InfraSec Engineer
Job description
InfraSec Engineer at Airspace Intelligence.com.
About the role
You will own the design and day-to-day operation of the secure cloud infrastructure that powers our mission-critical aviation and defense platforms. You will translate security frameworks and compliance mandates into deployed, automated controls that keep our systems resilient and auditable. You will partner closely with engineering and product teams to embed security into every pipeline and deployment, ensuring nothing ships that does not meet our bar. You will implement and manage the tooling required to achieve FedRAMP and DoD compliance across our cloud environments. You will enforce least privilege and Zero Trust principles while orchestrating secure software delivery workflows from development through production. You will leverage Infrastructure as Code to provision and govern environments on platforms such as AWS GovCloud and Azure GCCH. You will drive security automation, vulnerability management, and continuous monitoring to detect and remediate risks at speed. You will act as a subject matter expert for cloud security best practices and emerging threats, elevating the entire organization's security posture.
Key facts
What you'll do
Design, build, and maintain the infrastructure required to achieve FedRAMP and DoD compliance for ASI's mission-critical platforms.
Orchestrate and operate cloud environments on AWS GovCloud, Azure GCCH, and Platform One with a focus on security, reliability, and scalability.
Implement and automate security controls derived from frameworks such as SOC 2, NIST CSF, and FedRAMP using Infrastructure as Code.
Write and maintain infrastructure definitions using Terragrunt and Terraform to enforce consistent and auditable environments.
Deploy and manage containerized workloads on AWS EKS and other Kubernetes platforms using Helm and related tooling.
Integrate security automation into CI/CD pipelines to enforce policy, detect misconfigurations, and reduce manual toil.
Configure and operate vulnerability scanning, penetration testing support, and continuous monitoring to identify and remediate risks.
Apply secure coding best practices aligned with OWASP Top 10 and SANS Top 25 to infrastructure and application artifacts.
Champion Zero Trust architecture, least privilege access, and cloud security best practices across engineering teams.
Collaborate with engineers and leadership to compress analysis time into seconds, enabling rapid decision-making for aviation, defense, and critical infrastructure customers.
Contribute to the creation and maintenance of security artifacts, compliance evidence, and architectural diagrams required for regulatory assessments.
Serve as a technical liaison for security reviews, ensuring that infrastructure changes meet strict U.S. government and export control requirements.
Drive security improvements through automation, ensuring that resilient systems operate at scale without compromising compliance or performance.
Support incident response and security investigations by providing deep infrastructure visibility and rapid remediation guidance.
Requirements
You must have proven experience implementing FedRAMP security controls in a cloud environment and can demonstrate this through real-world deployments.
You must possess a strong understanding of security frameworks including SOC 2, NIST CSF, and FedRAMP, and how they map to cloud infrastructure.
You must have hands-on experience securing cloud environments, with a focus on AWS GovCloud, Azure GCCH, or Platform One deployments.
You must demonstrate coding skills in Python and/or Rust, with the ability to write secure, maintainable infrastructure automation.
You must show demonstrated skills in Infrastructure as Code, specifically with Terragrunt and Terraform for provisioning and governance.
You must have experience with Helm and Kubernetes, including the management of AWS EKS clusters in production environments.
You must be familiar with managing security automation tools, vulnerability scanning, and supporting penetration testing activities.
You must have a solid understanding of secure coding best practices, including OWASP Top 10 and SANS Top 25, and apply them in infrastructure and code reviews.
You must have experience implementing Zero Trust principles, least privilege access, and cloud security best practices at scale.
You must hold a current or recently obtained U.S. Security Clearance or be eligible to obtain one, given the sensitivity of our contracts and data.
You must be legally authorized to work in the United States without sponsorship, as our work involves U.S. Government data and export-controlled technology.
You must be able to pass background checks and satisfy all eligibility requirements for U.S. government contractor personnel.
You must have experience working with restricted U.S. Government data and understand the implications of handling such information in a cloud environment.
You must be comfortable operating in an environment where compliance and security are non-negotiable requirements of every delivery.
You must be able to communicate effectively with both technical and executive stakeholders about risk, compliance, and architectural decisions.
You must be willing to learn and adapt to evolving government requirements and industry best practices in cloud security.
You must be detail-oriented and capable of maintaining accurate security documentation and evidence for audits.
You must be committed to the principles of secure software supply chains and infrastructure integrity.
Nice to have
Experience with Platform One services and identity management solutions for government environments.
Familiarity with defense-oriented workflows and the Intelligence Community community.
Knowledge of export control regulations and their impact on technology deployment.
Experience with DevSecOps metrics and continuous compliance reporting for federal clients.
Practical notes
This role requires U.S. location in the Boston area and the ability to meet client or government site visit requirements as needed.
Employment offers are contingent on timely receipt and approval of required U.S. Security Clearances and all related authorizations for contemplated job duties.
Travel is not required on a regular basis, but occasional domestic travel may be necessary for customer engagement or audit support.
Candidates must be eligible to work in the United States without sponsorship due to the nature of restricted U.S. Government data and export-controlled technology.
The position is full-time and based in the Boston region, with flexibility for hybrid collaboration where applicable under security policies.