Cloud Security Engineer, U.S. Customs and Border Protection (CBP), Remote (East Coast)
- Hiring from
- United States
- Work type
- Remote
- Posted
- Sep 29, 2026
Job Description
This is a remote position.
Cloud Security Engineer, U.S. Customs and Border Protection (CBP), Remote (East Coast)
Summary:
- Job Title: Cloud Security Engineer
- Level: Senior (7+ years in cybersecurity or cloud engineering, including 3+ years securing AWS environments)
- Openings: Multiple
- Security Clearance: U.S. citizenship required. Must be able to obtain and maintain a CBP Public Trust background investigation. An existing DHS Public Trust (CBP, ICE, USCIS, CISA, or another DHS component) is preferred; other federal clearances, including Secret or Top Secret, will be reviewed and may require additional processing.
- Work Type: Remote: East Coast working hours, with travel approximately once per quarter; candidates in the Washington, DC area preferred
- Job Type: Full-time
- Agency name: U.S. Customs and Border Protection (CBP), Department of Homeland Security
- Start Date: Immediate. Start follows a favorable suitability determination and completion of customer onboarding.
BizFirst is assisting our client with recruiting skilled and experienced Cloud Security Engineers. This position supports a four-year U.S. Customs and Border Protection (CBP) program to move the agency's applications to the cloud; our client is the prime contractor and incumbent. CBP has set a goal of moving all 276 of its applications to the cloud by January 2028 while advancing a zero trust architecture. Cloud Security Engineers secure those environments, build security into delivery pipelines, and keep systems in line with federal controls such as NIST. The role is fully remote on East Coast hours and requires U.S. citizenship and the ability to obtain a CBP Public Trust.
Our client is an IT solutions and services company based in Alpharetta, Georgia, founded in 2000 to build mission-critical systems that run around the clock. Its cloud experts design and build cloud infrastructure on AWS, Azure, and Google Cloud, with work spanning cloud strategy and architecture, cloud modernization and engineering, security and compliance, cloud DevOps, and data and analytics. Federal civilian agencies are a core part of that work, supported through a GSA Multiple Award Schedule contract, and the company is an AWS Advanced Tier Services Partner.
What will you do
Secure the AWS environments that host CBP mission applications. You will implement and operate cloud security controls, build security checks into delivery pipelines, manage vulnerabilities, and support the Authority to Operate (ATO) and continuous monitoring process. You will work with platform engineers, developers, and CBP security staff to make security proactive and built in, not an after-the-fact compliance exercise.
Responsibilities:
- Design and implement security controls for AWS environments, including IAM, network segmentation, encryption and key management (KMS), and logging.
- Configure and operate AWS security services, including Security Hub, GuardDuty, Config, CloudTrail, Inspector, and WAF.
- Integrate security into CI/CD pipelines: static and dynamic code analysis, container image scanning, and infrastructure-as-code scanning.
- Run vulnerability management: scan, prioritize, and track findings to remediation through POA&Ms.
- Support ATO and continuous monitoring: map controls to NIST SP 800-53 and DHS 4300A, gather evidence, and update system security plans.
- Harden systems, containers, and Kubernetes clusters to DISA STIGs and CIS Benchmarks.
- Support zero trust architecture work, including identity-based access, micro-segmentation, and least privilege.
- Detect and respond to security events using SIEM tools such as Splunk; support incident response and root cause analysis.
- Automate security checks and remediation with Python, AWS Lambda, or policy as code.
- Review cloud architectures and changes for security risk and advise engineering teams.
Requirements:
- U.S. citizenship.
- Able to obtain and maintain a CBP Public Trust background investigation.
- At least seven (7) years of experience in cybersecurity, cloud, or systems engineering, including at least three (3) years securing AWS environments.
- Hands-on experience with AWS IAM, VPC security, KMS, and AWS native security services.
- Working knowledge of NIST SP 800-53, the Risk Management Framework (RMF), and federal ATO processes.
- Experience with vulnerability scanning tools (Tenable/Nessus, Qualys, or Prisma Cloud) and SIEM platforms such as Splunk.
- Experience securing containers and Kubernetes.
- Scripting in Python or Bash; infrastructure as code with Terraform.
- Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or a related field.
- Able to work remotely on East Coast hours and travel approximately once per quarter.
Desired Skills
- CISSP, CCSP, or AWS Certified Security Specialty.
- Experience with DHS 4300A, Continuous Diagnostics and Mitigation (CDM), and FedRAMP.
- Experience with AWS GovCloud (US).
- Experience supporting DHS or CBP systems.
- A current DHS Public Trust (CBP, ICE, USCIS, CISA, or another DHS component).