Logo for BizFirst LLC

Cloud Security Engineer, U.S. Customs and Border Protection (CBP), Remote (East Coast)

Role overview

Qualifications

  • U.S. citizenship
  • At least seven (7) years of experience in cybersecurity, cloud, or systems engineering
  • Hands-on experience with AWS IAM, VPC security, KMS, and AWS native security services
  • Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or a related field

Responsibilities

  • Design and implement security controls for AWS environments, including IAM, network segmentation, encryption and key management (KMS), and logging
  • Configure and operate AWS security services, including Security Hub, GuardDuty, Config, CloudTrail, Inspector, and WAF
  • Integrate security into CI/CD pipelines: static and dynamic code analysis, container image scanning, and infrastructure-as-code scanning
  • Run vulnerability management: scan, prioritize, and track findings to remediation through POAMs

Key facts

Hard skills

About the company

BizFirst LLC logo

BizFirst LLC

IT Services & IT Consulting

BizFirst is an US-based company dedicated to bridging the talent gap in the small business, commercial, enterprise, and public government sectors. Offering tailored services from te3mporary contractors to direct hiring and consulting, we enable organizations to efficiently meet their staffing objectives. Through our advanced AI-matching platform, we ensure candidates' skills align perfectly with our clients' needs. Our dedicated team is passionate about building enduring relationships with both companies and candidates, paving the way for mutual success.

Company details

Company typeStartup
IndustryIT Services & IT Consulting
Company size11 - 50

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

This is a remote position.

Cloud Security Engineer, U.S. Customs and Border Protection (CBP), Remote (East Coast)

Summary:

  • Job Title: Cloud Security Engineer
  • Level: Senior (7+ years in cybersecurity or cloud engineering, including 3+ years securing AWS environments)
  • Openings: Multiple
  • Security Clearance: U.S. citizenship required. Must be able to obtain and maintain a CBP Public Trust background investigation. An existing DHS Public Trust (CBP, ICE, USCIS, CISA, or another DHS component) is preferred; other federal clearances, including Secret or Top Secret, will be reviewed and may require additional processing.
  • Work Type: Remote: East Coast working hours, with travel approximately once per quarter; candidates in the Washington, DC area preferred
  • Job Type: Full-time
  • Agency name: U.S. Customs and Border Protection (CBP), Department of Homeland Security
  • Start Date: Immediate. Start follows a favorable suitability determination and completion of customer onboarding.

BizFirst is assisting our client with recruiting skilled and experienced Cloud Security Engineers. This position supports a four-year U.S. Customs and Border Protection (CBP) program to move the agency's applications to the cloud; our client is the prime contractor and incumbent. CBP has set a goal of moving all 276 of its applications to the cloud by January 2028 while advancing a zero trust architecture. Cloud Security Engineers secure those environments, build security into delivery pipelines, and keep systems in line with federal controls such as NIST. The role is fully remote on East Coast hours and requires U.S. citizenship and the ability to obtain a CBP Public Trust.

Our client is an IT solutions and services company based in Alpharetta, Georgia, founded in 2000 to build mission-critical systems that run around the clock. Its cloud experts design and build cloud infrastructure on AWS, Azure, and Google Cloud, with work spanning cloud strategy and architecture, cloud modernization and engineering, security and compliance, cloud DevOps, and data and analytics. Federal civilian agencies are a core part of that work, supported through a GSA Multiple Award Schedule contract, and the company is an AWS Advanced Tier Services Partner.

What will you do

Secure the AWS environments that host CBP mission applications. You will implement and operate cloud security controls, build security checks into delivery pipelines, manage vulnerabilities, and support the Authority to Operate (ATO) and continuous monitoring process. You will work with platform engineers, developers, and CBP security staff to make security proactive and built in, not an after-the-fact compliance exercise.

Responsibilities:

  • Design and implement security controls for AWS environments, including IAM, network segmentation, encryption and key management (KMS), and logging.
  • Configure and operate AWS security services, including Security Hub, GuardDuty, Config, CloudTrail, Inspector, and WAF.
  • Integrate security into CI/CD pipelines: static and dynamic code analysis, container image scanning, and infrastructure-as-code scanning.
  • Run vulnerability management: scan, prioritize, and track findings to remediation through POA&Ms.
  • Support ATO and continuous monitoring: map controls to NIST SP 800-53 and DHS 4300A, gather evidence, and update system security plans.
  • Harden systems, containers, and Kubernetes clusters to DISA STIGs and CIS Benchmarks.
  • Support zero trust architecture work, including identity-based access, micro-segmentation, and least privilege.
  • Detect and respond to security events using SIEM tools such as Splunk; support incident response and root cause analysis.
  • Automate security checks and remediation with Python, AWS Lambda, or policy as code.
  • Review cloud architectures and changes for security risk and advise engineering teams.

Requirements:

  • U.S. citizenship.
  • Able to obtain and maintain a CBP Public Trust background investigation.
  • At least seven (7) years of experience in cybersecurity, cloud, or systems engineering, including at least three (3) years securing AWS environments.
  • Hands-on experience with AWS IAM, VPC security, KMS, and AWS native security services.
  • Working knowledge of NIST SP 800-53, the Risk Management Framework (RMF), and federal ATO processes.
  • Experience with vulnerability scanning tools (Tenable/Nessus, Qualys, or Prisma Cloud) and SIEM platforms such as Splunk.
  • Experience securing containers and Kubernetes.
  • Scripting in Python or Bash; infrastructure as code with Terraform.
  • Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or a related field.
  • Able to work remotely on East Coast hours and travel approximately once per quarter.

Desired Skills

  • CISSP, CCSP, or AWS Certified Security Specialty.
  • Experience with DHS 4300A, Continuous Diagnostics and Mitigation (CDM), and FedRAMP.
  • Experience with AWS GovCloud (US).
  • Experience supporting DHS or CBP systems.
  • A current DHS Public Trust (CBP, ICE, USCIS, CISA, or another DHS component).

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Cloud Security Engineer Related jobs

Other jobs at BizFirst LLC

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.