About the role
What will you do at Leidos?
Leidos was awarded the U.S. Air Force Cloud One Architecture and Common Shared Services contract and currently has an opening for a Cybersecurity and Cloud Automation Engineer to support AWS, Azure, Google, and Oracle clouds. This is an exciting opportunity to use your experience to modernize a leading, global-scale multi-cloud environment in support of a critical mission, supporting USAF system resiliency, security, and cost effectiveness.
Location: This position may require travel to support customer or corporate meetings near Hanscom AFB (Boston, MA), Huntsville, AL or Reston, VA. Role Summary: Dual-role engineer focused on securing and automating AWS environments using IaC, CaC, and Security-as-Code. Works within DevSecOps teams to design secure cloud solutions and build automated provisioning, configuration, and monitoring pipelines.
Core
Responsibilities
- Implement and maintain security controls for AWS services, aligned with NIST, FISMA, and DISA STIG requirements.
- Configure secure logging, monitoring, and telemetry (e.g., CloudTrail, CloudWatch, SIEM integrations) for cloud workloads.
- Perform vulnerability scanning, assessment, and coordination of remediation across cloud hosts, containers, and services.
- Contribute to security architecture reviews and change/configuration boards to ensure secure designs and deployments.
- IaC/CaC & Automation: Develop, maintain, and version-control IaC modules (e.g., Terraform, CloudFormation) for AWS networking, compute, storage, IAM, and security resources.
- Use CaC tools (e.g., Ansible, Puppet) to automate OS, middleware, and application configuration and hardening.
- Build and support CI/CD pipelines that integrate IaC/CaC and security checks for automated build, test, and deployment.
- Create and maintain hardened, STIG/CIS-aligned golden images and reusable templates for repeatable secure deployments.
- Security-as-Code & Compliance: Encode security baselines, IAM policies, network segmentation, and encryption standards into IaC/CaC and pipeline code (Security-as-Code).
- Integrate automated security and compliance testing (SAST/DAST, dependency scanning, policy-as-code) into pipelines to enforce controls before release.
- Support continuous monitoring and ATO/continuous authorization by maintaining evidence, automated checks, and documentation for audits.
- Operations & Zero Trust: Support day-to-day operation of multi-environment AWS landscapes (dev/test/stage/prod/DR), including monitoring health and performance.
- Troubleshoot issues across networking, access, and application deployment; contribute to incident and problem management and root cause analysis.
- Implement and maintain identity- and context-aware access controls, MFA, and policy-based access in line with Zero Trust strategies.
- Collaboration & Documentation: Collaborate with developers, cloud engineers, security analysts, and operations staff to design secure, automated solutions.
- Contribute to technical documentation, including architecture diagrams, IaC/CaC module references, SOPs, and runbooks.
- Share best practices in secure cloud engineering and automation with teammates; provide informal knowledge transfer and peer support (no direct reports).
- Required
Qualifications
- Bachelor’s degree in a technical field with 8 years of applicable experience, additional years of experience in cloud and cybersecurity engineering will be accepted in lieu of a degree.
- Hands-on experience with AWS cloud services and DevSecOps practices in production environments.
- Practical experience with IaC/CaC tools (e.g., Terraform/CloudFormation and Ansible/Puppet) and CI/CD pipelines.
- Experience applying NIST, FISMA, and STIG/CIS controls in cloud environments and supporting ATO/accreditation activities.
- Strong written and verbal communication skills and ability to work effectively in cross-functional teams.
Preferred Qualifications
- AWS certifications (e.g., Solutions Architect, Security Specialty) or security certifications such as CISSP, CISM, or CAP.
- Familiarity with Zero Trust architectures, SASE/ZTNA solutions, and ICAM integrations.
- US DoW Secret clearance.
- Access to SIPR Facility.
- C1NACSS If you're looking for comfort, keep scrolling.
- At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it.
- We're not hiring followers.
- We're recruiting the ones who disrupt, provoke, and refuse to fail.
- Step 10 is ancient history.
- We're already at step 30 — and moving faster than anyone else dares.
- Original Posting: July 1, 2026 For U.S.
- Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.
- Pay Range: Pay Range $107,900.00 - $195,050.00 The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary.
- Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.
- Leidos Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations.
- Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $17.2 billion for the fiscal year ended January 2, 2026.
- For more information, visit www.Leidos.com.
- Pay and Benefits Pay and benefits are fundamental to any career decision.
- That's why we craft compensation packages that reflect the importance of the work we do for our customers.
- Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement.
- More details are available here.
- Securing Your Data Leidos will never ask you to provide payment-related information at any part of the employment application process.
- And Leidos will communicate with you only through emails that are sent from a Leidos.com email address.
- If you receive an email purporting to be from Leidos that asks for payment-related information or any other personal information, please report the email to [email protected].
- Commitment and Diversity All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law.
- Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.
Which skills does this role require?
Make your next move
Build a shortlist and prepare
Identify the requirements you can demonstrate, then choose examples from your work to discuss with the hiring team.
- Build a focused shortlist before you applyCompare role requirements with your experience and give each application a clear reason.
- Practice explaining your experience in an interviewRehearse your answers before meeting the hiring team.
Other roles to compare
Review the responsibilities and requirements before adding an opening to your shortlist.
Security Engineer
Brightspot · Reston, Virginia, United States
Lead Engineer, Information Security (Application Security)
RXO, Inc. · United States
Cybersecurity Assessment Data Analyst
CACI International Inc · United States
Senior Network Security Engineer
GovCIO · United States
Network Security Engineer Master
GovCIO · United States
Senior Security Engineer
Credit Sesame · Mountain View, California, United States
Role information can change. Confirm current details on the original application page.
