Cloud Security Engineer
Overview
In this role you will design and operate secure cloud environments to support government and intelligence missions, safeguarding sensitive data across AWS GovCloud, Azure, and multi-cloud setups. You’ll drive compliance with NIST, FedRAMP, RMF, and DoD IL requirements while enabling secure modern cloud practices. Join a fast-growing aerospace startup and help protect critical workloads as Apex scales its satellite bus platforms. You will collaborate cross-functionally to integrate security into CI/CD and IaC practices, delivering tangible security posture improvements.
Compensation / Benefitsequity in Apex100% company-paid healthcare, dental, visionPTO 15–20 days + 10 holidays401(k) with company match8 weeks paid parental leave and childcare reimbursementon-site meals and snacks
ResponsibilitiesDesign and implement secure cloud architectures across AWS GovCloud, Azure, and GCPMaintain compliance with NIST 800-53 Rev. 5, FedRAMP, DoD ILs, RMF, and SCCA requirementsManage IAM/RBAC, JIT access, Key Vaults, and Zero Trust principlesDeploy and optimize cloud-native security tools (Microsoft Defender for Cloud, Azure Sentinel, AWS GovCloud services, CSPM/CWPP, Elastic SIEM)Perform vulnerability assessments, PT/reds-teaming simulations, and security reviews against STIGs/CIS/NISTDevelop and update System Security Plans (SSP), SARs, POA&Ms, and risk/compliance reportingRespond to IoCs, threat intel, and security incidents with root-cause analysis and preventive controlsConduct periodic security reviews across Azure, AWS, and hybrid environments and maintain security policiesCollaborate with DevSecOps and development teams to secure CI/CD pipelines and IaC practicesGuide and educate teams on secure cloud design patterns and best practicesCoordinate with configuration management to ensure security across hardware/software changesMonitor for security incidents and coordinate response activitiesIdentify emerging threats and drive automation to improve security postureProvide training on secure cloud patterns to engineering teamsBe on-site 5 days a week at Playa Vista, CA
Key requirementsBachelor’s degree in Cybersecurity, Information Assurance, Computer Science, or related field; or 5+ years of equivalent cloud security experience5–9+ years of cloud security engineering experience in AWS GovCloud, Azure Government, or multi-cloud environmentsStrong analytical, problem-solving, communication, and collaboration skills in fast-paced settingsstrong communicationcollaborationproblem-solvingAWS GovCloud and Azure Government knowledgeIAM/RBAC, encryption, network securitycloud-native security services; SIEM; vulnerability scanners; threat intelligence