- Company Name
- LightFeather
- Job Title
- Cloud DevSecOps Engineer
- Job Description
-
Job title: Cloud DevSecOps Engineer
Role Summary: Design, implement, and secure multi‑cloud infrastructures (AWS, Azure, GCP, GovCloud, DoD IL6) using DevSecOps principles. Drive automation, compliance, and threat‑modeling across enterprise platforms to ensure secure delivery pipelines and secure environments at scale.
Expectations:
- Deliver secure, compliant cloud architecture for commercial, GovCloud, and DoD IL6 environments.
- Embed security controls across all development stages and infrastructure.
- Lead cross‑functional initiatives with architects, compliance, and engineering teams.
- Maintain continuous compliance and readiness for ATO, NIST 800‑53, FedRAMP, CIS, and DoD standards.
Key Responsibilities:
- Architect and enforce security baselines (CIS, NIST 800‑53, FedRAMP) across AWS, Azure, GCP, and restricted clouds.
- Drive threat‑modeling, secure‑design reviews, and architecture reviews.
- Build and maintain Terraform IaC modules enforcing security policies at scale.
- Integrate CI/CD pipelines with automated SAST, DAST, IaC scanning, and container security tools.
- Develop and refine guardrails, remediation pipelines, and policy enforcement.
- Support ATO compliance by embedding controls into build processes and leading assessments.
- Implement centralized logging, monitoring, and incident response across multi‑cloud environments.
- Mentor and guide security and platform engineering teams on secure development practices.
- Act as subject matter expert in cloud security, providing guidance to stakeholders and architects.
Required Skills:
- 5+ years cloud security experience in AWS, Azure, GCP (and optionally GovCloud, DoD IL6).
- Advanced Terraform, CloudFormation, ARM/ Bicep, and IaC expertise.
- Proficient in GitLab, GitHub Actions, or equivalent CI/CD systems.
- Strong programming/scripting skills (Python, Go, PowerShell, Bash).
- Deep understanding of IAM/RBAC, KMS/Key Vault, networking, encryption.
- Familiarity with native cloud security services (AWS Security Hub, GuardDuty; Azure Defender; Google SCC).
- Knowledge of OWASP ASVS/Top 10, NIST 800‑53, FedRAMP, CIS Benchmarks.
- Proven track record embedding security into Agile/DevSecOps pipelines.
- Excellent communication, leadership, and stakeholder management.
Required Education & Certifications:
- Bachelor’s degree in Computer Science or related technical field (or equivalent experience).
- Certifications: AWS Certified Security – Specialty, Azure Security Engineer Associate, Google Professional Cloud Security Engineer, OSCP, CISSP (preferred).
Alexandria, United states
On site
Mid level
17-12-2025