LeoLabs logo
LeoLabs

Persistent Orbital Intelligence 📡 🛰️

Cloud Engineer

Cloud EngineerCloud EngineerFull TimeRemoteSeniorTeam 51-200Since 2016H1B SponsorCompany SiteLinkedIn

Location

United States

Posted

3 days ago

Salary

0

Seniority

Senior

Bachelor Degree5 yrs expEnglishAnsibleAWSAzureCloudDNSTerraformVault

Job Description

Cloud Engineer

LeoLabs

• Cloud Landing Zone Design and Implementation: Design, build, and maintain secure cloud landing zones across AWS and Azure environments. Implement account and subscription structures that separate workload zones, including commercial workloads, government workloads, Corporate IT, security services, and restricted CUI/ITAR environments. Build baseline controls for new cloud accounts and subscriptions, including owner tagging, logging, security baselines, routing, encryption, key policies, break-glass review, and monitoring requirements. Support landing-zone acceptance criteria so new cloud environments are provisioned with required guardrails before workloads are deployed. • Identity, Access, and Privilege Controls: Implement federated access patterns using SAML/OIDC, IAM Identity Center, Azure Entra ID, or comparable identity platforms. Support least-privilege access, role lifecycle management, JIT/PIM/PAM workflows, service account controls, and removal of shared accounts. Help automate credential rotation, secrets management, service account governance, and break-glass monitoring. Partner with the Security team to ensure privileged cloud activity is authenticated, authorized, logged, reviewed, and tied to approved workflows. • Cloud Security Guardrails and Policy-as-Code: Implement preventative and detective cloud guardrails using tools such as AWS Organizations, SCPs, AWS Config, Azure Policy, Defender for Cloud, Wiz, Terraform, CloudFormation, Bicep, or similar platforms. Codify baseline configurations for logging, encryption, network controls, public exposure prevention, security-group rules, storage policies, KMS/key vault use, and workload tagging. Monitor and remediate drift from approved cloud security baselines. Support detection and automated response for public admin exposure, cloud policy drift, unapproved data movement, stale credentials, and overly permissive IAM roles. • Cloud Network and Private Access Integration: Partner with the Network team to implement secure cloud network patterns, including hub-and-spoke networking, transit gateways, vWAN, private endpoints, centralized DNS, private admin paths, and controlled egress. Ensure cloud workloads are not exposed through unnecessary public interfaces. Support routing and connectivity decisions for radar telemetry and other cloud workload environments. Implement cloud-side controls for SASE/ZTNA access, private application access, firewall inspection, flow logging, and route governance. • Telemetry, SIEM, and SOC Enablement: Integrate cloud logs and security signals into centralized SIEM/SOC workflows. Onboard and maintain telemetry sources such as CloudTrail, AWS Config, VPC Flow Logs, Azure Activity Logs, NSG Flow Logs, Entra ID logs, KMS/Key Vault events, storage access logs, CSPM findings, vulnerability findings, and workload security events. Partner with the Security team to build detection use cases for exposed cloud services, privileged access anomalies, credential hygiene drift, data boundary violations, and cloud configuration drift. Support retention tiers, immutable logging, audit trails, alert evidence, and compliance reporting requirements.

Job Requirements

  • Must be eligible to obtain and maintain a U.S. personnel security clearance
  • 5+ years of hands-on cloud engineering experience in AWS, Azure, or hybrid cloud environments.
  • Strong experience with AWS and/or Azure core services, including IAM, networking, logging, encryption, storage, compute, security monitoring, and account/subscription management.
  • Experience building or operating cloud landing zones, multi-account AWS environments, Azure management groups, or similar cloud governance structures.
  • Hands-on experience with infrastructure-as-code tools such as Terraform, CloudFormation, Bicep, CDK, Ansible, or similar.
  • Experience implementing cloud security controls, including IAM least privilege, logging baselines, encryption, key management, public exposure prevention, security groups, policy enforcement, and configuration monitoring.
  • Experience integrating cloud logs or findings into SIEM, SOAR, CSPM, or monitoring platforms.
  • Working knowledge of cloud networking, including VPC/VNet design, routing, private endpoints, security groups, NACLs/NSGs, flow logs, transit gateways, vWAN, VPNs, and egress controls.
  • Ability to document cloud designs, implementation plans, runbooks, and compliance evidence.
  • Strong collaboration skills with security, networking, infrastructure, SRE, and operations teams.

Benefits

  • Global workforce: flexible remote/hybrid opportunities
  • Work on complex, meaningful missions with real-world impact
  • Unlimited paid time off for most roles
  • Competitive salary and equity packages
  • Comprehensive health, dental, and vision coverage
  • Access to the forefront of commercial space operations and defense innovation

Related Categories

Related Job Pages

More Cloud Engineer Jobs

ContractRemoteTeam 1,001-5,000H1B No Sponsor

• Design, deploy, and maintain GovCloud-based cloud infrastructures across AWS and Azure, ensuring high availability, scalability, and security. • Architect and implement secure cloud environments, including networking, virtualization, and containerization solutions. • Develop and manage Infrastructure-as-Code (IaC) solutions using tools such as Terraform, AWS CloudFormation, or ARM templates. • Support hybrid and multi-cloud architectures, including VPC peering, cross-domain solutions, and secure cloud integrations. • Implement and manage Identity and Access Management (IAM) and role-based access control (RBAC) policies. • Configure and optimize cloud networking components, including VPCs, subnets, VPNs, and security groups. • Lead or support Authority to Operate (ATO) processes, including: Preparing System Security Plans (SSP) Developing Security Assessment Reports (SAR) Managing Plans of Action & Milestones (POA&M). • Ensure compliance with DoD Risk Management Framework (RMF), NIST 800-53 Rev. 5, FedRAMP, and DoD IL-4/IL-5 requirements. • Perform continuous monitoring and compliance assessments for cloud environments. • Collaborate with cybersecurity teams to implement Zero Trust Architecture (ZTA) and enforce security controls. • Optimize cloud environments for compute, storage, and networking efficiency while maintaining security and compliance.

United States
Job Closed
NEORIS logo

Cloud Migration Expert (AWS)

NEORIS

NEORIS is a Digital Accelerator that helps companies step into the future.

Cloud Engineer3 days ago
Full TimeRemoteTeam 1,001-5,000H1B No Sponsor

Role Description Nos encontramos en la búsqueda de un Experto en Migración Cloud (AWS) para liderar iniciativas de migración de infraestructura y aplicaciones hacia AWS en proyectos de alto impacto, trabajando en modalidad remota. - Definir y ejecutar la estrategia de migración a AWS (rehost, replatform y evolución). - Liderar la planificación por oleadas (waves) y la priorización del portafolio de aplicaciones. - Diseñar y validar arquitecturas cloud seguras, escalables y resilientes. - Coordinar equipos multidisciplinarios de infraestructura, arquitectura, seguridad, desarrollo y negocio. - Asegurar la adopción de prácticas de gobernanza, seguridad y FinOps. - Gestionar riesgos, dependencias y planes de mitigación durante el proceso de migración. - Medir y reportar métricas clave de avance, costos, desempeño y estabilidad. - Promover la transferencia de conocimiento y adopción del modelo operativo cloud. Qualifications - Experiencia comprobada liderando migraciones a AWS en entornos empresariales. - Dominio de servicios AWS como EC2, VPC, RDS, S3, IAM y CloudWatch. - Conocimientos sólidos en arquitectura cloud, redes, seguridad y automatización (IaC). - Experiencia en entornos regulados y de alta criticidad. - Conocimiento de sistemas operativos Windows, Linux, WebLogic e IIS. - Experiencia con metodologías ágiles y gestión de proyectos tecnológicos. Benefits - Salario competitivo - Medicina prepagada - Seguro de vida - NEORIS Days (días libres) - Bonificación por cumplimiento anual - Bono vacacional - Plataformas de capacitación y entrenamiento. - Auxilio de conectividad - Actividades o eventos de bienestar

Worldwide

Azure Engineer

Alpha Omega Integration

Alpha Omega Integration is a mission-driven IT solutions provider dedicated to ensuring the United States’ continued global leadership through innovative and

Cloud Engineer3 days ago

• Provide support for a mission critical application maintained in Azure • Collaborate with Azure pier architects and engineers on the program to maintain Microsoft Azure Solutions. • Develop and implement automation solutions to support operations, provisioning, and cost control of assets/environments/products. • Collaborate with other project teams to share lessons learned and best practices • Attend and participate in all agile ceremonies and activities, including daily scrums • Write automation code (IaC) and developing CI/CD pipelines

Virginia
$101K - $130K / year
Spyrosoft logo

OpenStack Cloud Engineer

Spyrosoft

We enable our clients to thrive, thanks to a combination of technical proficiency and domain-specific knowledge.

Cloud Engineer3 days ago
ContractRemoteTeam 1,001-5,000Since 2016H1B No Sponsor

• Develop and maintain OpenStack Cinder block storage services. • Develop and maintain OpenStack Nova compute services. • Build and maintain automation workflows using Python and/or Go. • Operate and administer Linux-based cloud infrastructure. • Contribute patches and improvements to OpenStack upstream projects. • Participate in code reviews and knowledge sharing within the team.

Poland
zł110 - zł190 / hour