ST

Principal Cloud Engineer

Space Telescope
Posted 2 hours ago
United StatesHybrid$160K–$175KEngineering & Development
Is this job info correct?

Are you seeking a mission critical role in expanding humanity’s knowledge of the Universe?

The Space Telescope Science Institute (STScI) is a multi-mission science and operations center for NASA’s flagship observatories. The Cloud Center of Excellence at STScI is seeking a Principal AWS Cloud Cybersecurity Automation & Systems (CACS) Engineer to join our team supporting NASA flagship space telescope missions that are transforming our understanding of the universe.

In this role, you will lead cloud security automation initiatives and apply platform engineering and Kubernetes practices to design, implement, and operate security controls, guardrails, and monitoring systems across the AWS cloud applications and environments supporting observatories such as the Hubble Space Telescope, the James Webb Space Telescope, and the Nancy Grace Roman Space Telescope (Roman). You will build the paved road that lets mission and science teams deliver securely by default, and you will own solutions from concept through production.

This position supports hybrid or fully remote work arrangements. Candidates must reside in MD, DE, VA, PA, DC, or WV. Hybrid staff are expected on-site a minimum of three days per week.

U.S. Citizenship or Permanent Residency required; ITAR clearance required.

Primary Responsibilities
  • Serve as the technical lead for cloud security automation, partnering with software engineers, Institute security engineers, and DevOps engineers to design and deliver secure cloud capabilities.
  • Take solutions from idea to production independently: identify the gaps, propose an approach, socialize it with stakeholders, and own delivery through implementation.
  • Design, deploy, and secure workloads on Amazon EKS, including cluster hardening, workload identity, admission control, and runtime protection.
  • Drive platform engineering implementation by building paved road tooling, reusable modules, and self-service capabilities so product teams can ship securely by default.
  • Build and maintain infrastructure as code using CloudFormation, Terraform, or CDK, with security controls and guardrails expressed as code.
  • Embed automated security testing and policy enforcement into CI/CD pipelines.
  • Build and operate automated incident response workflows spanning detection, triage, containment, and remediation.
  • Evaluate and implement agentic AI capabilities to automate security engineering and operational tasks, with appropriate guardrails and human review.
  • Collaborate across engineering, IT, and other security teams, and build relationships with internal customers to identify needs and increase the impact of the team's work.
Required Qualifications
  • Minimum of 10 years of experience in one or more of the following roles: Software Developer, System Development Engineer, Site Reliability Engineer, or DevOps Engineer.
  • Minimum of 7 years of experience as a Cloud Security Automation Engineer or Cloud DevSecOps Engineer.
  • Hands-on experience deploying and operating Amazon EKS in production.
  • Demonstrated experience implementing platform engineering practices, including internal developer platforms or self-service tooling.
  • Deep expertise in AWS cloud security and automation.
  • Expertise with infrastructure as code using CloudFormation, Terraform, or CDK.
  • Experience designing and operating automated incident response.
  • Strong grounding in DevOps principles and automated security testing within CI/CD.
  • Applied knowledge of cloud security best practices and control frameworks.
  • Proven ability to work independently and drive solutions to completion through active stakeholder engagement.
Preferred Qualifications
  • Experience with single sign-on platforms such as Okta, Auth0, or similar.
  • Experience with log management and dashboarding using Datadog, ELK, or similar platforms.
  • Experience implementing agentic AI or LLM-based automation in an engineering or security context.
  • Professional-level certifications such as AWS Certified DevOps Engineer – Professional, AWS Certified Solutions Architect – Professional, and a Kubernetes certification such as Certified Kubernetes Administrator (CKA) or Certified Kubernetes Security Specialist (CKS)

The substitution of additional relevant education and/or experience for stated qualifications may be considered.

Salary range is $160,000 - $175,000. Final compensation is based on experience, skills, internal equity, and market conditions. The posted salary range represents a general guideline. STScI considers several factors when determining salary offers, including internal equity, position scope and responsibilities, candidate qualifications, experience, education, skills, and current market conditions.

TO APPLY: Share your experience by uploading a resume and completing an online application. Applications received by 10/22/26 will receive full consideration. Applications received after this date will be considered until the position is filled.

Reference: 0016538

Please use this link to apply: Principal Cloud Engineer

We offer an excellent and generous benefits package, tuition reimbursement, flexible work schedules and a stimulating and diverse work environment. Explore our benefits:

http://www.stsci.edu/opportunities/benefits

Our world-class astronomical research center is based on the Johns Hopkins University Homewood campus in Baltimore, Maryland. Visit our website to learn more about our missions

Individuals needing assistance with the employment process can contact us at careers@stsci.edu.

#LIHYBRID

Similar jobs