The Cloud ISSE will design and maintain secure AWS cloud architectures while ensuring compliance with Federal Government standards and the Risk Management Framework. They will manage authorization processes, conduct security assessments, and collaborate with engineering teams to integrate DevSecOps practices.
Position Overview
LATG is seeking a Cloud Information Systems Security Engineer (ISSE) to join our AWS-based cloud operations team. This role will focus on developing and maintaining secure cloud architectures, ensuring compliance with Federal Government standards, and managing risk across the cloud system lifecycle. The Cloud ISSE will work closely with engineers and analysts to support authorizations, strengthen defenses, and streamline cybersecurity processes in a dynamic cloud environment.
Key Responsibilities
Design and maintain cybersecurity architecture for AWS cloud environments, ensuring alignment with Federal Government standards and the Risk Management Framework (RMF).
Lead the development and upkeep of authorization artifacts, including System Security Plans (SSPs), Security Assessment Reports (SARs), and Plans of Action and Milestones (POAMs), within eMASS.
Conduct security assessments, vulnerability scans, and technical testing using tools such as ACAS, STIGs, and AWS-native security services.
Manage Authorization to Operate (ATO) processes and compliance activities across IaaS, PaaS, and SaaS models.
Collaborate with cloud engineering teams to integrate secure Infrastructure-as-Code (IaC) and DevSecOps practices.
Utilize AWS Security Hub, GuardDuty, CloudWatch, CloudTrail, and Splunk for monitoring, log analysis, and incident response.
Provide technical guidance on interpreting ACAS/STIG results and ensure compliance with security baselines.
Support audits, inspections, and risk assessments by delivering documentation and remediation strategies.
Continuously improve cybersecurity processes, tools, and documentation to maintain audit readiness and enhance security posture.
Required Qualifications
Active SECRET Security Clearance.
DoD 8570 IAM Level II certification (e.g., CISSP, CAP, or Security+ CE).
Minimum of 4 years of cybersecurity experience, with 2+ years in cloud security (AWS preferred).
Expertise in RMF, eMASS artifact development, and NIST 800-53 control assessments.
Proficiency with AWS cloud security tools (Security Hub, GuardDuty, CloudWatch, CloudTrail) and Splunk.
Experience with ACAS scanning, STIG compliance, and vulnerability management tools (Trellix, Invicti, Anchore).
Familiarity with Infrastructure-as-Code (Terraform, Bicep) and DevSecOps integration.
Strong communication, problem-solving, and documentation skills.
“I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”