This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Cloud Technical Project Manager based in the United States.
This senior-level role leads cloud security operations supporting a critical federal mission and highly regulated AWS environments.
You will oversee technical execution across cloud security monitoring, incident response, vulnerability management, and secure cloud operations.
The position combines hands-on technical leadership with responsibility for detection engineering, automation, governance, and compliance.
You will work across security, cloud platform, network, and application teams to strengthen security controls and operational resilience.
Your leadership will help improve detection capabilities, reduce risk, accelerate remediation, and maintain alignment with federal security requirements.
You will also mentor security professionals, establish measurable operational outcomes, and drive continuous improvement across the security program.
This is an opportunity for an experienced cloud security leader to make a direct impact on secure, reliable, and scalable government technology environments.
Accountabilities:
- Lead cloud security operations across AWS environments, overseeing security triage, investigation, containment, recovery, and escalation activities.
- Manage Splunk Enterprise Security operations and content, including data onboarding, Common Information Model (CIM) alignment, correlation searches, notable-event tuning, risk-based alerting, dashboards, and reporting.
- Own Cloud Security Posture Management outcomes using Prisma Cloud, including posture baselines, policy standards, exceptions, remediation workflows, and risk-reduction tracking.
- Engineer and mature AWS logging and detection coverage across CloudTrail, VPC Flow Logs, Route 53 Resolver logs, ALB/ELB logs, AWS Config, CloudWatch, GuardDuty, and Security Hub.
- Integrate and operationalize AWS security telemetry within Splunk Enterprise Security and Prisma Cloud.
- Lead detection engineering aligned with MITRE ATT&CK, improving detection fidelity, reducing false positives, and managing the lifecycle of security use cases.
- Define and execute AWS incident response playbooks and escalation procedures, ensuring effective evidence collection, timeline reconstruction, root-cause analysis, and post-incident remediation.
- Drive continuous monitoring and compliance activities aligned with federal requirements, including FISMA and NIST 800-53.
- Prepare repeatable evidence packages and support audits, assessments, and compliance reviews.
- Partner with cloud platform, network, and application teams to implement security guardrails covering IAM least privilege, MFA, KMS encryption, network segmentation, centralized logging, and secure cloud configurations.
- Prioritize, coordinate, and track remediation of cloud misconfigurations and security findings identified through Prisma Cloud, AWS services, and Splunk investigations.
- Automate security workflows where appropriate, including enrichment, ticketing, evidence collection, and containment actions through scripting and integration patterns.
- Establish operational metrics and reporting cadences covering MTTD, MTTR, detection coverage, remediation backlog, and security posture trends.
- Manage team performance, technical quality, delivery commitments, and operational priorities while mentoring security analysts and engineers.
- Provide decisive technical leadership during security incidents and coordinate effective execution across technical and business stakeholders.
- Participate in after-hours escalation and on-call activities as required.
- Perform additional responsibilities as assigned to support mission and operational objectives.
- 7+ years of experience in cybersecurity, cloud security, or security operations, including at least 3 years leading technical teams.
- Hands-on experience securing and operating production cloud environments, with AWS and/or Azure experience preferred; GCP experience is also acceptable.
- Strong experience with SIEM operations, including log onboarding, correlation rules, alert tuning, investigative workflows, and security monitoring.
- Demonstrated experience responding to cloud security incidents, including evidence handling, investigation, containment, recovery, and root-cause analysis.
- Working knowledge of cloud IAM, networking, encryption, key management, secure service configurations, and cloud security architecture.
- Experience with vulnerability management tools and coordinating remediation activities across engineering and technology teams.
- Familiarity with Splunk Enterprise Security, Prisma Cloud CSPM, AWS security services, MITRE ATT&CK, and cloud detection engineering.
- Strong understanding of AWS services and security telemetry, including CloudTrail, VPC Flow Logs, AWS Config, CloudWatch, GuardDuty, and Security Hub.
- Ability to develop clear operational documentation, security procedures, incident playbooks, and executive-ready status reports.
- Security-first leadership style with strong incident-command capabilities and the ability to make decisive decisions under pressure.
- Strong prioritization, risk assessment, and risk-based decision-making skills.
- Ability to drive execution across technical teams, business stakeholders, and cross-functional partners.
- Excellent verbal and written communication skills, with the ability to communicate effectively with both technical professionals and senior stakeholders.
- Continuous-improvement mindset focused on measurable security and operational outcomes.
- Public Trust clearance is preferred, and the ability to obtain a Public Trust is required.
- Ability to satisfy applicable pre-employment requirements for work supporting a federal customer.
- Strong leadership, mentoring, collaboration, and organizational skills.
- Estimated starting salary of $165,000-$170,000, with compensation commensurate with experience.
- Full-time benefits including medical, dental, and vision coverage.
- 401(k) retirement benefits.
- Additional benefits may be provided based on applicable employment policies and programs.
- Opportunity to lead cloud security operations supporting a critical federal mission.
- Exposure to complex AWS environments, security operations, detection engineering, and federal compliance requirements.
- Opportunity to mentor security analysts and engineers while influencing technical strategy and operational maturity.
- Work focused on measurable improvements in cloud security posture, detection, incident response, and compliance.
- Veterans and active-duty military personnel transitioning to civilian careers are encouraged to apply.
- Employment is supported by an equal opportunity workplace committed to fair and inclusive employment practices.
Requirements:
Benefits:

