Information System Security Engineer (ISSE) AWS Cloud Security - Clearance Required

Security EngineerSecurity EngineerOtherRemoteMid LevelTeam 1,001-5,000

Location

United States

Posted

2 days ago

Salary

$90.3K - $155K / year

Seniority

Mid Level

Job Description

Overview

LMI is seeking a skilled Information System Security Engineer (ISSE) with hands-on experience in AWS cloud security to provide advanced cybersecurity engineering and Risk Management Framework (RMF) support for Department of Defense (DoD) cloud-based systems. This position focuses on designing, implementing, and maintaining secure AWS environments aligned with DoD Cloud Computing Security Requirements Guide (CC SRG), NIST SP 800-53, and DISA STIGs/SRGs to support Authorization to Operate (ATO) efforts.

 

LMI is a new breed of digital solutions provider dedicated to accelerating government impact with innovation and speed. Investing in technology and prototypes ahead of need, LMI brings commercial-grade platforms and mission-ready AI to federal agencies at commercial speed.

 

Leveraging our mission-ready technology and solutions, proven expertise in federal deployment, and strategic relationships, we enhance outcomes for the government, efficiently and effectively. With a focus on agility and collaboration, LMI serves the defense, space, healthcare, and energy sectors—helping agencies navigate complexity and outpace change. Headquartered in Tysons, Virginia, LMI is committed to delivering impactful results that strengthen missions and drive lasting value.

 

This position can be remote but requires quarterly travel for planning increments.

 

This position requires an active SECRET clearance; TS/SCI preferred.

Responsibilities

  • Architect and manage robust access control strategies using AWS Identity and Access Management (IAM), enforcing the principle of Least Privilege across all roles and users.

  • Implement encryption and key management solutions using AWS Key Management Service (KMS) and related tools to protect data at rest and in transit, aligning with DoD data classification standards.

  • Deploy and configure native AWS security services (e.g. GuardDuty, Security Hub, Inspector, and Config) to provide continuous threat detection, compliance monitoring, and automated remediation.

  • Collaborate with network teams to secure VPCs using AWS Network Firewall, WAF, and hybrid connectivity solutions (Direct Connect, VPN) within a GovCloud environment.

  • Lead technical implementation and validation of NIST SP 800-53 and DoD CC SRG controls to achieve and maintain ATO.

  • Serve as a technical SME for RMF documentation and artifact generation within eMASSor other DoD compliance systems.

  • Design, test, and implement DISA STIG/SRG-based configuration hardening across AWS services, operating systems, and containerized workloads.

  • Conduct continuous vulnerability scanning and monitoring using DoD-approved tools (ACAS/Nessus), coordinating remediation and risk mitigation activities.

  • Integrate security into CI/CD pipelines using Infrastructure-as-Code (IaC) tools such as Terraform or CloudFormation to automate compliance and security controls.

  • Build and maintain centralized, compliant logging architectures using Splunk, Elastic, or equivalent SIEM platformsto ensure event visibility and retention per DoD policy.

  • Participate in incident response activities for cloud-based threats, performing forensic analysis and recommending corrective actions.

  • Collaborate with DoD stakeholders, system owners, and developers to embed security throughout the system lifecycle and support RMF accreditation efforts.

Qualifications

  • Active SECRET clearance required; TS/SCI preferred

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or related field (or equivalent experience)

  • 3–5+ years of experience in information security, with at least 3 years focused on AWS cloud security engineering

  • Deep experience with DoD RMF, NIST SP 800-53, DoD CC SRG, and DISA STIG/SRG compliance frameworks

  • Strong hands-on expertise with AWS security services (IAM, KMS, GuardDuty, Security Hub, Config)

  • Experience with Docker, Kubernetes, and system hardening for Linux/Windows environments

  • Proficiency in IaC tools (Terraform, CloudFormation) for managing and enforcing security policies

  • Familiarity with ACAS/Nessus, continuous monitoring, and vulnerability management processes

  • Experience integrating security within DevSecOps and CI/CD workflows

  • Certifications:

    • DoD 8570/8140-M compliant (e.g., CISSP, CASP+, CISM) – required

    • AWS Certified Security – Specialty – highly preferred

    • Kubernetes certification (CKS/CKA) – a plus

Target Salary Range: $90,270.00 - $155,037.00

 

Disclaimer: 

 

The salary range displayed represents the typical salary range for this position and is not a guarantee of compensation. Individual salaries are determined by various factors including, but not limited to location, internal equity, business considerations, client contract requirements, and candidate qualifications, such as education, experience, skills, and security clearances.

Job Requirements

  • Active SECRET clearance required; TS/SCI preferred
  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or related field (or equivalent experience)
  • 3–5+ years of experience in information security, with at least 3 years focused on AWS cloud security engineering
  • Deep experience with DoD RMF, NIST SP 800-53, DoD CC SRG, and DISA STIG/SRG compliance frameworks
  • Strong hands-on expertise with AWS security services (IAM, KMS, GuardDuty, Security Hub, Config)
  • Experience with Docker, Kubernetes, and system hardening for Linux/Windows environments
  • Proficiency in IaC tools (Terraform, CloudFormation) for managing and enforcing security policies
  • Familiarity with ACAS/Nessus, continuous monitoring, and vulnerability management processes
  • Experience integrating security within DevSecOps and CI/CD workflows
  • Certifications: DoD 8570/8140-M compliant (e.g., CISSP, CASP+, CISM) – required
  • AWS Certified Security – Specialty – highly preferred
  • Kubernetes certification (CKS/CKA) – a plus
  • Target Salary Range: $90,270.00 - $155,037.00
  • The salary range displayed represents the typical salary range for this position and is not a guarantee of compensation. Individual salaries are determined by various factors including, but not limited to location, internal equity, business considerations, client contract requirements, and candidate qualifications, such as education, experience, skills, and security clearances.

Related Categories

Related Job Pages

More Security Engineer Jobs

Istari Digital logo

Cybersecurity Engineer

Istari Digital

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

OtherRemoteTeam 51-200

We are hiring a Cybersecurity Engineer to support customer deployments in classified environments, ensuring Istari’s platform operates securely, compliantly, and reliably in real-world mission systems. This role sits within Customer Success and focuses on hands-on system and in...

United States
$116K - $174K / year
Sunrun logo

Application Security Engineer

Sunrun

Life Runs on Clean Energy

OtherRemoteTeam 10,001+Since 2007H1B Sponsor

The Application Security Engineer will drive the identification, assessment, and mitigation of security risks across applications from design through deployment, collaborating with developers to integrate robust security practices.

United States
$154K - $185K / year
CNO Financial Group, Inc. logo

Sr IT Identity Security Engineer

CNO Financial Group, Inc.

CNO Financial Group, Inc. (NYSE: CNO) secures the future of middle-income America. CNO provides life and health insurance, annuities, financial services and workforce benefits solutions through our family of brands, including Bankers Life, Colonial Penn, Optavise and Washington National. Our customers work hard to save for the future, and we help protect their health, income and retirement needs with 3.3 million policies and more than $38.3 billion in total assets. We are financially strong and well positioned for continued growth, grounded in our core values of People Focused, Integrity, Customer Driven, and Excellence. We have offices in more than 220 communities in the U.S., including our headquarters in Carmel, Indiana, and corporate offices in Birmingham, Chicago, Orlando and Milwaukee. At CNO Financial Group, we’re always looking forward—to the security and stability we help create for our insurance brands’ customers, and the growth we create within our own company. We're looking for ambitious people who want to do more. We'll provide you with opportunities to grow your skills through challenging professional experiences. If you're looking for a culture that encourages development, helps you reach your potential, and rewards you for your contribution, then CNO Financial Group is right for you. For more information, visit CNOinc.com.

OtherRemoteTeam 201-500

The Senior IT Identity Security Engineer will act as the senior expert for Identity and Access Management (IAM) Identity Automation (IA) security, communicating security concepts related to automated identity provisioning and governance. This role involves leading the design and implementation of IAM IA security tools, monitoring system performance, and optimizing resources to enhance the IA environment's effectiveness and security.

United States
$107K - $161K / year
Manpower/itec logo

Functional Lead, Firewall Policy Management

Manpower/itec

Since 1999, ITEC has delivered mission-critical support to the DoD and Intelligence Community. Now part of ManpowerGroup Public Sector (MGPS), we continue that work with expanded capabilities.

The Functional Lead will be responsible for collaborating with multiple internal stakeholders to assist with functional planning, establish scope/requirements, solution design, documentation, and testing solutions. In addition, the Functional Lead will be responsible for reviewin...

United States