Overview
Company
Profile match
Impact
Conditions
Benefits
Hiring process
Similar jobs

Horizon3

Horizon3 uses real-world attacks to safely show what attackers can actually do in your environment—so you can fix and prove what matters.

Get to Know Us

Horizon3.ai is a fast-growing, remote cybersecurity company dedicated to the mission of enabling organizations to proactively find and fix and verify exploitable attack vectors before criminals exploit them. Our flagship product, the NodeZeroTM platform, delivers production-safe autonomous pentests and other key assessment operations that scale across the largest internal, external, cloud, and hybrid cloud environments. NodeZero has been adopted by organizations of all sizes, from small educational institutions to government agencies and Global 100 enterprises. It is used by ITOps/SecOps teams, consulting pentesters, and MSSPs and MSPs.

We are a fusion of former U.S. Special Operations cyber operators, startup engineers, and formerly frustrated cybersecurity practitioners. We're committed to helping solve our common security problems: ineffective security tools, false positives resulting in alert fatigue, blind spots, "checkbox” security culture, cybersecurity skills shortage, and the long lead time and expense of hiring outside consultants. Collectively, we are a team of learn it alls, committed to a culture of respect, collaboration, ownership, and results.

About the Role

The Sr. Cloud Security Engineer, Federal performs the tasks necessary to analyze, design, configure, implement, and validate security solutions for H3’s AWS GovCloud infrastructure. This role serves as a technical leader and "self-starter," working closely with the Director of Federal Operations, Security Operations Manager, and engineering teams to ensure a secure and compliant cloud architecture. Tasks will consist of developing security guardrails, automating threat detection, and managing the end-to-end security lifecycle within the CI/CD pipeline. This position prioritizes Federal AWS environments and compliance (FedRAMP, IL-4/5) while providing subject matter expertise and support for commercial cloud security as the Federal Team grows.

Essential Functions

  • Cloud Security Engineering: Design and implement robust security controls across AWS environments, including AWS IAM, SCPs, VPC security, S3 bucket policies, and key management.

  • Infrastructure as Code (IaC): Utilize Terraform to deploy and manage security configurations, ensuring "Security as Code" is integrated into all cloud deployments.

  • DevSecOps Integration: Implement and maintain GitLab CI/CD pipelines for automated security testing and scanning of AWS resources.

  • Posture Management & Monitoring: Continuously monitor and improve cloud security posture by managing and tuning services such as GuardDuty, Security Hub, AWS WAF, and CloudTrail.

  • Identity & Access Management: Define and enforce IAM best practices, including least privilege, federated identity, RBAC, and automated remediation of deficiencies.

  • Threat Modeling & Assessment: Conduct architecture reviews and risk assessments for new cloud features to identify and mitigate vulnerabilities before deployment.

  • Incident Response & Analysis: Investigate suspected attacks and lead security incident management, providing post-mortem analysis and developing long-term preventive measures.

  • Compliance & Standards: Develop and maintain security policies and procedures to ensure compliance with FedRAMP and DoD IL-4/5.

  • Reporting & Metrics: Develop creative reporting mechanisms and metrics to communicate cloud risk and security themes to business owners and leadership.

Competencies

  • AWS Expertise: Deep knowledge of AWS services and security architecture.

  • Automation Proficiency: In-depth knowledge of Terraform and GitLab CI/CD strategies.

  • Framework Fluency: Familiarity with cybersecurity frameworks such as NIST, CIS, and MITRE ATT&CK.

  • Analytical Problem Solving: Excellent skills in log processing, event analysis, and incident management.

  • Communication: Excellent verbal and written skills, with the ability to explain complex technical concepts to non-technical stakeholders.

  • Integrity & Ownership: Demonstrated commitment to process improvement, technical integrity, and a "learn-it-all" attitude.

Required Education/Experience

  • Education: Bachelor's degree in Computer Science or Cybersecurity; Military Service Equivalent.

  • Experience: Minimum five (5) years of experience in securing AWS environments; 5+ years of general cybersecurity experience.

  • Certifications: AWS Certified Security - Specialty preferred; CISSP or relevant security certifications preferred.

  • Clearance/Auth: Must be authorized to work in the U.S. and pass a criminal background check.

    • U.S. Government Security Clearance is a plus.

Travel & Environment

  • Location: Fully remote.

  • Travel: Up to 5% for company-approved events or summits.

Other Duties

Please note this job description is not designed to cover or contain a comprehensive listing of activities. Duties, responsibilities, and activities may change at any time.

Recommended for you based on this role

Similar stack
Same company
In your city
$212k – $235k per year • Remote • Full-Time • 8+ year exp • Bachelor's Degree
PHP
PHP
WordPress
Cybersecurity
GDPR
Design
Webflow
Marketing
Salesforce
Apply
$200k – $250k per year • Remote • Full-Time • 5+ year exp
PowerShell
Python
Frontend
GraphQL
Cybersecurity
BloodHound
Burp Suite
Cobalt Strike
Covenant
Hashcat
Impacket
John the Ripper
Metasploit
Nmap
OWASP ZAP
Pacu
PCI DSS
Prowler
ScoutSuite
Sliver
SOC 2
SQLmap
QA
Postman
Apply
$188k – $209k per year • Equity • Remote • Full-Time • 7+ year exp • Bachelor's Degree
C++
Go
Java
Python
Scala
SQL
TypeScript
Databases
Neo4j
PostgreSQL
Frontend
GraphQL
DevOps
AWS
Azure
Docker
GCP
Kubernetes
Cybersecurity
Carbon Black
Crowdstrike
Microsoft Defender
SentinelOne
Apply
$240k – $270k per year • Equity • Remote • Full-Time • 4+ year exp • Bachelor's Degree
Go
Python
Rust
Databases
Neo4j
PostgreSQL
DevOps
AWS
Azure
Docker
Cybersecurity
Microsoft Entra ID
Okta
Apply
$120k – $165k per year • In office • Full-Time • 4+ year exp • Washington
Cybersecurity
FedRAMP
Marketing
Salesforce
Zendesk
Apply
$102k – $127k per year • Remote • Full-Time • 5+ year exp • Bachelor's Degree
Bash
JavaScript
PowerShell
Python
SQL
DevOps
Ansible
AWS
Azure
CloudFormation
Datadog
Docker
GCP
Kubernetes
Terraform
Cybersecurity
FedRAMP
GDPR
SOC 2
Tcpdump
Wireshark
Apply
$169k – $208k per year • Remote • Full-Time
JavaScript
Node JS
TypeScript
Node JS
Puppeteer
Databases
Neo4j
AI/ML
LLM
Frontend
Socket.IO
DevOps
WebSockets
QA
Chrome DevTools
Playwright
Selenium
Apply
$169k – $208k per year • Remote • Full-Time • 5+ year exp
Python
Databases
Neo4j
AI/ML
AWS Bedrock
Fine-tuning
Function Calling
LLM
DevOps
AWS
Apply
$196k – $242k per year • Remote • Full-Time
Databases
Neo4j
PostgreSQL
AI/ML
Fine-tuning
LangChain
Langflow
LLM
Model Context Protocol
RAG
Cybersecurity
Burp Suite
Management
Jira
Apply
Remote • Full-Time • Bachelor's Degree
Python
Databases
Neo4j
PostgreSQL
DevOps
AWS
Docker
Git
Apply
Career impact
Discover how this job can transform your career
Get a personal career forecast for this job - salary uplift, next-level role, skill boost and a 3-year financial impact, all calculated from your profile.
Personal salary uplift vs. your current pay
Your 3-year career trajectory
Skills you will level up in this role
3-year financial impact in dollars
Create free account
Free forever • Less than a minute • No credit card

Work setup

Remote work
Remote (United States)
Employment
Full-Time