ECS Tech Inc

AWS Cloud / Security Engineer

ECS Tech Inc · Stafford, Virginia, United States · $100K–$120K/yr

IT Services and IT Consulting · 11-50 employees

5 h ago
Mid (2-5 yrs) Full-time United States
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The AWS Cloud Security Engineer will design, build, and maintain secure cloud infrastructure for mission-critical FBI applications. Responsibilities include implementing NIST security controls, managing IAM policies, and collaborating with development teams to ensure environment stability.

What they look for

AWS Cloud Security Infrastructure as Code CloudFormation IAM VPC Kubernetes NIST SP 800-53 Risk Management Framework Security+ System Administration PowerShell Bash Git Troubleshooting Network Security

Requirements

Candidates must possess an active Secret clearance and hands-on experience with AWS infrastructure and security hardening. Proficiency in scripting languages, familiarity with NIST SP 800-53 controls, and experience with Kubernetes are required.

Full description

Everforth ECS is seeking a AWS Cloud Security Engineer to work in our Stafford, VA (hybrid) office.

 

The ECS Team provides focused Agile software development and maintenance for CODIS, a mission-critical application for the FBI. CODIS supports a database repository of DNA profiles from individuals, unsolved crime scene evidence, and missing persons. CODIS software allows local, state, and national laboratories to compare DNA profiles electronically, thereby linking serial crimes to each other and identifying suspects by matching DNA profiles from crime scenes to individuals’ profiles.

 

Responsibilities:

  • Work in the Security & Infrastructure team for cloud-based development in AWS
  • Design, build, and maintain AWS infrastructure supporting CODIS development ,test  , pre-prod and prod environments, including EC2, IAM, VPC networking, security groups, and AMI lifecycle management.
  • Provision and manage infrastructure through code using CloudFormation.
  • Partner with the CODIS development and infrastructure teams to keep Dev and Test environments stable, current, and available to the sprint teams.
  • Occasional need for off-hours support for system upgrades, patches and maintenance activities
  • Implement and validate security settings across cloud infrastructure, operating system baselines, and application platforms.
  • Provide AWS network and security support, including subnet and routing design, security group and NACL configuration, encryption in transit and at rest, KMS key management, and enterprise certificate and TLS trust management.
  • Design and maintain least privilege IAM roles and policies, and remediate findings from IAM Access Analyzer, Security Hub, GuardDuty, and Config.
  • Implement NIST SP 800-53 security controls in the cloud environment and document how each is satisfied, working within the NIST Risk Management Framework.
  • Contribute technical content to ATO packages, including System Security Plan (SSP) narratives, control implementation statements, diagrams, and inventory artifacts.
  • Support security assessments by producing evidence on request, responding to assessor questions, and driving Plan of Action and Milestones (POA&M) items to closure.
  • Participate in Agile ceremonies, refine infrastructure and security stories, and provide realistic estimates to the sprint team.
  • Troubleshoot environment and pipeline issues with precision, and document root cause and resolution so the fix is repeatable.

Salary Range: $100,000-$120,000

General Description of Benefits

Qualifications

  • Active Secret clearance
  • Demonstrated hands-on AWS experience administering EC2, IAM, VPC, and AMIs
  • Practical experience implementing security settings and hardening across cloud and operating system layers.
  • Working familiarity with NIST SP 800-53 controls and the RMF or ATO process, including contributing to security documentation, assessment evidence, or POA&M remediation on an accredited system.
  • Experience working with Kubernetes and container images
  • Experience using or managing Git-based version control across multiple projects
  • Current Security+ certification or the ability to obtain within 6 months
  • System Administration experience
  • Strong attention to detail and solid troubleshooting ability
  • Proficiency in scripting language(s), PowerShell or bash preferred
  • Experience with security settings implementation