Cloud / DevOps Exploitation Specialist
AWSTerraformAnsibleCI/CDKubernetesDockerPythonBashPowerShellCheckov
About the Role
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Cloud / DevOps Exploitation Specialist based in the United States. As a Cloud / DevOps Exploitation Specialist, you will build, secure, assess, and continuously improve AWS environments supporting proactive cybersecurity operations. This hands-on role combines advanced cloud engineering, infrastructure-as-code, DevSecOps automation, and authorized security assessment. You will use Terraform and Ansible to create repeatable, version-controlled infrastructure while evaluating cloud, identity, CI/CD, container, and supply-chain security. Working in support of federal cybersecurity missions, you will help uncover exposures across externally and internally visible digital assets and turn findings into actionable remediation guidance. The role offers significant technical ownership within a collaborative environment spanning cloud engineering, attack-surface testing, and customer platform teams. Your work will contribute directly to strengthening the resilience, visibility, and security of critical government infrastructure. This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Cloud / DevOps Exploitation Specialist based in the United States. As a Cloud / DevOps Exploitation Specialist, you will build, secure, assess, and continuously improve AWS environments supporting proactive cybersecurity operations. This hands-on role combines advanced cloud engineering, infrastructure-as-code, DevSecOps automation, and authorized security assessment. You will use Terraform and Ansible to create repeatable, version-controlled infrastructure while evaluating cloud, identity, CI/CD, container, and supply-chain security. Working in support of federal cybersecurity missions, you will help uncover exposures across externally and internally visible digital assets and turn findings into actionable remediation guidance. The role offers significant technical ownership within a collaborative environment spanning cloud engineering, attack-surface testing, and customer platform teams. Your work will contribute directly to strengthening the resilience, visibility, and security of critical government infrastructure. Accountabilities: Design, implement, and maintain AWS infrastructure across networking, IAM, compute, storage, data, logging, and security services using reusable Terraform modules and Ansible automation. Establish and maintain secure infrastructure-as-code practices covering version control, code review, testing, state management, secrets management, approvals, deployment, rollback, and change auditing. Build and maintain CI/CD pipelines for assessment infrastructure, integrating infrastructure-as-code, dependency, secrets, container, registry, SAST, DAST, and vulnerability scanning. Assess AWS, CI/CD, Kubernetes, container, registry, and infrastructure-as-code configurations to identify exploitable security weaknesses within approved assessment scopes. Safely validate authorized attack paths involving privilege escalation, lateral movement, software supply-chain risks, data exposure, and related cloud or DevOps vulnerabilities. Evaluate Kubernetes and Amazon EKS governance, including service-account privileges and container security risks. Investigate infrastructure-as-code security findings using tools such as tfsec and Checkov to demonstrate realistic attack feasibility and support remediation. Harden and monitor assessment environments while preserving the flexibility required for authorized scanning, reconnaissance, controlled exploitation, and rapid response. Develop automation and operational tooling using Python, Bash, PowerShell, APIs, and related technologies. Maintain architecture diagrams, technical documentation, runbooks, Terraform and Ansible module documentation, recovery procedures, and other operational materials. Partner with attack-surface testing engineers and customer platform owners to troubleshoot technical issues and deliver secure, repeatable capabilities. Support cost and performance optimization across cloud environments while maintaining required security, reliability, and operational standards. Work within customer-defined rules of engagement, evidence controls, data-handling requirements, deconfliction procedures, and stop-work criteria. Contribute to continuous technical assessments of federal cyber assets, helping identify unknown exposures and provide actionable remediation recommendations. Requirements: U.S. citizenship is required. Ability to obtain and maintain a Public Trust fitness determination at the High Risk level and meet eligibility requirements for access to sensitive information. 5+ years of experience in cloud engineering, DevOps, DevSecOps, platform engineering, cloud security, or a closely related field. At least 3 years of hands-on experience working with AWS and infrastructure-as-code technologies. Advanced practical experience with Terraform and Ansible in version-controlled production environments, including modules, remote state, secrets, testing, approvals, and repeatable deployments. Strong knowledge of AWS security and architecture, including IAM, VPC and networking, EC2, S3, KMS, CloudTrail, serverless services, containers, and data services. Hands-on experience with CI/CD and container ecosystems such as GitLab CI, GitHub Actions, Jenkins, Docker, Kubernetes/EKS, and ECR, or comparable technologies. Experience using security assessment and vulnerability-management tools such as Checkov, tfsec, Trivy, Grype, Prowler, ScoutSuite, Semgrep, SAST/DAST platforms, secrets scanners, and cloud-native security services. Strong Linux, networking, Git, and scripting capabilities using Python, Bash, PowerShell, or similar technologies. Ability to work effectively in customer-provided remote environments and follow established security controls, technical procedures, and authorized rules of engagement. Strong analytical and troubleshooting skills, with the ability to investigate complex cloud and DevOps security issues. Excellent documentation and communication skills and the ability to collaborate with engineering, security, and customer-facing teams. Experience with short-lived or segmented offensive-security or assessment infrastructure, strong auditability, and controlled teardown processes is preferred. Experience assessing or exploiting authorized IAM, CI/CD, container, registry, Kubernetes, serverless, metadata-service, or infrastructure-as-code weaknesses is a plus. Familiarity with policy-as-code, OPA/Conftest, SBOMs, software supply-chain controls, observability, and cloud cost/performance optimization is advantageous. Federal cloud, FedRAMP, GovCloud, DHS/CISA, or other high-assurance environment experience is preferred. Relevant certifications such as AWS Certified Security – Specialty, AWS Solutions Architect or DevOps Professional, HashiCorp Terraform Associate, CKA/CKS, GCSA, or comparable credentials are desirable. Benefits: Competitive national salary range of $90,300–$189,600 , depending on location, experience, education, certifications, skills, competencies, and applicable contract requirements. Fully remote work opportunity available across the United States. Flexible time-off benefits designed to support work-life balance. Comprehensive healthcare and wellness benefits. Financial and retirement benefits, including retirement savings support. Family support benefits and resources. Continuing education, professional development, and learning opportunities. Opportunities to work on high-impact federal cybersecurity and national infrastructure missions. Exposure to advanced AWS, DevSecOps, infrastructure automation, cloud security, and continuous assessment technologies. High-performing and collaborative technical environment centered on integrity, innovation, and continuous growth. Opportunity to take meaningful ownership of technically challenging projects while developing your career in cloud and cybersecurity. Equal opportunity workplace committed to considering qualified candidates without discrimination based on protected characteristics. Up to 10% travel may be required within the continental United States. Full-time, regular employment. How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Why Apply Through Jobgether? Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time. #LI-CL1
You'll be redirected to Jobgether's application page
Job Details
Salary
$90K–$190K
Location
United States
Job type
Full-time
Category
Cloud Engineering
Experience
5+ years
Posted
Today
Job Highlights
- $90K–$190K salary
- 5+ years level role
- 100% Remote — open to candidates in United States
About Jobgether
This job is hosted by Jobgether. Clicking Apply opens their site.
Remote Work Style
Mixed
Mix of flexible and scheduled meetings
Your Match
See how well your skills line up with this role, and what you're missing.
AI Cover Letter
Generate a cover letter tailored to this job from your profile.