For Employers

OneZero Solutions

Cyber Security Engineer – Senior / Cloud DoS CSS

Posted 5 days ago
10+ years experience
Apply Now

Please mention DailyRemote when applying

?
Resume Match Score

See how much of this job your resume covers, and what’s missing.

Want a recruiter to go through it line by line?

Get professional review

Create a cover letter for this job

Upload your resume and we draft a letter for this exact role, tailored to what it asks for.

  • Tailored to this role
  • Based on your resume
  • Fully editable
AI Summary

The engineer will own cloud security engineering for hybrid authorization boundaries, including operating the Wiz platform and applying zero-trust overlays. They are responsible for maintaining security evidence, performing vulnerability scans, and ensuring compliance with federal standards.

We are an employee-centric company that truly values our team members and the contributions they make to our customers and the missions they support. We pride ourselves on being forward-leaning thinkers and on building teams that are, and continue to be, technically proficient across a broad range of cyber mission areas. OneZero full-time employees receive a highly competitive benefits package, including health, dental, vision, and life insurance, a 401(k) with company matching, paid time off and holidays, an employee referral program, and educational assistance. Additional details are available on our website: https://www.onezerollc.com/careers/ 

Position Title: Cyber Security Engineer – Senior / Cloud

Location: Remote; must reside within the National Capital Region (NCR).

Clearance: Secret

Work Schedule: Full-time, 40 hours per week. Must be available during Department core hours of 9:00 a.m. – 3:00 p.m. ET, Monday – Friday, and flex working hours as needed to meet CST day-to-day and emergent requirements. No work is performed on Federal holidays or during Government closures. Participates in a rotating on-call schedule supporting 24x7x365 availability of the vulnerability and compliance scanning platforms.

Employment Type: Full-Time, Exempt (W-2), contingent upon Call Order award

Position Summary

The Senior Cloud Security Engineer owns cloud security engineering for DT/EA/CST's cloud-based and hybrid authorization boundaries. The engineer operates and extends the Wiz cloud security platform, applies Department cloud and zero-trust overlays, documents controls inherited from cloud service providers and DT enterprise services, supports cryptographic key management activities, and produces the cloud evidence the ISSO team needs to obtain and maintain ATOs.

Key Responsibilities

  • Engineer, operate, and maintain the Wiz platform for cloud-based consular systems: account/subscription onboarding, asset grouping and tagging per CA configuration standards, policy tuning, integrations, and dashboards.
  • Support agent deployment, vulnerability and compliance scanning, data ingest and sharing, pipeline, and other integration efforts for cloud workloads.
  • Apply Department and CA cloud-security and zero-trust overlays; identify and document controls inherited from CSPs and DT enterprise services in each system's Inherited Controls Matrix and SSP(RMF Step 2).
  • Support cryptographic key management and encryption key lifecycle activities for cloud and hybrid systems.
  • Develop and maintain cloud architecture, network, and data-flow diagrams and evidence for System Boundary & Data Flow Packages and the Evidence Index(RMF Steps 1 and 3).
  • Review cloud vulnerability and compliance scan results within 5 business days of scan completion; drive critical and high findings to closure within Department and BOD timelines; provide closure evidence to ISSOs for POA&M management(RMF Step 6).
  • Perform Security Impact Analysis on cloud infrastructure and configuration changes submitted through CA change management; participate in CCB/ECM.
  • Demonstrate cloud control implementations during Security Control Review Meetings and provide screenshots, logs, and configuration evidence to the SCA(RMF Step 4).
  • Support infrastructure-as-code and container image security checks in DevSecOps pipelines and ensure results are captured as SSP evidence(RMF Step 3).
  • Coordinate with cloud system operations teams and CSPs to validate remediation and maintain the accredited security posture of cloud systems.

Required Qualifications

  • Eight (8)+ years of cybersecurity or systems engineering experience, including three (3)+ years securing federal workloads in AWS GovCloud, Azure Government, or equivalent.
  • Hands-on experience with a CNAPP/CSPM platform (Wiz strongly preferred; Prisma Cloud, Defender for Cloud, or equivalent considered).
  • Working knowledge of NIST SP 800-53 Rev. 5 control implementation in cloud environments and FedRAMP inheritance models.
  • Active, final SECRET security clearance; U.S. citizenship.
  • DoD 8140/8570 IAT Level III or IAM Level II baseline certification (e.g., CISSP, CASP+, CCSP, CISM) or ability to obtain within 6 months.
  • Experience producing authorization evidence (diagrams, configuration exports, scan reports) for ISSOs and assessors.

Preferred Qualifications

  • CCSP, AWS Certified Security – Specialty, or Azure Security Engineer Associate; Wiz certification.
  • Department of State or other federal civilian cloud authorization experience.
  • Experience with Terraform/CloudFormation security, Kubernetes/container security, and CI/CD pipeline integration.
  • Experience with cryptographic key management services (AWS KMS, Azure Key Vault, HSMs) and FIPS 140-2/140-3 validated modules.

Technical Skills

  • Wiz (or comparable CNAPP), AWS/Azure native security services, IAM, logging/monitoring, KMS/Key Vault.
  • Tenable integration for hybrid boundaries; STIG/CIS benchmarks for cloud OS and services.
  • Infrastructure-as-code (Terraform, CloudFormation, Bicep), containers/Kubernetes, CI/CD tooling.
  • NIST SP 800-53 Rev. 5, 800-144/145/210 cloud guidance, FedRAMP, zero-trust architecture (NIST SP 800-207).
  • Scripting (Python, PowerShell, Bash) and REST API automation; Visio diagramming.

Education

Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field, or an additional four (4) years of directly relevant experience in lieu of degree.

Remote/Hybrid/On-site and any other relevant work-environment requirement

Remote. Duties are performed remotely; the selected candidate must reside within the National Capital Region (NCR). The Government does not furnish equipment; OneZero provides the laptop and collaboration tools. Position requires an OpenNet account, DoS PIV badge, multifactor authentication, and adherence to DoS SBU/CUI handling requirements. Local travel within the National Capital Region; minimal other travel.

Position Status:

New Position, contingent upon Call Order award

OneZero Solutions LLC is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or protected veteran status.

Automatically Apply to the Best Remote Jobs

Stop the endless job search. Our AI finds and applies to the best jobs for you.

Try it Now
Keep looking

Similar Jobs

See all Remote Software Development jobs →

Full Stack Engineer - Austin, TX (WFH)

Full Time United States Software Development

Field Service Engineer, AMS

Full Time United States Software Development

Senior AI Inference Engineer

Full Time United States Software Development

Data Engineer (Python, PySpark & Databricks)

Full Time Colombia Software Development

Technical Co-Founder

Full Time Germany Software Development

RPA Developer

Full Time United States Software Development
Apply Now

Personalize your Remote Job Search in 3 Easy Steps!

Featuring 219,313+ Jobs in Security Engineer

Answer easy questions

Answer easy questions

219,313+ jobs across 15+ categories

Get your best job matches

Get your best job matches

Only hand-screened, legit jobs

Find a remote job faster

Find a remote job faster

No ads, scams, or junk

“I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”

Sarah J. — Sarah J. · Marketing Manager ★★★★★ Verified