Logo for Coalfire

Cloud Engineer - FEDRAMP

Role overview

Qualifications

  • BS or above in a related Information Technology field or equivalent combination of education and experience
  • 5+ years in cloud, security, or platform engineering
  • 5+ years supporting cloud architecture, design, implementation, operations, and automation in AWS, Azure, or GCP
  • Experience with Infrastructure-as-Code and orchestration/automation tools such as Terraform and Ansible

Responsibilities

  • Design and implement the security capabilities that satisfy FedRAMP’s Key Security Indicators (KSIs) within your team’s specialty domains
  • Build the Security Decision Record (SDR) automation that deploys those capabilities repeatably across many client environments
  • Develop automated validation and continuous-monitoring evidence for each capability
  • Mentor junior team members by reviewing their work, sharing best practices, and guiding them through troubleshooting and operational standards

About the company

Coalfire logo

Coalfire

Cybersecurity

The world’s leading organizations – including the top five cloud service providers and leaders in financial services, healthcare, and retail – trust Coalfire to elevate their cyber programs and secure the future of their business. #1 in compliance, FedRAMP®, and cloud penetration testing, Coalfire is the world’s largest firm dedicated to cybersecurity services, providing unparalleled technology-enabled professional and managed services. To learn more, visit coalfire.com.

Company details

Company typeLarge
IndustryCybersecurity
Company size1001 - 5000

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

About Coalfire
 
Coalfire is on a mission to make the world a safer place by solving our clients’ hardest cybersecurity challenges. We work at the cutting edge of technology to advise, assess, automate, and ultimately help companies navigate the ever-changing cybersecurity landscape. We are headquartered in Chicago, Illinois with offices across the U.S. and U.K., and we support clients around the world.
 
But that’s not who we are – that’s just what we do.
 
We are thought leaders, consultants, and cybersecurity experts, but above all else, we are a team of passionate problem-solvers who are hungry to learn, grow, and make a difference.

Why Join Us

Under FedRAMP, compliance is no longer a document—it’s a set of Key Security Indicators (KSIs): measurable security outcomes validated through automation, continuously. Coalfire organizes its delivery engineering into capability-focused teams, each owning a set of KSI domains such as identity and access management, monitoring and logging, change management, or incident recovery. We’re looking for a Cloud Engineer to go deep on a team’s domains—building the standard implementation once, making it deployable anywhere, and landing it in client environment after client environment, getting better every time. If you’re driven by a desire to innovate, excel at operational excellence, and thrive in a collaborative environment, come be part of a team committed to making the world a safer place.


What You'll Do

· Design and implement the security capabilities that satisfy FedRAMP’s Key Security Indicators (KSIs) within your team’s specialty domains.

· Build the Security Decision Record (SDR) automation that deploys those capabilities repeatably across many client environments—infrastructure-as-code, pipelines, and configuration baselines, not one-off builds.

· Develop automated validation and continuous-monitoring evidence for each capability, so the certified state is provable every day.

· Deploy into client environments as the subject-matter expert for your domain: land the capability, integrate it with the client’s stack, troubleshoot, and harden.

· Bring lessons from every deployment back to your team, improving the standard implementation for the next client.

· Mentor junior team members by reviewing their work, sharing best practices, and guiding them through troubleshooting and operational standards.

· Contribute to documentation, runbooks, and machine-readable compliance artifacts.

· Support both new FedRAMP environment builds and the modernization of existing ones.

· Author and peer review detailed design and security documentation, inclusive of vendor best practices.

 

WORK ENVIRONMENT/TRAVEL REQUIRED:

Travel: Approximately 10%, driven by client needs

U.S. citizenship is required, as this position supports federal compliance programs.


What You'll Bring

· BS or above in a related Information Technology field or equivalent combination of education and experience

· 5+ years in cloud, security, or platform engineering

· 5+ years supporting cloud architecture, design, implementation, operations, and automation in AWS, Azure, or GCP

· Experience with Infrastructure-as-Code and orchestration/automation tools such as Terraform and Ansible

· Automation-first mindset with strong Infrastructure-as-Code (Terraform or equivalent), CI/CD, and scripting (Python, Go, or similar); exposure to policy-as-code

· Hands-on depth with at least one major cloud platform (AWS, Azure, or GCP) and its native services

· Working knowledge of NIST 800-53, FedRAMP, or comparable security control frameworks

· The instinct to solve a problem once, properly, and package the solution so it works everywhere

· Excellent communication, organizational, and problem-solving skills

· Effective documentation skills, including technical diagrams and written descriptions

· Ability to work independently and as part of a team with a professional attitude and demeanor

· Critical thinking, and the ability to balance security requirements with mission needs

REQUIRED CERTIFICATIONS:

· Associate-level (or higher) certification in AWS, Azure, or GCP


Bonus Points

· Direct familiarity with FedRAMP 20x and Key Security Indicators (KSIs)

· Experience with OSCAL or JSON machine-readable compliance formats

· Depth in a likely specialty area: identity (SSO, phishing-resistant MFA), SIEM and log pipelines, vulnerability management, or resilience engineering

· Relevant certifications such as cloud security specialty certifications, CISSP, or GIAC

· Previous experience supporting clients from within a professional services organization

· Familiarity with configuration baseline standards such as CIS Benchmarks & DISA STIG

· Familiarity with frameworks such as FedRAMP, FISMA, HIPAA, HITRUST, or PC

Why You’ll Want to Join Us
 
At Coalfire, you’ll find the support you need to thrive personally and professionally. In many cases, we provide a flexible work model that empowers you to choose when and where you’ll work most effectively – whether you’re at home or an office.
 
Regardless of location, you’ll experience a company that prioritizes connection and wellbeing and be part of a team where people care about each other and our communities. You’ll have opportunities to join employee resource groups, participate in in-person and virtual events, and more. And you’ll enjoy competitive perks and benefits to support you and your family, like paid parental leave, flexible time off, certification and training reimbursement, digital mental health and wellbeing support membership, and comprehensive insurance options.
 
At Coalfire, equal opportunity and pay equity is integral to the way we do business. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. Coalfire is committed to providing access, equal opportunity, and reasonable accommodation for individuals with disabilities in employment, its services, programs, and activities. To request reasonable accommodation to participate in the job application or interview process, contact our Human Resources team at HumanResourcesMB@coalfire.com.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Cloud Engineer Related jobs

Other jobs at Coalfire

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.