2 open positions available
Design and implement secure, scalable multi-cloud infrastructure and support cloud migration and deployment activities. | Bachelor's degree plus relevant experience, active Secret clearance, cloud architecture expertise, DevOps tools knowledge, and security compliance experience. | SMX is seeking Cloud Systems Engineers (Junior/Mid/Senior/SME) supporting the design and implementation of secure, scalable multi-cloud infrastructure, applications, and services in support of enterprise cloud migration and mission-critical systems for the United States Air Force. Responsible for cloud design, development, engineering, integration, and architecture. Will help onboard new cloud accounts and applications, conduct security patching, build code pipelines, and support deployment activities, primarily with AWS, but familiarity with multi-cloud solutions (Azure, Google, and Oracle), and Commercial Cloud Enterprise (C2E) classified cloud migration and deployments is important. May develop solutions from scratch using tools such as Ansible, Jenkins, Packer, AWS Code*, and related products. Will contribute to the overall strategic vision and integrate a broad range of engineering solutions in support of client requirements for Air Force cloud projects. Helps formulate and define system scope and objectives; develops or modifies processes to solve complex problems for cloud systems, business, and electronic interfaces to achieve desired results through the use of innovative technologies. Able to apply engineering and design methods, theories, and research techniques in the investigation and solution of complex and advanced cloud requirements, hardware/software interfaces, and applications, and solutions. Essential Duties & Responsibilities • Design, architect, and optimize secure cloud solutions in AWS, Azure, Google, and/or Oracle environments • Navigate client-facing engagements and work in tandem with other vendors • Contribute to technical discussions both internally and with customer or vendor teams • Focus on cloud-native services and optimizing the customer landscape through adoption of these services • Define and engineer solution capabilities that satisfy customer business drivers / requirements and meet service delivery objectives • Lead and/or support cloud migration strategies and establish environments (Dev, QA, Prod, etc.) across classified and unclassified networks • Implement automation for provisioning, configuration, security, and monitoring using DevOps best practices • Integrate cloud services with analytics tools • Support infrastructure security design, patching, and compliance documentation to support governance and ATO processes • Develop and apply engineering methods and solutions for cloud environments Required Skills & Experience • Must have High School diploma or Bachelors degree and minimum 1-3 years' experience for junior-level. Must have Bachelor’s degree or equivalent certification plus 4 years' experience for mid-level. Must have Bachelor’s degree or equivalent certification plus 8 years' experience for senior-level. Must have Master’s degree or equivalent certification plus 16 years' experience for SME-level. • Active Security Clearance Required: Secret • DoD 8570 compliant certification: CompTia Sec+ • Expertise in cloud architectures (native services for compute, store, network, security, and automation) • Experience implementing DevOps practices (Kubernetes) using tools such as Terraform, CloudFormation, Jenkins, Git, or Ansible • Demonstrated ability to support enterprise-scale system integrations and automation projects • Proven experience establishing and managing environments across multiple enclaves and security domains • Strong understanding of cloud security frameworks, continuous monitoring, and system hardening • Familiarity with cloud governance tools (e.g., Xacta, eMASS) and experience supporting Authority to Operate (ATO) processes • Ability to develop and maintain technical documentation, infrastructure diagrams, and cloud migration strategies • Experience with Infrastructure as Code (IaC) • Demonstrate the ability to improvise solutions, either with automation or with existing products • Understanding of C4I systems • Knowledge of Windows operating environments • Familiarity with RMF, NIST 800-53, STIGs, and basic cloud security principles • Knowledge/experience with integration of Software with IBM Maximo Application Suite (MAS) Architecture, IBM WebSphere, and Red Hat OpenShift on Azure Desired Skills & Experience • Prior experience supporting United States Air Force cloud programs (AWS Govcloud) • Experience in Zero Trust and modern DevSecOps concepts • Cloud certification(s) #CJPOST The SMX salary determination process takes into account a number of factors, including but not limited to, geographic location, Federal Government contract labor categories, relevant prior work experience, specific skills, education and certifications. At SMX, one of our Core Values is to Invest in Our People so we offer a competitive mix of compensation, learning & development opportunities, and benefits. Some key components of our robust benefits include health insurance, paid leave, and retirement. The proposed salary for this position is:: $103,200 USD - $172,000 USD At SMX®, we are a team of technical and domain experts dedicated to enabling your mission. From priority national security initiatives for the DoD to highly assured and compliant solutions for healthcare, we understand that digital transformation is key to your future success. We share your vision for the future and strive to accelerate your impact on the world. We bring both cutting edge technology and an expansive view of what’s possible to every engagement. Our delivery model and unique approaches harness our deep technical and domain knowledge, providing forward-looking insights and practical solutions to power secure mission acceleration. SMX is an Equal Opportunity employer including disabilities and veterans. Selected applicant may be subject to a background investigation and/or education verification. SMX does not sponsor a new applicant for employment authorization or immigration related support for this position (i.e. H1B, F-1 OPT, F-1 STEM OPT, F-1 CPT, J-1, TN, E-2, E-3, L-1 and O-1, or any EADs or other forms of work authorization that require immigration support from an employer).
Provide security engineering and compliance support for federal cloud environments, advising on authorization and audit readiness, and automating compliance workflows. | Requires 5+ years cybersecurity experience with federal cloud security, knowledge of NIST, FedRAMP, DoD IL4-6, strong communication skills, and relevant certifications like CISM. | The Cyber Security Engineer will provide security engineering, compliance, and risk management support for cloud-based systems aligned with NIST SP 800-53, FedRAMP, and DoD IL4–6 requirements. The role will advise partners and customers navigating government security requirements while supporting authorization, audit readiness, and continuous monitoring activities. A key focus will be improving compliance efficiency through GRC platforms, APIs, scripts, cloud-native services, and automation for evidence collection, control validation, documentation, reporting, and remediation tracking. This position is remote supporting a Herndon, VA based team. Essential Skills • Provide cybersecurity engineering and compliance support for FedRAMP and DoD-authorized cloud environments, including IL4–6. • Advise partners and customers on federal and DoD security requirements, authorization strategies, control implementation, and audit readiness. • Develop, review, and maintain authorization documentation, including SSPs, SAPs, SARs, POA&Ms, FedRAMP appendices, policies, and supporting evidence. • Support system authorization and reauthorization activities across FedRAMP/RMF, including gap assessments, control validation, evidence development, and remediation planning. • Leverage GRC platforms, APIs, scripts, and automation to streamline compliance workflows, evidence collection, documentation updates, control testing, and reporting. • Develop repeatable and auditable processes that reduce manual compliance effort and improve the accuracy and consistency of authorization artifacts. • Collaborate with cloud engineering and DevOps teams to design, implement, and validate security controls across AWS, Azure, and hybrid environments. • Review system changes and significant change requests to assess security impact, identify documentation updates, and maintain authorization boundaries. • Coordinate with system owners, engineers, 3PAOs, Authorizing Officials, and government stakeholders to address findings and support authorization outcomes. • Support continuous monitoring, vulnerability management, POA&M updates, remediation tracking, and recurring compliance deliverables. • Evaluate security tooling and data sources to identify opportunities for automated control validation and compliance reporting. • Track evolving federal cybersecurity requirements and translate them into practical technical and operational actions. Required Skills & Experience • Strong analytical, documentation, and problem-solving skills with a focus on secure and compliant outcomes. • Excellent communication and stakeholder-management skills, including the ability to advise partners, customers, engineers, and government stakeholders. • Ability to translate federal security requirements into practical technical controls and operational processes. • U.S. citizenship with the ability to obtain and maintain a Secret or higher security clearance. • Bachelor's degree in Information Security, Cybersecurity, Computer Science, or a related field, or equivalent practical experience. • Five or more years of cybersecurity experience, including at least three years supporting federal cloud security engineering, information assurance, RMF, or ISSO functions. • Knowledge of NIST SP 800-53 Rev. 5, FedRAMP Moderate and High, DoD IL4–6 overlays, RMF, and related federal compliance frameworks. • Experience developing and maintaining SSPs, POA&Ms, SARs, policies, control evidence, and other authorization artifacts. • Experience supporting authorization planning, gap assessments, audit readiness, control implementation, and remediation activities. • Hands-on experience with AWS, Azure, or hybrid cloud environments, including IAM, encryption, logging, configuration management, and security monitoring. • Experience using GRC platforms, APIs, scripting, or automation to improve compliance and security workflows. • Familiarity with tools such as eMASS, Paramify, Nessus/Tenable, Splunk, Prisma Cloud, or comparable solutions. • CISSP, CGRC/CAP, CISM, Security+, or similar cybersecurity certificate . Desired Skills & Experience • Experience supporting FedRAMP, DoD, DISA, or federal agency ATO activities. • Experience developing automation with Python, PowerShell, REST APIs, infrastructure-as-code, or cloud-native services. • Experience integrating vulnerability, configuration, and cloud-security data into GRC (Paramify) and POA&M workflows. • Familiarity with DevSecOps pipelines, automated security testing, policy-as-code, and continuous control validation. • Knowledge of FISMA, the Privacy Act, and agency-specific security requirements. #CJPOST At SMX®, we are a team of technical and domain experts dedicated to enabling your mission. From priority national security initiatives for the DoD to highly assured and compliant solutions for healthcare, we understand that digital transformation is key to your future success. We share your vision for the future and strive to accelerate your impact on the world. We bring both cutting edge technology and an expansive view of what's possible to every engagement. Our delivery model and unique approaches harness our deep technical and domain knowledge, providing forward-looking insights and practical solutions to power secure mission acceleration. SMX is an Equal Opportunity employer including disabilities and veterans. Selected applicant may be subject to a background investigation and/or education verification. SMX does not sponsor a new applicant for employment authorization or immigration related support for this position (i.e. H1B, F-1 OPT, F-1 STEM OPT, F-1 CPT, J-1, TN, E-2, E-3, L-1 and O-1, or any EADs or other forms of work authorization that require immigration support from an employer).
Create tailored applications specifically for SMX with our AI-powered resume builder
Get Started for Free