, and remediation activities during audits and assessments.
**Conduct Security Reviews**
Work with project teams to evaluate the security of new, cloud-based initiatives, project, and products for customer facing and internal use applications.
**Compliance, risk, and assurance expectations**
Design cloud security controls aligned to PCI DSS, HIPAA/HITECH, HITRUST CSF, SOC 2, SOX ITGC, and internal security standards.
Support continuous compliance efforts such as automated configuration checks, continuous monitoring, and repeatable evidence generation.
Participate in risk assessments, exception handling, and corrective action plans for cloud security gaps.
Contribute to customer assurance activities by providing clear technical explanations and diagrams with guidance from senior architects.
**WHAT YOU'LL NEED**
3+ years of hands-on experience securing workloads in public cloud environments (Google Cloud Platform (GCP), AWS, or Azure). Multi-cloud experience preferred.
Solid understanding of core cloud security concepts: IAM, networking, segmentation, logging/monitoring, encryption, key management, secrets management, and workload security.
Experience using infrastructure-as-code and automation tools (e.g., Terraform, CloudFormation, Bicep) and supporting CI/CD pipelines.
Familiarity with container and/or Kubernetes security fundamentals.
Experience participating in threat modeling or security design reviews.
Strong written and verbal communication skills; able to document designs and explain security requirements to engineering teams.
Bachelor's degree in Computer Science, Engineering, or a related field (or equivalent practical experience).
**Preferred qualifications**
Exposure to PCI DSS, HIPAA/HITECH, or HITRUST control implementation in cloud environments.
Experience with CSPM tools, cloud-native security services, or SIEM integrations.
Familiarity with application security and DevSecOps tooling (SAST/DAST/SCA, secrets scanning).
Knowledge of modern cloud patterns such as zero trust, API security, or event-driven architectures.
Relevant certifications (one or more): CCSP, GCP Professional Cloud Security Engineer, AWS/Azure security specialty, or equivalent.
**ABOUT WAYSTAR**
Through a smart platform and better experience, Waystar helps providers simplify healthcare payments and yield powerful results throughout the complete revenue cycle.
Waystar's healthcare payments platform combines innovative, cloud-based technology, robust data, and unparalleled client support to streamline workflows and improve financials so providers can focus on what matters most: their patients and communities. Waystar is trusted by 1M+ providers, 1K+ hospitals and health systems, and is connected to over 5K commercial and Medicaid/Medicare payers. We are deeply committed to living out our organizational values: honesty; kindness; passion; curiosity; fanatical focus; best work, always; making it happen; and joyful, optimistic & fun.
Waystar products have won multiple Best in KLAS® or Category Leader awards since 2010 and earned multiple #1 rankings from Black Book surveys since 2012. The Waystar platform supports more than 500,000 providers, 1,000 health systems and hospitals, and 5,000 payers and health plans. For more information, visit waystar.com or follow @Waystar ( on Twitter.
**WAYSTAR PERKS**
+ Competitive total rewards (base salary + bonus, if applicable)
+ Customizable benefits package (3 medical plans with Health Saving Account company match)
+ We offer generous paid time off for our non-exempt team members, starting with 3 weeks + 13 paid holidays, including 2 personal floating holidays. We also offer flexible time off for our exempt team members + 13 paid holidays
+ Paid parental leave (including maternity + paternity leave)
+ Education assistance opportunities and free LinkedIn Learning access
+ Free mental health and family planning programs, including adoption assistance and fertility support
+ 401(K) program with company match
+ Pet insurance
+ Employee resource groups
Waystar is proud to be an equal opportunity workplace. We celebrate, value, and support diversity and inclusion. Qualified applicants will receive consideration for employment without regard to race, color, religion, age, sex, national origin, disability status, genetics, marital status, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state, or local laws.
This applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation, and training.
**Job Category:** Technology/Engineering
**Job Type:** Full time
**Req ID:** R3257
Is this job a match or a miss?
Job Description
Job Category: Information Technology
Time Type: Full time
Minimum Clearance Required to Start: TS/SCI
Employee Type: Regular
Percentage of Travel Required: Up to 10%
Type of Travel: Continental US
* * *
**The Opportunity:**
As a CACI Cloud Software Engineer to help design, build, and maintain scalable software solutions for a mission-critical, cloud-native ecosystem. This role sits inside the Special Operations Command Europe (SOCEUR) Hybrid Threat Action Platform (HTAP) team and is responsible for helping translate complex mission requirements into robust, reusable, and secure software tools on the Google Cloud Platform (GCP). The individual will contribute to the design and implementation of technology solutions and will be a key part of the software development lifecycle. The individual will interact regularly with data scientists, DevSecOps engineers, and mission owners to enhance and sustain a cutting-edge analytics environment for Allied, partner, and US operations.
**Responsibilities:**
+ Develop, test, and maintain scalable, resilient, and secure software tools and microservices for a cloud-native environment.
+ Contribute to the design of software subsystems, promoting code reuse and adhering to established technical standards.
+ Develop and integrate custom APIs, including those that expose AI/ML model outputs for enterprise applications.
+ Deploy and manage cloud-native infrastructure, including Google Kubernetes Engine (GKE) clusters, using Infrastructure as Code (IaC) principles.
+ Contribute to the implementation and maintenance of CI/CD pipelines for automated building, testing, and deployment of software.
+ Implement application monitoring, logging, and alerting using Google Cloud's operations suite to ensure system health and performance.
+ Collaborate with security teams to perform regular security patching, address vulnerabilities, and implement secure coding best practices.
+ Participate in code reviews to maintain high code quality and share knowledge with the team.
+ Maintain clear and comprehensive technical documentation for developed software.
**Qualifications:**
_Required:_
+ Must be a US Citizen possessing an active TS/SCI security clearance.
+ Bachelor's degree in Computer Science, Engineering, or a related technical field (or equivalent practical experience).
+ DoD -M / DoD 8140 IAT Level II (or higher) baseline certification (e.g., CompTIA Security+).
+ 3-5+ years of professional software development experience.
+ Proven experience working in a collaborative, cross-functional team environment.
+ Proficiency in scripting and programming languages (e.g., Python, Go, Java, Bash).
+ Experience with containerization (Docker) and a foundational understanding of orchestration with Kubernetes.
+ Familiarity with CI/CD principles and tools (e.g., GitLab CI, Jenkins).
+ Knowledge of cloud networking (VPCs, firewall rules) and secure coding principles in a GCP environment.
+ Google Cloud Professional Cloud Developer certification.
**Desired:**
+ Master's degree in Engineering, Computer Science, or a related technical field.
+ Experience with big data processing frameworks such as Apache Spark or Apache Airflow.
+ Google Cloud Professional Cloud Architect or DevOps Engineer certification.
+ Experience working in a regulated DoD or Intelligence Community environment.
-
**What You Can Expect:**
**A culture of integrity.**
At CACI, we place character and innovation at the center of everything we do. As a valued team member, you'll be part of a high-performing group dedicated to our customer's missions and driven by a higher purpose - to ensure the safety of our nation.
**An environment of trust.**
CACI values the unique contributions that every employee brings to our company and our customers - every day. You'll have the autonomy to take the time you need through a unique flexible time off benefit and have access to robust learning resources to make your ambitions a reality.
**A focus on continuous growth.**
Together, we will advance our nation's most critical missions, build on our lengthy track record of business success, and find opportunities to break new ground - in your career and in our legacy.
**Pay Range** :
There are a host of factors that can influence final salary including, but not limited to, geographic location, Federal Government contract labor categories and contract wage rates, relevant prior work experience, specific skills and competencies, education, and certifications. Our employees value the flexibility at CACI that allows them to balance quality work and their personal lives. We offer competitive compensation, benefits and learning and development opportunities. Our broad and competitive mix of benefits options is designed to support and protect employees and their families. At CACI, you will receive comprehensive benefits such as; healthcare, wellness, financial, retirement, family support, continuing education, and time off benefits.
Since this position can be worked in more than one location, the range shown is the national average for the position.
The proposed salary range for this position is:
$105,100-$231,100
_CACI is_ _an Equal Opportunity Employer._ _All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, age, national origin, disability, status as a protected veteran, or any_ _other protected characteristic._
Is this job a match or a miss?
Job Description
NTT DATA strives to hire exceptional, innovative and passionate individuals who want to grow with us. If you want to be part of an inclusive, adaptable, and forward-thinking organization, apply now.
We are currently seeking a Cloud Security Specialist to join our team in Plano, Texas (US-TX), United States (US).
The NTT DATA Cloud & Security Senior Specialist works closely with the Information Security Manager (ISM) to ensure the seamless delivery of all information security services that NTT DATA provides to the customer.
This role will be on-site at our client site on a hybrid basis. Only local candidates will be considered.
**Role Responsibilities**
+ Identify and continually review and recommend cloud security leading practices Obtain and review industry-recognized periodical bulletins regarding cloud security
+ Utilize native cloud security solutions or third-party solutions (e.g. CSPM, CNAPP, CIEM, CASB) to secure the cloud environment and individual applications
+ Utilize native cloud SIEM or integrate cloud monitoring events into SIEM or other operational solution
+ Monitor cloud network security based on best-practice and recommended standards and Customer's security standards,
+ Support and maintain familiarity with modern cloud network architectures, such as Software Defined Networking (SDN), virtual private clouds such as Virtual Subnets (VNETs), and Security Groups where needed
+ Maintain virtual private cloud network segregation (i.e., the separation of the VNETs, VPCs, and subnets for production and non-production )
+ Monitor cloud VPN gateway; ensure any external connections to the environment utilize secure connectivity methods (such as IPSEC Tunnels); and disablement or blocking any unnecessary or unapproved ports and protocols for cloud workloads;
+ Manage multi-factor authentication used for resource access to the cloud console and management network
+ Monitor firewall/security group Configurations
+ Detect and ensure cloud hosted data I encrypted as required
+ Monitor the security posture of the cloud supplier's DNS / routing configurations and cloud resources
+ Continuously assess cloud network configurations against regulatory and organizational standards (e.g., CIS, NIST) and generate automated audit-ready reports.
+ Monitor and secure administrative level and root account privileges through following recommended best practices, such as:
+ enabling and enforcing multi-factor authentication; and
+ support and assist with AD integration, enable and support Azure role-based access control (RBAC), as well as conditional access with privileged accounts (attribute-based access control or context-based access control)
+ adhere to cloud best practice standards and procedures for access key management, rotation, and secure storage
+ ensure cloud-hosted resources have appropriate security rules and standards for only necessary ports and protocols
+ manage and administer the cloud environment role provisioning and de-provisioning based on least-privilege and need-to-know principles.
+ Cloud Account Management - Create, modify, delete Accounts; associate and de-associate Cloud Services Resources within defined Tenants; collect and validate all Asset information for
+ Customer Cloud Accounts; utilize Public Cloud Services to manage & maintain account standardization and compliance throughout the lifecycle of an Account; and
+ Cloud Services Identity and Access Management (IAM) - Management of Identity and Access Management to grant End Users the right to use a service and deny access to unauthorized users.
+ Grant End Users the right to use a service and deny access to unauthorized users;
+ Define, implement and operate access management protocols, tools and processes that enable access rights and identities to be established, controlled, authorized, administered, reported and audited in adherence with the Identity Management Policy standards;
+ Develop and best practices and implement including -Least Privilege Access, Strong Authentication Mechanisms, Role-Based Access Control (RBAC) ,etc
+ Develop policies on privacy protection and protective security for access to data, including security, data and records management, and electronic records and data
+ Conduct periodic access reviews, detect procedure violations, and generate audit-ready reports (for regulatory standards like ISO 27001, SOC 2, and GDPR.)
+ User Management - Control User access to cloud resources by users for maintaining system security and the prevention of unauthorized use. Implement strong authentication methods, monitoring user activities, and ensuring compliance with security policies and regulatory requirements.
+ Cloud VM and Storage Security - Monitor VM and storage encryption security requirements; provide, monitor and oversee OS, container, and workload instances to ensure hardening of workloads to comply with the CIS level 1 security standard that complies; monitor resiliency and recovery of cloud workloads to ensure sound backup management, scheduling, retention management
+ Cloud Security Posture Management - Manage cloud security posture management platform and capabilities. Responsibilities include:
+ Support the administration of the CSPM platform, which includes access control, Software updates, and working with the vendor on platform support
+ manage and monitor vulnerability detection of cloud workloads and services, this includes both CVE registered vulnerabilities and security misconfigurations detected by the tool
+ assist with prioritization, escalation, and management of Alerts and detections from the tool
+ Integrate with Security Operations Centre and SIEM platform
+ support and monitor the identity and entitlements management functionalities of the too
+ Integrate CSPM tool into SASE tool stack and cloud environment.
**Basic Requirements:**
+ 6+ years of Cloud Security Experience
**Additional Preferences:**
+ Knowledge of risk management concepts
+ Knowledge of systems and network administration (i.e., desktop, server)
+ Familiarity with information security technologies and issues on multiple platforms
+ Knowledge of Globally Accepted Information Security Principles
+ Knowledge of network security that pertains to communications, computer system environments and related infrastructure
+ Knowledge of server and desktop configurations that will protect systems from unauthorized access and software invasion
+ Preferred: CISSP, GIAC, SSCP or CEH
_NTT DATA provides a reasonable range of compensation for U.S.-based positions. The starting pay range for this role is $87,720 - $131,580. Actual compensation will depend on a number of factors, including the candidate's relevant experience, technical skills, and other qualifications._
_This position may also be eligible for incentive compensation based on individual and/or company performance._
_This position is eligible for company benefits including medical, dental, and vision insurance with an employer contribution, flexible spending or health savings account, life and AD&D insurance, short and long term disability coverage, paid time off, employee assistance, participation in a 401k program with company match, and additional voluntary or legally-required benefits._
**About NTT DATA**
NTT DATA is a $30 billion business and technology services leader, serving 75% of the Fortune Global 100. We are committed to accelerating client success and positively impacting society through responsible innovation. We are one of the world's leading AI and digital infrastructure providers, with unmatched capabilities in enterprise-scale AI, cloud, security, connectivity, data centers and application services. our consulting and Industry solutions help organizations and society move confidently and sustainably into the digital future. As a Global Top Employer, we have experts in more than 50 countries. We also offer clients access to a robust ecosystem of innovation centers as well as established and start-up partners. NTT DATA is a part of NTT Group, which invests over $3 billion each year in R&D.
Whenever possible, we hire locally to NTT DATA offices or client sites. This ensures we can provide timely and effective support tailored to each client's needs. While many positions offer remote or hybrid work options, these arrangements are subject to change based on client requirements. For employees near an NTT DATA office or client site, in-office attendance may be required for meetings or events, depending on business needs. At NTT DATA, we are committed to staying flexible and meeting the evolving needs of both our clients and employees. NTT DATA recruiters will never ask for payment or banking information and will only use @nttdata.com, @nttdatafed.com and @talent.nttdataservices.com email addresses. If you are requested to provide payment or disclose banking information, please submit a contact us form, .
**_NTT DATA endeavors to make_** **_ **_accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact us at_** **_ **_._** **_This contact information is for accommodation requests only and cannot be used to inquire about the status of applications. NTT DATA is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status. For our EEO Policy Statement, please click here ( . If you'd like more information on your EEO rights under the law, please click here ( . For Pay Transparency information, please click here ( ._**
Is this job a match or a miss?
Job Description
100% ONSITE in Washington DC
Per Federal contract U.S. Citizenship Required
Must be able to pass enhanced FBI background screening (criminal, financial and finger printing) for Public Trust clearance
Performance Period: June 2026- Dec , with the possibility of multi-year extension based on performance
W-2 or C2C
Deadline to apply May 5th
PROJECT DESCRIPTION:
The IT Security Engineering team is seeking a Senior Cloud Security Specialist with deep expertise in AWS cloud services, cloud-native security tools and services.
BACKGROUND:
We are seeking a Senior Cloud Security Specialist to support the Security Engineering team within the IT division. This team is responsible for the strategy, design, deployment, and maintenance of effective security solutions in cloud, local, and hybrid environments.
REQUIREMENTS:
The candidate shall also demonstrate the knowledge and experience below:
+ Required Experience:
+ Minimum 5 years hands-on AWS security experience
+ Personnel Qualifications
+ AWS Certified Security - Specialty (strongly preferred)
+ AWS Certified Solutions Architect - Professional or Associate
+ Demonstrated experience implementing secure, scalable AWS cloud architectures following industry best security practices and security frameworks.
+ Demonstrated federal experience and comprehensive knowledge in adopting and implementing federal cybersecurity requirements, including but not limited to the NIST Cybersecurity Framework, OMB Memorandum M-22-09, NIST SP 800-53
+ Possess deep analytical, problem-solving, and troubleshooting experience, to independently resolve complex security challenges.
+ Proven ability to provide technical security consultation and advisory services with a proactive approach to identifying potential issues, raising questions, and engaging in open dialogue with team members and stakeholders to ensure security objectives are met.
+ Strong understanding of security concepts and technologies related to Identity and Access Management (IAM), security engineering, network security design, security operations, security architecture, general engineering processes, cloud security, data loss protection, zero trust, DevSecOps and vulnerability management.
+ Technical skills in AWS cloud security, security engineering, DevSecOps, scripting, and Infrastructure-as-code (IaC)
+ Self-motivated and able to work independently
+ Strong attention to detail
The Consultant shall deliver, but not limited to, the following:
+ Conduct regular security reviews of cloud infrastructure deployed by engineering teams
+ Evaluate infrastructure-as-code against security standards
+ Review and validate compliance with security policies and best practices
+ Assess adherence to AWS Well-Architected Framework security pillar
+ Identify and document security misconfigurations and non-compliant controls
+ Develop and maintain security posture dashboards
+ Create or update security configuration guides and playbooks
+ Offer technical consultation to engineering teams on secure implementation
+ Implement AWS security controls and services to ensure proper security hardening and other security engineering tasks.
+ Develop and update AWS security configuration standards
+ Conduct security training sessions for engineering teams
+ Present findings and recommendations in team meetings
+ Identify opportunities to automate security assessments
+ Recommend security tooling improvements
PLACE OF PERFORMANCE:
On-site at FRB locations, Washington, DC
CITIZEN STATUS:
U.S. Citizenship is required per Federal Contract
INTERVIEW: Selected candidates will participate in a phone screening. Those that pass the phone screening may be invited to an in-person interview. The use of video conference tools
(e.g., MS Teams or WebEx) can be used in accordance with agency guidelines.
Ref: #851-Rockville-S1
System One, and its subsidiaries including Joulé, ALTA IT Services, CM Access, TPGS, and MOUNTAIN, LTD., are leaders in delivering workforce solutions and integrated services across North America. We help clients get work done more efficiently and economically, without compromising quality. System One not only serves as a valued partner for our clients, but we offer eligible full-time employees health and welfare benefits coverage options including medical, dental, vision, spending accounts, life insurance, voluntary plans, as well as participation in a 401(k) plan.
System One is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, age, national origin, disability, family care or medical leave status, genetic information, veteran status, marital status, or any other characteristic protected by applicable federal, state, or local law.
Is this job a match or a miss?
Job Description
Suitability/Public Trust
Hybrid schedule
Cyber Security Services
**Overview**
GovCIO is currently hiring for a Sr. Cyber/Cloud Security Specialist to serve as Lead Information Technology Specialist (INFOSEC) and Cybersecurity Operations (SECOPS). This position will be hybrid, mostly remote with occasional onsite time as needed (hybrid) at EEOC HQ in Washington, DC.
**Responsibilities**
+ Serve as Lead Information Technology Specialist (INFOSEC), Cybersecurity Operations (SECOPS) responsible for contributing to the Agency's IT Security Program, directs SECOPS, coordinates, and maintains inputs to EEOC's IT Security Program.
+ Advise and support the Chief Information Security Officer (CISO) on developments in Cybersecurity (CS), Information Security (INFOSEC) and IT Security emerging technical threat vectors, advanced persistent threats (APT), attack surface or weaknesses.
+ Advise Agency-level technical implementation or introduction of policy and orders, proactively developing supporting documentation and drafts for implementation.
+ Direct the Commission's Cybersecurity Operations (SECOPS) cell, influences a range of the EEOC's operations, many of which have a direct and corresponding impact to the mission of the EEOC and its' critical infrastructure.
+ Enables and administrates incident handling (IH) and response (IR), security incident and event management (SIEM) dashboards, inputs, "playbooks" and metrics to achieve efficiency.
+ Facilitates, coordinates, and administers EEOC's Cybersecurity Operations (SECOPS) in support of the Information Security (INFOSEC) Program, and aids Agency Information system security program officers. Ensures accurate and timely status reporting of SOC efficiency metrics and recommends necessary adjustments.
+ Advising authority for threat, vulnerability, and configuration management; conveys threat product recommendations to EEOC staff and customers; and provides expertise and insight to OIT for industry attack trends, mitigations, and active defenses.
**Qualifications**
Bachelor's degree in Cybersecurity, Information Assurance or Information Security with 12+ years (or commensurate experience)
Required Skills and Experience
+ Ability to guide discussions, support CISO decisions with or without team support and effectuate positive cybersecurity changes at varying levels - users, developers, system admins, Directors, Managers and Executives where necessary. Typically, engagement is related to varying levels of technical system owner and "SOC" staff. Demonstrated experience as a SOC lead or Senior Team successfully engaging with managed security service providers (MSSP), Joint Cybersecurity external entities (e.g., CISA, CYBERCOM) on incident response (IR), weakness, incident handling (IH) and vulnerability management (VM), including mitigating actions to contain activity and facilitating forensics analysis when necessary.
+ Documented applied theory as SOC Manager or Team lead conducting and guiding in-depth evaluations of current INFOSEC/IT Security/Cybersecurity tactics, technics, and procedures, to include their effect on baseline configurations.
+ Demonstrated proficiency as a SOC manager or Senior Team lead providing cybersecurity hygiene and posture status, support debriefings and input in support of Governance, Risk, and Compliance (GRC) activities, and ongoing evolutions.
+ Provide network subscribers with incident response support, including mitigating actions to contain activity and facilitating forensics analysis when necessary.
+ Demonstrated experience as a SOC manager or Senior Team lead with expertise conducting and guide log-based and endpoint-based threat detection to detect and protect against threats coming from multiple sources.
+ Security implementation techniques and strategies in web services.
+ Solid understanding of securing web technology, Microsoft cloud (e.g., Azure, M365, etc.) security knowledge and demonstrable abilities.
+ Skilled security evaluation of complex web portals (e.g., Java, APIs, Ruby,; databases (i.e., SQL , Oracle) using commercial or open-source tools such as SQLmap, mongoaudit, etc.
+ Near Expert Web Application Attack and Audit Frameworks to include Security evaluation of applications and websites using commercial or open tools NMAP, W3af, etc.
+ Near Expert execution of a continuous monitoring and remediation program using commercial or open tools (i.e., Azure Security Center, Defender for Cloud, NMAP, Wireshark, Qualys)
+ Near Expert execution of an end-point detection and response (EDR) remediation program using commercial or open tools (i.e., HBSS, SEP, Defender)
+ Near Expert knowledge of and experience coordinating security operation center (SOC) principles, incident handling (IH), incident response (IR) as well as exploitation tactics, techniques, and procedures (TTP).
+ Facilitate the adoption of security best practices with functional teams (i.e., developers, database administrators, web application administrators) using technical knowledge and interpersonal skills.
Clearance Required: Must be able to acquire an EEOC Public Trust
Preferred Skills and Experience
+ Most Desirable Certification(s): CISSP, OSCP, GCIH, GPEN, GSEC, GSNA, GAWN, GCIA, GSE, GWEB, GPPN, GCED, GCID, CCSP, GCWN
**Posted Salary Range**
USD $185,000.00 - USD $200,000.00 /Yr.
**Company Overview**
GovCIO is a team of transformers--people who are passionate about transforming government IT. Every day, we make a positive impact by delivering innovative IT services and solutions that improve how government agencies operate and serve our citizens.
But we can't do it alone. We need great people to help us do great things - for our customers, our culture, and our ability to attract other great people. We are changing the face of government IT and building a workforce that fuels this mission. Are you ready to be a transformer?
**What You Can Expect**
**Interview & Hiring Process**
If you are selected to move forward through the process, here's what you can expect:
+ During the Interview Process
+ Virtual video interview conducted via video with the hiring manager and/or team
+ Camera must be on
+ A valid photo ID must be presented during each interview
+ During the Hiring Process
+ Enhanced Biometrics ID verification screening
+ Background check, to include:
+ Criminal history (past 7 years)
+ Verification of your highest level of education
+ Verification of your employment history (past 7 years), based on information provided in your application
**Employee Perks**
At GovCIO, we consistently hear that meaningful work and a collaborative team environment are two of the top reasons our employees enjoy working here. In addition, our employees have access to a range of perks and benefits to support their personal and professional well-being, beyond the standard company offered health benefits, including:
+ Employee Assistance Program (EAP)
+ Corporate Discounts
+ Learning & Development platform, to include certification preparation content
+ Training, Education and Certification Assistance*
+ Referral Bonus Program
+ Internal Mobility Program
+ Pet Insurance
+ Flexible Work Environment
*Available to full-time employees
Our employees' unique talents and contributions are the driving force behind our success in supporting our customers, which ultimately fuels the success of our company. Join us and be a part of a culture that invests in its people and prioritizes continuous enhancement of the employee experience.
**We are an Equal Opportunity Employer.** All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender, gender identity or expression, sexual orientation, national origin, disability, or status as a protected veteran. EOE, including disability/vets.
**Posted Pay Range**
The posted pay range, if referenced, reflects the range expected for this position at the commencement of employment, however, base pay offered may vary depending on multiple individualized factors, including market location, job-related knowledge, skills, education, experience, and internal equity. The total compensation package for this position may also include other compensation elements, to be discussed during the hiring process. If hired, employee will be in an "at-will position" and the GovCIO reserves the right to modify base salary (as well as any other discretionary payment or compensation program) at any time, including for reasons related to individual performance, GovCIO or individual department/team performance, and market factors.
Is this job a match or a miss?
Information Systems Security Officer - Cloud Security Specialist
Posted 6 days ago
Job Viewed
Job Description
INFORMATION SYSTMES SECURITY OFFICER - CLOUD SECURITY SPECIALIST (NAUT):
Bowhead seeks an Information Systems Security Officer (ISSO Cloud) to support our customer on the Nautical contract in the Arlington, VA area. This position ensures information systems security compliance and manages security controls for DoD cloud migration projects while coordinating security accreditation activities and maintaining ongoing security posture.
**Responsibilities**
- Implement and maintain security controls per NIST 800-53 and DoD standards for cloud-based systems
- Conduct comprehensive security assessments and vulnerability analyses on cloud infrastructure
- Manage security documentation and compliance reporting for continuous monitoring programs
- Coordinate with Authorizing Officials for system accreditation and Risk Management Framework (RMF) processes
- Monitor security incidents and coordinate response activities across cloud environments
- Maintain security awareness training programs and ensure personnel compliance with DoD security requirements
- Support continuous monitoring and security control assessments for cloud-based information systems
- Conduct vulnerability scans and recognize cloud-based vulnerabilities in security systems
- Utilize DoD network analysis tools to identify cloud-based vulnerabilities (e.g., ACAS, HBSS, etc.)
- Apply system, network, and OS hardening techniques for cloud environments
- Conduct cloud-based application vulnerability assessments and penetration testing
- Identify systemic security issues based on analysis of vulnerability and configuration data
- Apply cybersecurity and privacy principles to organizational requirements (confidentiality, integrity, availability, authentication, non-repudiation)
- Utilize Tenable Assured Compliance Assessment Solution (ACAS) for vulnerability management
- Manage Trellix Endpoint Security System (ESS), previously known as McAfee Host Based Security System (HBSS)
- Apply cloud-based access controls (access control lists, LDAP, Active Directory, etc.)
- Configure and maintain Virtual Private Network (VPN) devices and encryption protocols
- Troubleshoot and diagnose cyber defense infrastructure anomalies and work through resolution
- Perform impact/risk assessments for cloud security implementations
- Develop insights about the context of organizational threat environments to improve risk management posture
- Ensure complete understanding and implementation of NISPOM and ICD requirements
- Plan, schedule, and prioritize security activities to accomplish mission objectives
- Handle classified information according to proper procedures and security protocols
- Other duties as assigned
**Qualifications**
- Bachelor's degree in Cybersecurity, Information Systems, Information Technology, Computer Science, or related field from an ABET accredited or CAE designated institution or 10 years experience in leiu of this degree.
- Minimum of 16+ years of information security experience with demonstrated expertise in cloud security
- Minimum of 5+ years of DoD security experience in enterprise environments
- Minimum of 3+ years of hands-on experience with cloud security frameworks and implementations
- Complete understanding and experience implementing requirements of the NISPOM and ICDs
- Knowledge of cloud security principles and FedRAMP requirements
- Meets the Core and Additional Knowledge, Skills, and Abilities Tasks (KSATs) defined in the DoD Cyber Workforce Framework
- Demonstrated ability to develop solutions to complex security problems
- Proven ability to work in fast-paced, deadline-driven environments
- Excellent verbal and written communication skills for technical and executive audiences
- Recent experience with security management policies and procedures
- Proficiency with Microsoft Office Suite and security management tools
**CERTIFICATION REQUIREMENTS:**
Required: CISSP, CISM, or equivalent DoD Directive 8570 compliant certification; CompTIA SecurityDesired: GCIH, GSEC, CISSP, CISA, FITSP-M, GCSA, GISF, SSCP, CEH, or other advanced security certifications
Physical Demands
+ Must be able to lift 25 pounds on occasion.
+ Must be able to stand and walk for prolonged period amounts of time.
+ Must be able to twist, bend, and squat periodically.
SECURITY CLEARANCE REQUIREMENTS: Must be able to maintain a security clearance at the Top Secret level with SCI eligibility and maintain SAP eligibility. Due to work requirements, this position will not entertain work from home capabilities. US Citizenship is a requirement for this contract.
\#LI-KC1
Applicants may be subject to a pre-employment drug & alcohol screening and/or random drug screen, and must follow UIC's Non-DOT Drug & Alcohol Testing Program requirements. If the position requires, an applicant must pass a pre-employment criminal background history check. All post-secondary education listed on the applicant's resume/application may be subject to verification.
Where driving may be required or where a rental car must be obtained for business travel purposes, applicants must have a valid driver license for this position and will be subject to verification. In addition, the applicant must pass an in-house, online, driving course to be authorized to drive for company purposes.
UIC is an equal opportunity employer. We evaluate qualified applicants without regard to race, age, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, and other protected characteristics EOE/D/V. In furtherance, pursuant to The Alaska Native Claims Settlement Act 43 U.S.C. Sec. 1601 et seq., and federal contractual requirements, UIC and its subsidiaries may legally grant certain preference in employment opportunities to UIC Shareholders and their Descendants, based on the provisions contained within The Alaska Native Claims Settlement Act. Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities. Please view Equal Employment Opportunity postershere ( .
All candidates must apply online at , and submit a completed application for all positions they wish to be considered. Once the employment application has been completed and submitted, any changes to the application after submission may not be reviewed. Please contact a UIC HR Recruiter if you have made a significant change to your application. In accordance with the Americans with Disabilities Act of 1990 (ADA), persons unable to complete an online application should contact UIC Human Resources for assistance .
The contractor will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with the contractor's legal duty to furnish information. 41 CFR 60-1.35(c)
UIC Government Services (UICGS / Bowhead) provides innovative business solutions to federal and commercial customers in the areas of engineering, maintenance services, information technology, program support, logistics/base support, and procurement. Collectively, the fast-growing Bowhead Family of Companies offers a breadth of services which are performed with a focus on quality results. Headquartered in Springfield, VA, we are a fast-growing, multi-million-dollar company recognized as a top Alaska Native Corporation providing services across the Department of Defense and many federal agencies. Bowhead offers competitive benefits including medical, dental, vision, life insurance, accidental death and dismemberment, short/long-term disability, and 401(k) retirement plans as well as a paid time off programs for eligible full-time employees. Eligible part-time employees are able to participate in the 401(k) retirement plans and state or contract required paid time off programs.
**Join our Talent Community!**
Join our Talent Community ( to receive updates on new opportunities and future events.
Software Powered by ICIMS ( _ _
**Category** _Engineering_
**Location : Location** _US-VA-Arlington_
**Clearance Level Must Be Able to Obtain** _Top Secret/SCI_
**Minimum Clearance Required** _Secret_
**Travel Requirement** _N/A_
Is this job a match or a miss?
Senior Cloud Security Specialist(API)
Posted 3 days ago
Job Viewed
Job Description
Contract Performance Period
June 1, 2026 - December 31, 2026
Job LocationWashington, DC location(s) (Metro Access) on‑site 5 days/week.
Direct HireTerm: through 31/12/2026, with a strong possibility of extension
Pay RangeDepending on Experience
Travel RequirementsWashington, DC location(s) (Metro Access) on‑site 5 days/week.
Working RemotelyNot possible
Project DescriptionSenior Cloud Security Specialist (API) — supporting an IT Security Engineering team responsible for the strategy, design, deployment, and maintenance of effective security solutions in cloud, local, and hybrid environments. This role supports a data access management project and requires proficiency in REST API integrations, providing hands‑on API integration support between cloud applications using modern and secure techniques. Anticipated Period of Performance: 06/01/2026 – 12/31/2026 (strong possibility of extension) Place of Performance: on‑site, Washington, DC U.S. Citizenship required.
Qualification Requirements- Extensive REST API experience in implementing, securing, automating, testing, and documenting API integrations
- Strong understanding of resilient integration patterns including error handling, retry mechanisms, and monitoring strategies
- Demonstrated federal experience and comprehensive knowledge in adopting and implementing federal cybersecurity requirements, including the NIST Cybersecurity Framework, OMB Memorandum M-22-09, and NIST SP 800-53
- Deep analytical, problem‑solving, and troubleshooting experience to independently resolve complex security challenges
- Proven ability to provide technical security consultation and advisory services
- Preferred: AWS Certified Security – Specialty (strongly preferred); AWS Certified Solutions Architect – Professional or Associate
- Preferred: Experience with integrations between ServiceNow, Collibra, and Saviynt
- Proficiency in scripting and automation languages for security orchestration
- Experience implementing cloud‑native serverless architectures and services
- Experience architecting and implementing security controls across public cloud platforms
- Experience implementing DevSecOps practices including CI/CD pipelines and infrastructure as code
- Experience implementing cloud access security broker (CASB) solutions for SaaS application security and visibility
- Strong understanding of IAM, network security design, security operations, security architecture, cloud security, data loss protection, zero trust, DevSecOps, and vulnerability management
- Build resilient, secure API integrations between cloud applications in support of an end‑to‑end data access management solution
- Produce API integration architecture documentation detailing integrations between cloud systems
- Develop data models and attribute mapping across cloud systems
- Write automation scripts and orchestration components (serverless functions, scheduled jobs, event handlers)
- Conduct comprehensive testing and documentation of cloud integrations
- Support data loss prevention and cloud access security broker initiatives
- Work across multiple teams as a Cloud Security Engineer SME to support security design, build, implementation, and monitoring of cloud platforms, applications, and tools
- Offer technical consultation to cloud engineering teams on secure implementations
- Create or update security configuration guides and playbooks
1535
#J-18808-LjbffrIs this job a match or a miss?
Note: If you’re asked to pay for a job, avoid the role and report the job to us immediately.
Job Description
Our client, a dynamic technology solutions provider located in Phoenix, Arizona , is seeking a dedicated Cloud Security Specialist to join their growing team. This role is central to ensuring the security and integrity of their cloud infrastructure, encompassing platforms like AWS, Azure, and GCP. The ideal candidate will have a deep understanding of cloud security best practices, threat landscapes specific to cloud environments, and experience implementing and managing cloud-native security controls. You will play a key role in protecting our client's cloud assets, ensuring compliance, and architecting secure cloud solutions. This is an excellent opportunity to specialize in a high-demand area of cybersecurity and contribute to the secure deployment of innovative cloud services.
Key Responsibilities- Design, implement, and manage security controls and solutions for cloud environments (AWS, Azure, GCP).
- Develop and enforce cloud security policies, standards, and best practices.
- Monitor cloud infrastructure for security threats, vulnerabilities, and misconfigurations.
- Respond to cloud security incidents, conduct investigations, and implement remediation measures.
- Collaborate with DevOps and engineering teams to integrate security into CI/CD pipelines.
- Conduct security assessments and audits of cloud environments.
- Manage identity and access management (IAM) for cloud resources.
- Stay up-to-date with the latest cloud security trends, tools, and threats.
- Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent experience.
- 3-5 years of experience in cybersecurity, with a strong focus on cloud security.
- Hands-on experience securing major cloud platforms such as AWS, Azure, or Google Cloud Platform.
- Proficiency with cloud security tools and services (e.g., security groups, IAM, WAF, cloud-native security monitoring).
- Understanding of containerization technologies (e.g., Docker, Kubernetes) and their security implications.
- Familiarity with infrastructure-as-code (IaC) tools (e.g., Terraform, CloudFormation) and their security aspects.
- Knowledge of relevant compliance frameworks (e.g., SOC 2, ISO 27001) as they apply to cloud environments.
- Strong analytical, problem-solving, and communication skills.
- Competitive annual salary with performance-based bonuses.
- Comprehensive health, dental, and vision insurance plans.
- Generous paid time off and holiday schedule.
- Retirement savings plan with employer match.
- Opportunities for professional growth, certifications, and skill development.
- Exposure to leading-edge cloud technologies and security solutions.
- Fully remote work arrangement, offering significant flexibility and autonomy.
- A stimulating and collaborative work environment in the growing tech scene of Phoenix, Arizona .
Is this job a match or a miss?
Network Security Engineer — Threat & Cloud Security Specialist
Posted 3 days ago
Job Viewed
Job Description
Riverside Health System in Newport News, Virginia, seeks a Network Security Engineer I to design, implement, and maintain robust network security solutions using leading technologies. The role conducts vulnerability scans and threat assessments, and oversees host-based security such as antivirus, HIPS, and DLP to protect data and systems.
The engineer will work with management and technical staff to define requirements for security infrastructure, ensuring maximum uptime for Firewalls, VPNs, and
#J-18808-LjbffrIs this job a match or a miss?
Note: If you’re asked to pay for a job, avoid the role and report the job to us immediately.
Senior Cloud Security Specialist
Posted 3 days ago
Job Viewed
Job Description
- 40 Water Street - 40 Water Street Boston, Massachusetts 02109 United States
- Leveraging cybersecurity fundamentals, you will possess a strong understanding of cybersecurity principles, threat landscape, risk management and compliance requirements (such as GDPR, HIPPA, PCI DSS)
- Security Architecture Design: Proficiency in designing secure cloud architectures, including network security, identity and access management (IAM), data protection, encryption, and secure application development practices.
- Network Security: Expertise in designing secure cloud network architectures including VPCs, virtual network segmentation, network security groups (NSGs), Cloud Firewalls, VPN gateways, IDS/IPS, and DDoS protection.
- Data Security and Encryption: Knowledge of data protection techniques such as encryption, data masking, tokenization, and data loss prevention (DLP) Identity and Access Management (IAM)
- Compliance and Governance: Understanding of regulatory compliance requirements and best practices for ensuring Cloud environments meet industry standards and regulatory mandates. This may include knowledge of Azure Policy, Azure Blueprints, GCP Security Command Center, AWS Compliance Center and other compliance assessment tools.
- Experience with multiple cloud service providers (AWS, GCP, Azure) with deep knowledge in at least one major Cloud service provider
- Fundamental understanding of security in cloud and how it differs from on-premise
- Extensive hands-on experience in Terraform and CI/CD processes and an understanding of DevSecOps pipelines/workflows
- Experience in working in a highly regulated environment such as banking, financial services or government (regional/network borders etc.)
- Bachelor s degree in computer science, Information Systems or related course of study required or equivalent work experience. Related master s degree a plus
- Security certifications in (CISSP, GIAC, Security+)
Benefits of Working Here
- An inclusive workplace that promotes diversity and collaboration.
- Access to ongoing learning and development opportunities.
- Competitive compensation and benefits package.
- Flexibility to support work-life balance.
- Comprehensive health benefits for you and your family.
- Generous paid leave and holidays.
- Wellness program and employee assistance.
Pay Range: $160,000 - $215,000
The range shown represents a grouping of relevant ranges currently in use at Publicis Sapient. Actual range for this position may differ, depending on location and specific skillset required for the work itself.
As part of our dedication to an inclusive and diverse workforce, Publicis Sapient is committed to Equal Employment Opportunity without regard for race, color, national origin, ethnicity, gender, protected veteran status, disability, sexual orientation, gender identity, or religion. We are also committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans in our job application procedures. If you need assistance or an accommodation due to a disability, you may contact us at
Your information will be kept confidential according to EEO guidelines.
Company DescriptionPublicis Sapient is a digital transformation partner helping established organizations get to their future, digitally-enabled state, both in the way they work and the way they serve their customers. We help unlock value through a start-up mindset and modern methods, fusing strategy, consulting and customer experience with agile engineering and problem-solving creativity. United by our core values and our purpose of helping people thrive in the brave pursuit of next, our 20,000+ people in 53 offices around the world combine experience across technology, data sciences, consulting and customer obsession to accelerate our clients’ businesses through designing the products and services their customers truly value.
Looking for the latest openings or want to get rewarded for recommending a peer?
#J-18808-LjbffrIs this job a match or a miss?
Note: If you’re asked to pay for a job, avoid the role and report the job to us immediately.