SAIC

Cybersecurity Engineer - Cloud

SAIC Colorado Springs, Colorado, United States

Defense and Space Manufacturing · 10,001+ employees

5 h ago
security Senior (5-10 yrs) Full-time United States
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The Cybersecurity Engineer secures and accredits multi-tenant cloud environments by implementing JSIG, NIST, and STIG baselines. They are responsible for developing RMF/ATO packages and validating cyber artifacts to ensure mission readiness.

What they look for

Cybersecurity Cloud Security RMF ATO STIG NIST SP 800-53 JSIG DevSecOps Terraform Ansible Helm ACAS Nessus SAST DAST

Requirements

Candidates must have a Bachelor's degree and at least nine years of experience, or equivalent advanced degrees with corresponding experience. Required certifications include DoD 8140 aligned credentials such as CISSP, CCSP, or CASP+.

Full description

SAIC is a trusted leader in delivering advanced command and control capabilities across the Department of the Air Force. We bring deep expertise in engineering, securing, and deploying cutting-edge technologies that support mission-critical operations. In partnership with the Assistant Secretary of the Air Force for Acquisition, Technology, and Logistics, SAIC supports programs that unify data, sensors, mission applications, cloud-based services, and emerging AI-enabled automation. These efforts empower warfighters with a decisive edge, transforming complex, multidomain information into fast, clear, and actionable decisions when it matters most. As part of this team, you will help accelerate the integration, testing, security, and transition of new capabilities into operational use. You will work side by side with operators, engineers, Capability Providers, and government teams to ensure every delivery strengthens mission readiness. This role offers the opportunity to directly shape how the Air Force sees, decides, and acts across all domains—making a tangible and immediate impact on warfighter effectiveness. The Cybersecurity Engineer (Cloud) secures and accredits multi tenant cloud environments (Dev, Integration, Test). The role implements JSIG/NIST/STIG baselines, engineers secure multi classification cloud designs, validates Capability Provider and External cyber artifacts, and ensures all required evidence is provided to the Infrastructure TO for Baseline updates. The Cybersecurity Engineer (Cloud) develops RMF/ATO packages for cloud environments, partners closely with DSOP, Platform, CE, and Cloud SMEs, and contributes hands on effort to early DSOP/cloud design and environment build out. Job Duties include:

  • Build and secure multi‑tenant cloud environments.
  • Implement JSIG, NIST SP 800‑53, STIG, and MLS/MILS baselines across Dev/Integration/Test cloud enclaves.
  • Own RMF/ATO packages for cloud environments, producing SSP, POA&M, and full RMF evidence.
  • Validate STIG, ACAS/Nessus, SAST/DAST, and container‑security outputs prior to environment promotion.
  • Perform functional validation of CP/External cyber artifacts; coordinate delivery of validated evidence to Infrastructure TO.
  • Maintain cloud‑aligned continuous monitoring, including audit logs, cloud telemetry, and Prometheus/Grafana security metrics.
  • Support Cloud + DSOP joint early design efforts; collaborate to integrate pipeline‑aware cloud security.
  • Validate IaC/CaC baselines (Terraform, Ansible, Helm) for secure, consistent cloud deployments and promotion gates.
  • Provide cyber recommendations during CCB promotion evaluations.
  • Offer WHY‑based guidance and vector checks to Capability Providers and team members.

Qualifications

Required Qualifications & Experience:

  • Bachelors and nine (9) years or more experience; Masters and seven (7) years or more experience ; PhD or JD and four (4) years or more experience.
  • Proven experience securing multi classification cloud environments.
  • Hands on experience performing STIG review/hardening, validating ACAS/Nessus outputs, and adjudicating SAST/DAST results.
  • Experience maintaining RMF/ATO artifacts (SSP, POA&M, continuous monitoring evidence).
  • Familiarity with Jira/Xacta workflows for RMF and vulnerability tracking.
  • DoD 8140 aligned certifications: CISSP, CCSP, CASP+, or equivalent.

Desired Qualifications and Experience:

  • Experience architecting and securing hybrid cloud and MLS/MILS cross domain environments.
  • Prior support to SCA assessments (finding remediation, documentation, assessor coordination).
  • Knowledge of secure DevSecOps pipeline integration, including image signing, SBOM/SCA, and environment gate validation.

Desired Skills and Certifications:

  • Experience with advanced cyber assessment, scanning, and STIG automation tools.
  • Experience with cloud IaC/CaC security tooling (Terraform, Ansible, Helm, Argo CD).
  • Familiarity with Zero Trust architecture, container hardening, and cloud security automation platforms.
  • Strong documentation and communication skills aligned with RMF evidence and CMCC governance.

SAIC® is a premier mission integrator focused on advancing the power of technology and innovation to serve and protect our world. Our robust portfolio of offerings across the defense, space, intelligence, and civilian markets includes secure high-end solutions in mission IT, enterprise IT, engineering services, and professional services. We integrate emerging technology, rapidly and securely, into mission critical operations that modernize and enable critical national imperatives.

We are approximately 23,000 strong; driven by mission, united by purpose, and inspired by opportunities. SAIC is an Equal Opportunity Employer. Headquartered in Reston, Virginia, SAIC has annual revenues of approximately $7.3 billion. For more information, visit saic.com. For ongoing news, please visit our newsroom.

Similar roles