Principal Multi-Cloud Cybersecurity Engineer
Listed on 2026-01-13
-
IT/Tech
Cybersecurity, Systems Engineer -
Engineering
Cybersecurity, Systems Engineer
Principal Multi-Cloud Cybersecurity Engineer
2 days ago Be among the first 25 applicants
Light Feather is seeking a Principal Multi-Cloud Cybersecurity Engineer with security engineering experience building and securing cloud infrastructure at scale across AWS/Azure/GCP and an understanding of development lifecycle phases as part of the Dev Sec Ops methodology. A successful Principal Cloud Security Engineer knows one or more modern programming languages, has a cyber security background in the cloud, understands cloud architecture, development fundamentals, and has worked as part of an Agile team to deliver solutions across an organization.
The Principal Cloud Security Engineer will utilize the Dev Sec Ops methodology to successfully secure platform features and capabilities deployed onto Commercial and Gov Cloud AWS/Azure/GCP environments.
This role offers the opportunity to support high-impact cloud security and platform engineering initiatives within the federal sector, helping secure, compliant, automated, and scalable cloud capabilities that meet mission‑critical requirements.
- Location:
In‑Person (5 days/week) in Washington, DC 20036 - Job Type: Full Time
- Citizenship: U.S. Citizenship Required
- Clearance Requirement:
Active Secret or higher clearance
- Design and implement secure architecture across AWS, Azure, and GCP, including Commercial, Gov Cloud, and IL6 enclaves.
- Define and enforce security baselines (CIS, NIST 800‑53, FedRAMP, etc) and align security controls with compliance frameworks.
- Lead architecture reviews, threat modeling, and secure design guidance for cloud services and workloads.
- Automation & Dev Sec Op
- Build and maintain Infrastructure as Code modules (Terraform) to enforce security at scale across hundreds of accounts, subscriptions, and projects.
- Integrate CI/CD pipelines with automated security scans (SAST, DAST, IaC scanning, container security) and drive secure coding practices across the organization.
- Develop and enhance automated guardrails, policies, and remediation pipelines.
- Support ATO compliance efforts by embedding controls into the cloud buildout process and lead assessments.
- Partner with compliance officers, auditors, and platform engineers to ensure evidence and reporting readiness.
- Implement centralized logging, monitoring, and incident response across multi‑cloud environments.
- Guide a team of security and platform engineers on secure cloud development and automation practices.
- Partner with architects, developers, and compliance teams to align security objectives between projects, stakeholders, and platform teams.
- Act as a cloud security subject matter expert for stakeholders, architects, and engineering leads.
- Bachelor Degree in computer science or relevant technical degree; or equivalent industry experience.
- 8+ years of cybersecurity or cloud engineering experience, with at least 5+ in cloud security.
- Hands‑on advanced experience securing and automating two or more cloud environments (AWS/GCP/Azure/Oracle).
- Experience with native cloud security tools (AWS Security Hub, Guard Duty, Defender for Cloud, Google SCC, etc).
- Strong background in infrastructure as code (Terraform, Cloud Formation, ARM/Bicep) and CI/CD (Git Lab, Git Hub Actions, etc).
- Proficient in at least one programming/scripting language (Python, Go, Power Shell, Bash).
- Deep knowledge of cloud identity and access management (IAM/RBAC), key management (KMS/Key Vault/Cloud KMS), networking, and encryption.
- Experience with application security standards such as OWASP ASVS/Top 10 and CWE 25.
- Experience aligning security controls with NIST 800‑53, FedRAMP, CIS Benchmarks, or equivalent frameworks.
- Proven track record embedding security into Agile/Dev Sec Ops teams and pipelines.
- Strong communication and leadership skills, with demonstrated experience in successfully designing, delivering, and iterating on complex projects with a diverse set of stakeholders.
- Experience securing Gov Cloud, DoD IL6, or other restricted cloud environments.
- Knowledge of Service Now for CMDB integrations, discovery, and security workflows.
- Familiarity with supply chain security (SBOM, SLSA,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).