Job Closed

This listing is no longer active.

Tetrad Digital Integrity logo
Tetrad Digital Integrity

Tetrad Digital Integrity (TDI) is a cybersecurity firm built for high-consequence environments where mission, complexity, and trust intersect. Our single focus has been delivering cyber solutions to effectively manage risk & the business of cyber for 25 years! TDI does business with the federal government, which restricts employment to individuals who are either US citizens or lawful permanent residents of the United States. TDI is an Equal Opportunity Employer. Employment decisions are made based on individual qualifications, merit, and business needs. We do not discriminate in employment opportunities or practices based on race, color, religion, sex, or national origin, in accordance with applicable federal laws.

Cloud Security Engineer

Location

United States

Posted

126 days ago

Salary

0

Seniority

Mid Level

Job Description

Cloud Security Engineer

Tetrad Digital Integrity

This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description TDI is hiring an exceptional DoW Cloud Security Engineer to strengthen the security engineering posture of a mission-critical, cloud-hosted defense system treated as a high-value target. This is a high-visibility engagement with frequent change, heavy stakeholder involvement, and a system operating under elevated adversary interest. This is not a “watch-the-console” role. We need a hands-on engineer who can build and mature cloud security telemetry, logging pipelines, detections, and automation, enabling faster, higher-confidence response by the CSSP while measurably improving the system’s defensibility. - Comply with currently mandated national and DoD-approved policies, directives, architectures, programs, standards, and guidelines. - Design, implement, and sustain security telemetry/logging architecture in GCP, ensuring high-fidelity signals are collected, normalized, and delivered to the VDSS/SIEM/SOAR stack. - Own logging coverage and quality for cloud and platform signals, including: - Cloud Audit Logs (Admin Activity, Data Access, System Event) - IAM/service account activity and privileged actions - VPC Flow Logs, load balancer/WAF/proxy signals - GKE audit logs and Kubernetes control-plane events - Security-relevant application/service logs - Build detection engineering content: queries, correlation logic, alert rules, and dashboards aligned to cloud threat scenarios (IAM abuse, suspicious API usage, workload compromise, data access anomalies, lateral movement paths). - Develop automation and guardrails to reduce toil and accelerate investigations/response: - API-driven enrichment and evidence capture (e.g., asset inventory, IAM bindings, network path/context, log exports) - Repeatable runbooks/workflows and integration into ticketing/notification pipelines - Partner with teams to implement and validate security controls that improve defensibility: - Secure configuration baselines and drift detection - Identity and access telemetry improvements - Network segmentation signals and policy validation - Container/GKE security instrumentation and runtime visibility - Execute continuous control-health checks and instrumentation validation (telemetry completeness, parsing quality, alert fidelity, logging pipeline reliability). - Coordinate cleanly with the CSSP: provide engineered signals, detection content, and automation that improves downstream monitoring and response outcomes. - Produce clear technical deliverables (engineering notes, detection documentation, dashboards/coverage maps, stakeholder-ready updates) with minimal editing. Qualifications - Active DoD Secret secret clearance. - Role-required security certification such as: CFR, CCNA Cyber Ops, CCNA-Security, CHFI, CySA+, GCFA, GCIH, SCYBER. - Demonstrated experience in cloud security engineering or security-focused platform engineering in enterprise/mission environments. - GCP strongly preferred (AWS/Azure acceptable with ability to ramp quickly in GCP). - Strong proficiency in cloud logging/telemetry design, including integration into VDSS/SIEM/SOAR platforms. - Hands-on experience with automation and APIs (Python/Go/Bash, REST/JSON, gcloud/SDKs) to build repeatable security workflows. - Experience with Kubernetes/container security concepts; ability to instrument and operationalize GKE audit/runtime telemetry. - Practical incident-response awareness (evidence preservation and containment guidance) — not a primary duty, but able to support when needed. - Strong writing/briefing skills; can deliver precise, customer-ready outputs with minimal oversight. - Comfort operating in a high-change environment with competing priorities and frequent stakeholder engagement. - Cloud certification preferred (e.g., CCSP or Google Professional Cloud Security Engineer, Professional Cloud DevOps Engineer, Professional Cloud Network Engineer). Company Description Tetrad Digital Integrity (TDI) is a cybersecurity firm built for high-consequence environments where mission, complexity, and trust intersect. Our single focus has been delivering cyber solutions to effectively manage risk & the business of cyber for 25 years! TDI does business with the federal government, which restricts employment to individuals who are either US citizens or lawful permanent residents of the United States. TDI is an Equal Opportunity Employer. Employment decisions are made based on individual qualifications, merit, and business needs. We do not discriminate in employment opportunities or practices based on race, color, religion, sex, or national origin, in accordance with applicable federal laws.

Job Requirements

  • Active DoD Secret secret clearance.
  • Role-required security certification such as: CFR, CCNA Cyber Ops, CCNA-Security, CHFI, CySA+, GCFA, GCIH, SCYBER.
  • Demonstrated experience in cloud security engineering or security-focused platform engineering in enterprise/mission environments.
  • GCP strongly preferred (AWS/Azure acceptable with ability to ramp quickly in GCP).
  • Strong proficiency in cloud logging/telemetry design, including integration into VDSS/SIEM/SOAR platforms.
  • Hands-on experience with automation and APIs (Python/Go/Bash, REST/JSON, gcloud/SDKs) to build repeatable security workflows.
  • Experience with Kubernetes/container security concepts; ability to instrument and operationalize GKE audit/runtime telemetry.
  • Practical incident-response awareness (evidence preservation and containment guidance) — not a primary duty, but able to support when needed.
  • Strong writing/briefing skills; can deliver precise, customer-ready outputs with minimal oversight.
  • Comfort operating in a high-change environment with competing priorities and frequent stakeholder engagement.
  • Cloud certification preferred (e.g., CCSP or Google Professional Cloud Security Engineer, Professional Cloud DevOps Engineer, Professional Cloud Network Engineer).

Related Categories

Related Job Pages

More Security Engineer Jobs

Vannevar logo

Information Security Engineer - Compliance (ATO)

Vannevar

Vannevar is a defense technology company building AI to deter our adversaries. In the 21st century, conflict moves at algorithmic speed and foresight equals firepower. Our agentic AI is purpose-built to compete with China—from cross-Strait conflict to gray zone coercion. Trained on the most mission-relevant datasets in defense, our technology models adversary behavior, simulates campaigns, and recommends the best course of action to decision makers. Our AI systems are some of the most trusted in the industry and actively used on the front lines of the Indo-Pacific to keep the peace and save lives. Exceptional technology starts with exceptional people. Vannevar is a small agile team combining world-class engineers with veteran strategists who bring deep expertise in defense and tradecraft. We’re building a company defined by mission impact, user empathy, and disciplined growth. In just three years, we grew from $3M to $80M in ARR, achieved early profitability, and reached unicorn status—proving that disruption doesn’t require an ego, and staying power doesn’t mean standing still.

Security Engineer126 days ago
OtherRemoteTeam 51-200Since 2019

This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description Vannevar Labs is seeking an experienced Information Security Engineer to lead our IL-6 / IL-7 ATO (Authority to Operate) and follow-on compliance efforts. This role will be critical to unlocking our ability to deploy classified capabilities for defense and intelligence customers. You will serve as the dedicated technical leader responsible for achieving platform operation on classified networks, working directly with government ISSMs, AOs, and security stakeholders to navigate the RMF process and achieve ATOs across Navy, Joint, and COCOM user groups. What you’ll do - Own and execute our strategy for how we approach ATOs across our customers. - Lead the end-to-end ATO process for IL-6 (SIPR) and IL-7 (JWICS) environments, through full authorization and follow-on compliance. - Own RMF (Risk Management Framework) documentation and control implementation across multiple simultaneous ATOs. - Work with 3PAOs and federal government AOs to achieve compliance certifications and reports. - Ensure the implementation, oversight, monitoring, and maintenance of security configurations, practices, and procedures. - Serve as a liaison between system owners and other security personnel, ensuring that selected security controls are effectively implemented and maintained throughout the lifecycle of projects. - Interface directly with government ISSMs, AOs, and security stakeholders to manage authorization packages and navigate accreditation tools (XACTA, eMASS). - Design and implement role-based access controls, data classification frameworks, and audit logging capabilities for classified environments. - Architect solutions for handling TS/SCI data with proper controls and separation that meet DoD requirements. - Ensure compliance with DISA STIGs, SRGs, NIST 800-53, and DoD hardening standards. - Build scalable systems and processes for managing ATOs across different customers and sponsors. - Coordinate with platform engineering teams on security roadmap priorities and technical implementation. - Manage relationships with government sponsors and identify opportunities to parallel-path authorization efforts. - Work closely with mission engineering teams deploying to classified environments and partner with compliance engineering on FedRAMP and CMMC efforts. - Brief executive leadership on ATO status, risks, and strategic decisions. Qualifications - Must have personally led or been deeply involved in achieving ATOs or DISA provisional authorizations. - 5+ years in information security, with significant time in government/DoD compliance. - Direct experience with RMF, NIST 800-53, DISA STIGs, and IL-4/IL-5/IL-6/IL-7 environments. - Track record of working closely with government ISSMs, AOs, to navigate and expedite bureaucratic processes. - Experience with XACTA, eMASS, or similar government accreditation platforms. - Deep understanding of classified network architectures (SIPR, JWICS). - Experience implementing RBAC, audit logging, and data classification systems. - Knowledge of cloud security in AWS GovCloud, Google Government, and Azure Government. - Familiarity with container security, Kubernetes/OpenShift in classified environments. - Understanding of cross-domain solutions and data transfer between classification levels. - Ability to navigate complex government processes and build relationships with government stakeholders. - Strong written communication for technical documentation and compliance artifacts. - Must hold an active U.S. TS Security clearance with SCI Eligibility. Benefits - Health, dental, and vision insurance. - Remote friendly with WeWork access. - Unlimited PTO, shared downtime during the federal holiday calendar, and company-wide off time at the end of each year. - 401(k) match. - Lifestyle & wellbeing stipends. - Salary top-up during military reserve duty. - Fully paid parental leave. - Child and pet care reimbursement during travel.

United States
Job Closed
Full TimeRemoteTeam 501-1,000Since 1958H1B No Sponsor

• Contribuer aux projets destinés à nos clients en France et à l’international • Intervenir sur l’ensemble du cycle de développement, de la conception jusqu’à la mise en production • Travailler sur les interfaces de communication et leur sécurisation • Pré-étude en lien avec le chef de projet • Définir ou faire évoluer les solutions de cybersécurité ainsi que l’architecture logicielle et matérielle • Analyse de risque cybersécurité • Définir la stratégie de tests de cybersécurité • Développer les nouvelles fonctionnalités cyber nécessaires • Concevoir les tests requis : tests unitaires, fonctionnels et d’intégration • Mettre en œuvre et utiliser les outils de CI/CD • Intégrer et tester les livrables sur cible embarquée • Participer à la conception de nouveaux produits • Réaliser des tests de pénétration sur nos produits

France
OtherRemoteTeam 1,001-5,000Since 2008H1B Sponsor

• Leads business and technical partners with expert knowledge of relevant security technologies. • Applies innovative techniques to address emerging technologies, specifically focusing on AI integration and modern cloud security paradigms. • Prepares and analyzes overall security architecture and detailed systems specifications for complex security systems • Serves as InfoSec Ambassador and lead technical representative to Infrastructure and Reliability and R&D as a whole. • Leads discussion with stakeholder teams regarding best practices in design and implementation of secure cloud systems • Leads initiatives designed to share knowledge across InfoSec, R&D, and Technology teams. • Identifies, recommends, coordinates, and delivers timely knowledge to support teams regarding technologies, processes or tools. • Develops and executes strategies to increase Cloud Security knowledge throughout the enterprise. • Represents Security Platform in development and implementation of the overall global enterprise cloud architecture • Designs, develops, and implements cloud-native architectures that will allow requirements to be met with appropriate security controls present.

United States
$177K - $284K / year
Job Closed

• Own the RMF 'engine room' • Apply DoD cloud security policies and NIST SP 800-53 controls • Develop and maintain RMF artifacts • Execute POA&M management with discipline • Support security change governance activities • Conduct security engineering analysis for cloud-native workloads • Engineer evidence and control health • Integrate security into delivery pipelines • Assist with threat modeling and vulnerability assessments • Partner with system architects and developers to integrate security • Monitor, track, and report security compliance posture • Optimize and automate compliance operations

United States
Job Closed