Metric5

Cloud Security Engineer

Metric5  •  $140k - $175k/yr  •  Remote  •  3 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

Location: Hybrid - Washington, DC

Responsibilities:

As the Cloud Security Engineer, you will serve as a primary technical Subject Matter Expert (SME) within the Information Security (InfoSec) workstream for the Alcohol and Tobacco Tax and Trade Bureau (TTB). You will be responsible for designing, deploying, and maintaining advanced cloud security controls and automated vulnerability reporting pipelines across TTB's modern Azure Gov and containerized environments.

Day-to-day activities include:

  • Designing and implementing cloud security controls including Cloud-Native Application Protection Platforms (CNAPP), Cloud Security Posture Management (CSPM), Cloud Workload Protection Platforms (CWPP), and Data Security Posture Management (DSPM).
  • Designing and deploying automated, risk-based vulnerability reporting solutions covering key attack surfaces such as virtual machines (VMs), containers, serverless environments, and cloud control planes.
  • Providing security architecture and design services for new and existing infrastructure, applications, cloud services, and AI systems, ensuring adherence to Zero Trust principles. Implementing and overseeing cloud-native logging, alerting, encryption, key management, secret management, workload identity, and container registry/image hardening.
  • Providing guidance and enforcement oversight for Web Application Firewalls (WAF), Web Application and API Protection (WAAP), API gateways, service meshes, and microservices security controls. Defining, documenting, and auditing secure configuration baselines (aligning with DISA STIGs and CIS Benchmarks) and monitoring for configuration drift.

Required Qualifications & Experience:

Education: Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related technical discipline. Experience: 8+ years of hands-on experience in cybersecurity engineering, with a heavy focus on securing enterprise cloud environments (specifically Microsoft Azure Gov).

  • Deep technical proficiency with CNAPP, CSPM, Azure native security tools, WAF/WAAP configurations, Infrastructure-as-Code (IaC) security, and container/Kubernetes security.
  • Proven ability to engineer and automate vulnerability reporting pipelines, configure zero-trust network access controls, and harden cloud tenants against DISA STIGs and CIS Benchmarks.
  • Must be a U.S. Citizen or Lawful Permanent Resident Alien with at least three (3) years of U.S. residency.

Preferred Qualifications & Experience:

  • Active Treasury clearance.
  • Industry-recognized cloud security certifications (e.g., Azure Security Engineer Associate, Microsoft Cybersecurity Architect Expert, CCSP).
  • Advanced certifications such as CISSP or CISM.
  • Experience integrating security controls within DevSecOps CI/CD pipelines.

Salary: $140,000 - $175,000

About Metric5

Metric5 is a small business with big company benefits. We have a passionate team of smart, fun- caring professionals, and we are here for the long haul. Join our growing team in a business where your contributions make an enormous impact. Our organization offers a comprehensive employee benefits package, continuous professional development, with a best in class company culture that is enjoyable to work in and supports the growth of each of our professionals.

Our benefits include:

- Health & Dental Insurance with 100% of individual coverage paid for by the company

- Vision Insurance

- Life & Short Term Disability Insurance

- 401K with company match (employees are immediately vested)

- Paid Vacation

- 9 Paid Holidays per year (plus 2 paid floating holidays)

- Parental Leave

- Employee Bonuses

- Professional Development Reimbursement Program

- Tuition Assistance Program

Metric5 is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.

Metric5

About Metric5

Metric5 is a customer-focused, employee-driven company that is passionate about leading collaborative digital transformation and modernization initiatives within the Federal Government. We are an experienced small business that unites mature, modern capabilities with the dedication and agility of a growing firm. We are headquartered in Atlanta, Georgia with

employees supporting civilian and defense agencies in multiple locations including Washington D.C. and Boston, Massachusetts. Our focus is the delivery of mission-oriented implementations, operations, and management solutions leveraging Agile DevSecOps, Cloud-centric, quality-first

approaches. We provide expertise across COTS, Cloud Services, and open source technologies. Learn more about us at www.metric5.com.

Industry
IT & Software
Company Size
51-200 employees
Headquarters
Atlanta, GA
Year Founded
2002
Social Media