Cloud Security Specialist (AWS) – Washington, DC
About us
Creative Information Technology Inc (CITI) is an esteemed IT enterprise renowned for its exceptional customer service and innovation. We serve both government and commercial sectors, offering a range of solutions such as Healthcare IT, Human Services, Identity Credentialing, Cloud Computing, and Big Data Analytics. With clients in the US and abroad, we hold key contract vehicles including GSA IT Schedule 70, NIH CIO-SP3, GSA Alliant, and DHS-Eagle II.
Join us in driving growth and seizing new business opportunities.
Role and Responsibilities
We are seeking a Senior Cloud Security Specialist to support the Security Engineering team. This team is responsible for the strategy, design, deployment, and maintenance of effective security solutions in cloud, local, and hybrid environmentsConduct regular security reviews of cloud infrastructure deployed by engineering teams Evaluate infrastructure-as-code against security standards Review and validate compliance with security policies and best practices Assess adherence to AWS Well-Architected Framework security pillar Identify and document security misconfigurations and non-compliant controls Develop and maintain security posture dashboards Create or update security configuration guides and playbooks Offer technical consultation to engineering teams on secure implementation Implement AWS security controls and services to ensure proper security hardening and other security engineering tasks. Develop and update AWS security configuration standards Conduct security training sessions for engineering teams Present findings and recommendations in team meetings Identify opportunities to automate security assessments Recommend security tooling improvementsAWS Certified Security - Specialty (strongly preferred) AWS Certified Solutions Architect - Professional or Associate Demonstrated experience implementing secure, scalable AWS cloud architectures following industry best security practices and security frameworks. Demonstrated federal experience and comprehensive knowledge in adopting and implementing federal cybersecurity requirements, including but not limited to the NIST Cybersecurity Framework, OMB Memorandum M-22-09, NIST SP 800-53 Possess deep analytical, problem-solving, and troubleshooting experience, to independently resolve complex security challenges. Proven ability to provide technical security consultation and advisory services with a proactive approach to identifying potential issues, raising questions, and engaging in open dialogue with team members and stakeholders to ensure security objectives are met. Strong understanding of security concepts and technologies related to Identity and Access Management (IAM), security engineering, network security design, security operations, security architecture, general engineering processes, cloud security, data loss protection, zero trust, DevSecOps and vulnerability management. Technical skills in AWS cloud security, security engineering, DevSecOps, scripting, and Infrastructure-as-code (IaC) Self-motivated and able to work independently Strong attention to detailMinimum Qualification
Minimum 5 years hands-on AWS security experienceCloud Security Specialist – Washington, DC
About us
Creative Information Technology Inc (CITI) is an esteemed IT enterprise renowned for its exceptional customer service and innovation. We serve both government and commercial sectors, offering a range of solutions such as Healthcare IT, Human Services, Identity Credentialing, Cloud Computing, and Big Data Analytics. With clients in the US and abroad, we hold key contract vehicles including GSA IT Schedule 70, NIH CIO-SP3, GSA Alliant, and DHS-Eagle II.
Join us in driving growth and seizing new business opportunities.
Role and Responsibilities
We are seeking a Senior Cloud Security Specialist to support the Security Engineering team. This team is responsible for the strategy, design, deployment, and maintenance of effective security solutions in cloud, local, and hybrid environments.
API integration architecture document detailing out the integrations between cloud systems. Data model and attribute mapping across cloud systems. Automation scripts and orchestration (serverless functions, scheduled jobs, event handlers) Build resilient, secure API integrations between cloud applications in support of an end to-end data access management solution. Comprehensive testing and documentation of cloud integrations Support data loss prevention and cloud access security broker cloud initiatives Work across multiple teams as a Cloud Security Engineer SME to support security design, build, implementation, and monitoring of cloud platforms, applications, and tools. Offer technical consultation to cloud engineering teams on secure implementations Create or update security configuration guides and playbooksMinimum Qualification
Extensive REST API experience specifically in implementing, securing, automating, testing, and documenting API integrations. Strong understanding of resilient integration patterns including error handling, retry mechanisms, and monitoring strategies Proficient in scripting and automation languages for security orchestrationPreferred Qualification
AWS Certified Security - Specialty (strongly preferred)AWS Certified Solutions Architect - Professional or AssociatePrefer experience with integrations between ServiceNow, Collibra, and SaviyntExperience implementing cloud-native serverless architectures and servicesExperience architecting and implementing security controls across public cloud platformsExperience implementing DevSecOps practices including continuous integration/deployment pipelines and infrastructure as code methodologiesExperience implementing cloud access security broker (CASB) solutions for SaaS application security and visibilityStrong understanding of security concepts and technologies related to Identity and AccessManagement (IAM), security engineering, network security design, security operations, security architecture, general engineering processes, cloud security, data loss protection, zero trust, DevSecOps and vulnerability management.Demonstrated federal experience and comprehensive knowledge in adopting and implementing federal cybersecurity requirements, including but not limited to the NIST Cybersecurity Framework, OMB Memorandum M-22-09, NIST SP 800-53Possess deep analytical, problem-solving, and troubleshooting experience, to independently resolve complex security challenges.Proven ability to provide technical security consultation and advisory services with a proactive approach to identifying potential issues, raising questions, and engaging in open dialogue with team members and stakeholders to ensure security objectives are met