Cloud Security Engineer
Job description
About the role
SteerBridge is a modern technology company delivering innovative, mission‑focused solutions to the U.S. Government and private sector. Leveraging deep expertise in federal acquisition, digital transformation, and emerging technologies, we deliver agile, commercial‑grade capabilities that accelerate operational effectiveness and drive measurable mission success.
At the core of SteerBridge is our people - especially the veterans whose leadership, problem‑solving mindset, and commitment to excellence elevate every project we support. We don't simply hire exceptional talent; we cultivate it, creating meaningful career pathways for veterans, military spouses, and professionals who share our passion for advancing technology and strengthening the missions we serve.
You will own the design, implementation, and continuous operation of security controls for critical infrastructure spanning on‑premises and cloud environments. You will serve as a technical authority responsible for hardening systems, reducing risk, and ensuring that security posture aligns with strict federal requirements. You will partner closely with cross‑functional teams to embed security into every phase of solution delivery and sustain resilient, compliant operations. You will lead incident response efforts, drive proactive threat detection, and translate complex security data into clear guidance for stakeholders. You will safeguard sensitive information assets and ensure that data protection, encryption, and identity management practices are consistently applied. You will champion continuous improvement by monitoring evolving threats, refining controls, and supporting rigorous audit and assessment activities.
Key facts
What you'll do
Plan, implement, monitor, and maintain on‑premises and virtual network services and systems to support mission operations.
Configure, administer, and maintain secure systems in strict accordance with organizational security policies and procedures and federal guidance.
Manage user accounts, permissions, and identity/access controls to enforce least‑privilege and appropriate access governance.
Perform system configuration, maintenance, backup, recovery, and disaster recovery activities to ensure continuity and resilience.
Develop, implement, and harden secure solutions across cloud and hybrid environments supporting mission‑essential systems and data assets.
Review, implement, and enforce NIST SP 800‑53 security controls and System Security Plans (SSPs) to support Authority to Operate (ATO) processes.
Identify, assess, and remediate system vulnerabilities to reduce security risks and measurably improve overall security posture.
Collaborate with software development, infrastructure, and compliance teams to integrate security best practices throughout the system lifecycle from design through operations.
Create and maintain security documentation, policies, procedures, and evidence packages that support compliance initiatives and audit readiness.
Participate in security assessments, audits, penetration testing, and incident response activities to validate control effectiveness and detect gaps.
Implement and enforce data protection strategies, encryption standards, and identity and access management (IAM) controls across platforms and applications.
Monitor system security posture, investigate security events, and support remediation efforts to restore secure operations quickly.
Safeguard sensitive and proprietary information by adhering to all organizational security, privacy, and data protection policies, ensuring confidentiality, integrity, and availability of information systems.
Leverage log aggregation and correlation techniques to detect anomalies, track indicators of compromise, and support timely threat hunting.
Utilize security tooling and automation to streamline configuration management, vulnerability remediation, and compliance reporting.
Requirements
Must be a U.S. Citizen, as this role requires eligibility for federal government employment and access to national security information.
Hold a Bachelor's or Master's degree in Cybersecurity, Information Systems, or a closely related field that provides foundational knowledge in security principles and technologies.
Possess an active Secret security clearance or demonstrate the ability to obtain one, given the sensitivity of the systems and data you will protect.
Bring a minimum of 5+ years of cybersecurity engineering experience within federal, military, or large enterprise environments where mission‑critical systems are protected.
Demonstrate familiarity with one or more of the following security frameworks: NIST SP 800, CNSSI, and SOC, and show how you have applied them in practice.
Show proven experience with system hardening, network security, encryption protocols, vulnerability scanning, and structured incident response activities.
Show experience working with public cloud platforms such as AWS, Azure, and GCP in secure, regulated environments.
Demonstrate hands‑on experience with a broad set of methodologies and tools, including SIEM, XDR, SAST/DAST, STIG, and SCAP, to support detection, prevention, and response.
Show experience implementing and managing identity and access management controls, including role‑based, attribute‑based, and federated access models to enforce least‑privilege and secure authorization.
Demonstrate competence in log aggregation and correlation, using solutions to collect, normalize, and analyze log data for security monitoring and forensic investigations.
Nice to have
Hold certifications such as CCNP Security, Security+, or CISSP, which validate advanced security knowledge and professional commitment.
Possess familiarity with Federal Executive and Military security requirements and the IT systems commonly used in those environments.
Show strong written and verbal communication skills, with the ability to produce audit‑ready documentation such as Incident Reports and Test Reports.
Show proficiency with security platforms and tools such as Microsoft Sentinel, Splunk, Tenable/Nessus, CrowdStrike, Zscaler, and Microsoft Defender for Endpoint.
Demonstrate experience securing AI‑based tools and understand the associated risks and controls for these emerging technologies.
Have a track record of coordinating with ISSOs, ISSEs, and federal security teams to align technical implementations with regulatory and mission requirements.
Practical notes
Hours: Full-time during standard business hours.
Travel: Limited travel may be required.
Visa: Candidates must be able to obtain a U.S. work visa if not already authorized.
Eligibility: Open to U.S. citizens only.
Application deadline: Please apply promptly to ensure full consideration.