Cloud Security Engineer (Secret Clearance)
Job Description
This Cloud Security Engineer role focuses on designing, implementing, and strengthening security controls across AWS, GCP, and Azure, while supporting cloud security architecture, engineering, monitoring, and risk reduction. The position is based onsite in Baltimore, MD, and requires local residency in the DMV area with the ability to work onsite up to five days per week, along with an active Secret clearance.
Responsibilities
- Evaluate cloud environments across AWS, GCP, and Azure to identify security risks, control gaps, and configuration issues.
- Design, implement, and refine cloud security controls, including identity and access management, network security, encryption, logging, and monitoring.
- Support cloud security architecture reviews for new and existing solutions and provide recommendations aligned to security and compliance requirements.
- Investigate cloud security events and findings, analyze root causes, and support remediation activities with engineering and operations teams.
- Develop and maintain technical documentation, standards, baselines, and reports related to cloud security controls and cloud risk management.
Requirements
- Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a similar technical field
- Active Secret Clearance
- Local to the DMV area and able to work onsite up to 5 days a week
- Travel approximately 20% depending on client needs
- 2+ years of experience in cloud security, cloud engineering, or cloud infrastructure
- Experience implementing or assessing security controls in AWS, GCP, and Azure
- Experience with cloud identity and access management, network security, encryption, logging, monitoring, and configuration management
- Experience using cloud-native security tools, security posture management tools, or infrastructure as code tools
- Must be legally authorized to work in the United States without employer sponsorship now or in the future
Technologies
- AWS, Google Cloud Platform (GCP), Microsoft Azure
- Cloud-native security tools, security posture management tools, infrastructure as code tools
- Terraform, Python, PowerShell, Bash
- Kubernetes
- NIST, CIS, ISO
Benefits
- Discretionary annual incentive program
The Team
Deloitte's Government & Public Services (GPS) practice delivers impact through people, ideas, technology, and outcomes. The team serves federal, state, and local government clients as well as public higher education institutions, bringing fresh perspectives to anticipate disruption and fulfill mission promises. The Enterprise Security offering embeds security across digital transformation, securing a client’s technical backbone while enabling secure innovation.