Skip to content

Open nowPosted 14 days ago

Principal Cloud Security Engineer

kgs401 open roles

Where
Washington, DC, USA
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowPrincipal Cloud Security Engineerkgs · Washington, DC, USA
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on kgs's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.6%1 day
  2. 3.4%3 days
  3. 7.8%7 days
  4. 14.3%14 days
  5. 33.7%30 days
This job: posted 14 days ago

The posting

The application deadline and start date are subject to change based on the status of the contract.  Applications will be accepted through expiration date or until the position is filled. If the contract is not awarded, this position may not be filled.   Koniag Technology Solutions, Inc a Koniag Government Services company, is seeking a Principal Cloud Security Engineer with a Secret security clearance to support KTS and our government customer in Washington, DC. The position is onsite with possibly hybrid availability. This position is for a Future New Business Opportunity.      This position is covered under the Service Contract Act. We offer competitive compensation and an extraordinary benefits package including health, dental and vision insurance, 401K with company matching, paid holidays, paid Vacation, paid sick leave and more.   Koniag Government Services is seeking an experienced Principal Cloud Security Engineer to join a dynamic team supporting cloud security architecture, implementation, and continuous monitoring across multiple cloud platforms. The ideal candidate is a technically proficient security professional with hands-on experience securing environments across Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform (GCP). This individual will be passionate about cybersecurity, committed to staying current with evolving threats and technologies, and capable of applying their expertise to solve complex, real-world security challenges in a federal government context. The ability to obtain or maintain an active Secret clearance is required to support our government customer.   The Principal Cloud Security Engineer will serve as the lead technical authority and SME for cloud security architecture, governance, and advanced threat defense across multi-cloud enterprise environments, including AWS, Microsoft Azure, and Google Cloud Platform (GCP). In this leadership role, you will define the multi-cloud security vision, architect complex security frameworks, drive tool selection and integration, and ensure robust security postures that align with federal compliance mandates and agency risk tolerances.   As a strategic technical lead, the Principal Engineer will bridge high-level enterprise risk management with hands-on engineering execution. You will mentor engineering teams, partner with agency leadership and System Owners, and lead Assessment and Authorization (A&A) strategies to maintain continuous authorization to operate (ATO) in high-stakes federal cloud environments.   Principal responsibilities will include but are not limited to:

Lead the design, engineering, and execution of scalable, resilient multi-cloud security solutions across AWS, Azure, and GCP that address complex threat vectors, zero-trust paradigms, and stringent federal mandates. Drive the strategic evaluation, selection, architectural integration, and optimization of cloud-native and enterprise third-party security platforms (CSPM, CWPP, CIEM, SIEM, and Vulnerability Management). Direct the configuration, enforcement, and integration of cloud-native security frameworks (e.g., AWS Security Hub/Config, Azure Defender/Policy, GCP Security Command Center Premium) with enterprise security operations centers (SOC). Pioneer "Security as Code" initiatives by integrating automated security controls, guardrails, compliance scanning, and vulnerability checks directly into Infrastructure as Code (IaC) and CI/CD pipelines. Oversee the creation, validation, and maintenance of comprehensive Assessment and Authorization (A&A) packages, including System Security Plans (SSPs), Security Assessment Reports (SARs), and continuous authorization artifacts. Lead security impact assessments for enterprise-level system architectural changes, evaluating complex risks and defining remediation strategies without impacting operational tempo. Establish proactive continuous monitoring, threat hunting, and incident handling protocols across multi-cloud environments utilizing integrated SIEM, SOAR, and telemetry platforms (e.g., Splunk, Sentinel, Qualys). Serve as the principal technical liaison to agency leadership, Authorizing Officials (AOs), CISOs, and cross-functional engineering leads to align technical security strategies with mission objectives. Mentor senior and mid-level security engineers, establishing operational guidelines, standard operating procedures (SOPs), and engineering baselines across the organization.

  Required Education and Experience:

Bachelor's degree in Computer Science, Information Systems, Cybersecurity, Systems Engineering, or a related field from an accredited college or university. (Master’s degree preferred). 8+ years of progressive professional experience in cybersecurity, cloud security engineering, network defense, or system architecture, with at least 5+ years dedicated to architecting and securing enterprise cloud environments. Proven track record architecting and executing security controls across at least two major cloud service providers (AWS, Azure, GCP). Deep expertise with federal security frameworks, including FISMA High/Moderate, FedRAMP, NIST SP 800-53 (Rev. 5), NIST SP 800-37 (RMF), and CMMC. Active Secret clearance or higher (Top Secret preferred).

  Required Skills and Competencies:

Exceptional written, verbal, and presentation skills, with a proven ability to articulate complex cybersecurity risks and technical architectures to executive leadership, Authorizing Officials, and technical teams. Advanced proficiency engineering and hardening enterprise infrastructure across AWS, Azure, and GCP (IaaS, PaaS, and SaaS models). Hands-on expertise configuring and scaling enterprise tools including CSPM/CWPP suites, vulnerability management (e.g., Qualys, Tenable), file integrity monitoring (e.g., Tripwire), and enterprise SIEM/SOAR platforms (e.g., Splunk, Microsoft Sentinel). Strong experience embedding security testing and guardrails into DevSecOps workflows using Infrastructure as Code (IaC) templates (Terraform, Bicep, CloudFormation) and CI/CD pipelines. Deep understanding of zero-trust architecture, enterprise identity federation, privilege management, SAML 2.0, OAuth2, and OIDC across multi-tenant cloud environments. Demonstrated ability to author, review, and defend complex SSPs, control worksheets, and POAMs to secure ATO approvals. Proven ability to resolve critical technical bottlenecks, address emerging security threats, and drive security automation to reduce operational overhead.

  Desired Skills and Competencies:

Industry Certifications (One or more strongly preferred): Executive/Architect: CISSP, CCSP, CISM. Cloud Provider Specific: AWS Certified Security – Specialty, Microsoft Certified: Cybersecurity Architect Expert (SC-100), Microsoft Certified: Azure Security Engineer Associate (AZ-500), or Google Professional Cloud Security Engineer. Master’s degree in Cybersecurity, Information Assurance, or Computer Science. Experience integrating security operations with GRC platforms (e.g., ServiceNow GRC, eMASS, CSAM). Expertise securing containerized workloads and orchestration systems (Kubernetes, EKS, AKS, GKE) and serverless deployment models. Applied knowledge of NIST SP 800-207 Zero Trust Architecture principles and implementation strategies across hybrid federal enterprises.

  Our Equal Employment Opportunity Policy The company is an equal opportunity employer. The company shall not discriminate against any employee or applicant because of race, color, religion, creed, ethnicity, sex, sexual orientation, gender or gender identity (except where gender is a bona fide occupational qualification), national origin or ancestry, age, disability, citizenship, military/veteran status, marital status, genetic information or any other characteristic protected by applicable federal, state, or local law. We are committed to equal employment opportunity in all decisions related to employment, promotion, wages, benefits, and all other privileges, terms, and conditions of employment.   The company is dedicated to seeking all qualified applicants. If you require an accommodation to navigate or apply for a position on our website, please get in touch with Heaven Wood via e-mail at [email protected] or by calling 703-488-9377 to request accommodations.   Koniag Government Services (KGS) is an Alaska Native Owned corporation supporting the values and traditions of our native communities through an agile employee and corporate culture that delivers Enterprise Solutions, Professional Services and Operational Management to Federal Government Agencies. As a wholly owned subsidiary of Koniag, we apply our proven commercial solutions to a deep knowledge of Defense and Civilian missions to provide forward leaning technical, professional, and operational solutions. KGS enables successful mission outcomes for our customers through solution-oriented business partnerships and a commitment to exceptional service delivery. We ensure long-term success with a continuous improvement approach while balancing the collective interests of our customers, employees, and native communities. For more information, please visit www.koniag-gs.com.   Equal Opportunity Employer/Veterans/Disabled. Shareholder Preference in accordance with Public Law 88-352

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against kgs's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on kgs's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    kgs's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.