GovCIO LLC seeks a Sr. Cyber/Cloud Security Specialist to secure mission-critical federal IT and cloud environments. You will design and implement cloud security architectures across AWS/Azure, harden workloads, and integrate zero-trust and identity controls. Responsibilities include security engineering, IaC-based guardrails, vulnerability and compliance management (NIST, FedRAMP), incident response, and automation with DevSecOps toolchains. In GovCIO's mission-driven, collaborative culture, you'll mentor engineers, engage with stakeholders, and support high-impact government modernization programs.
Responsibilities
- Design and implement secure cloud architectures in AWS and/or Azure for federal systems.
- Define and enforce cloud security standards, baselines, and guardrails using Ia
- C tools (e.g., Terraform, Cloud
- Formation).
- Implement and manage identity, access management, and zero-trust controls across environments.
- Conduct threat modeling, security reviews, and security impact assessments for new and existing services.
- Lead vulnerability management and remediation across cloud workloads and platforms.
- Configure and tune cloud-native and third party security tools (CSPM, CWPP, SIEM, EDR) for continuous monitoring.
- Support and lead security incident response, forensics, and root-cause analysis for cloud events.
- Ensure compliance with NIST, Fed
- RAMP, and related federal cybersecurity policies and frameworks.
- Collaborate with Dev
- Ops teams to embed security into CI/CD pipelines and automate security controls.
- Mentor junior engineers and advise stakeholders on cyber/cloud security best practices and risk posture.
Required Skills
- Cloud security architecture (AWS, Azure)
- Identity and access management (IAM, SSO, RBAC)
- Zero Trust security principles
- Infrastructure as Code (Terraform, Cloud
- Formation, ARM/Bicep)
- Vulnerability management and remediation
- Security monitoring and SIEM (e.g., Splunk, Sentinel, Cloud
- Trail/Cloud
- Watch)
- Incident response and digital forensics
- NIST, Fed
- RAMP, RMF compliance
- Dev
- Sec
- Ops and CI/CD security integration
- Network and application security (WAF, VPN, microsegmentation)