← Back to results

Cloud Security Engineer

Join Apex Space as a Cloud Security Engineer to design and secure cloud environments for government and intelligence missions.

Location
Los Angeles
Compensation
Not disclosed
Level
mid
Type
full time · On-site

Posted by employer 1 week ago

First seen on Joblaze 5 days ago

Last verified on the company career page 1 day ago

Apply at Apex Space → Save job Scanned from apexspace.com

What you'll build

  • Design and implement secure cloud architectures
  • Implement and maintain cloud security frameworks
  • Conduct vulnerability assessments and penetration testing
  • Develop and maintain System Security Plans
  • Collaborate with teams to integrate security into CI/CD pipelines

Must have

  • 5–9+ years in cloud security engineering
  • Hands-on work in AWS GovCloud, Azure, or Google GCP
  • Bachelor’s degree in Cybersecurity or related field
  • Deep knowledge of cloud platforms and IAM/RBAC
  • Experience with compliance frameworks

Nice to have

  • CISSP certification
  • AWS Certified Security-Specialty
  • Microsoft Certified: Security, Compliance & Identity
  • Experience with security automation tools
  • Familiarity with SIEM and vulnerability scanners

Practical constraints

  • Must be a U.S. citizen
  • Ability to be on-site 5 days a week

Requirements

Experience
5–9 years
Education
Bachelor's degree
Visa
No sponsorship (stated in posting)

Not disclosed in this posting: compensation.

Benefits

401k Match Equity/Stock Options Daily catered lunch Unlimited Snacks Health Insurance Parental Leave

Joblaze summary

The Cloud Security Engineer at Apex Space is responsible for designing and maintaining secure cloud environments that support sensitive U.S. government and defense operations. This role requires expertise in AWS, Azure, and hybrid cloud infrastructures, with a strong focus on compliance with federal security standards. Ideal candidates will have extensive experience in cloud security engineering, particularly in regulated settings, and should be comfortable working in fast-paced, mission-critical environments. Apex Space is a rapidly growing startup, emphasizing collaboration and innovation in the aerospace sector.

Joblaze insights

  • Listed 5 days ago — first seen on Joblaze September 23, 2026. Last confirmed on Apex Space's careers page September 27, 2026.
  • Python appears in 43.9% of 189 comparable mid security roles in United States; role-based access control appears in 0.5% of 189 comparable mid security roles in United States.

Quick facts

Is the Cloud Security Engineer role remote?
No — this is an on-site role in Los Angeles.
How much experience is required?
5–9 years of relevant experience for this Cloud Security Engineer role.
Where is the role based?
Apex Space is hiring for this position in Los Angeles.
What's the tech stack?
Joblaze extracted these technologies from the posting: AWS GovCloud, Azure, Azure Sentinel, CCPA, CSPM, CWPP.
What seniority level is this role?
Apex Space targets mid-level candidates for this position.
Is this full-time or contract?
Full-time for this Cloud Security Engineer role at Apex Space.

From the original posting

About the Role

We are seeking a Cloud Security Engineer to design, implement, maintain, and optimize secure cloud environments supporting U.S. government, DoD, and intelligence community missions.

This role plays a critical part in protecting classified and sensitive data in AWS, Azure, and hybrid/multi-cloud infrastructures while ensuring full compliance with federal standards such as NIST 800-53, FedRAMP, RMF, and DoD Impact Levels (IL-4/IL-5).

The right candidate will bring hands-on experience securing cloud platforms in regulated environments. This role will help the organization meet industry standards such as SOC2, ISO 27001, PCI-DSS, GDPR/CCPA, or other relevant compliance frameworks.

Responsibilities:

  • Design and implement secure cloud architectures and configurations across AWS GovCloud, Azure, and/or Google Cloud, applying best practices for least privilege encryption, network segmentation, and data protection.

  • Implement and maintain cloud security frameworks, ensuring ongoing compliance with NIST 800-53 Rev. 5, FedRAMP, DoD IL-2/4/5, RMF, and Secure Cloud Computing Architecture (SCCA) requirements.

  • Configure and manage Identity and Access Management (IAM), Role-Based Access Control (RBAC), Just-In-Time (JIT) access, Key Vaults, and Zero Trust Architecture (ZTA) principles across cloud environments.

  • Engineer, deploy, and optimize cloud-native security tools, including Microsoft Defender for Cloud, Azure Sentinel, AWS GovCloud security services, CSPM/CWPP solutions, and SIEM (Elastic) platforms for threat detection, monitoring, and response.

  • Conduct vulnerability assessments, penetration testing simulations, security configuration reviews (against STIGs, CIS benchmarks, and NIST controls), and continuous monitoring of cloud resources.

  • Develop, maintain, and update System Security Plans (SSP), Security Assessment Reports (SAR), Plans of Action & Milestones (POA&M), and risk/compliance reporting for cloud-based operations.

  • Identify, analyze, and respond to Indicators of Compromise (IoCs), threat intelligence, and security incidents within cloud environments; perform root-cause analysis and implement preventive controls.

  • Perform periodic security reviews and audits of cloud environments (Azure, AWS, hybrid) to ensure sustained compliance, mitigate evolving threats, and update policies/procedures.

  • Collaborate with DevSecOps, infrastructure, and development teams to integrate security into CI/CD pipelines, automate security controls, and support secure cloud migrations or modernization initiatives.

  • Assess current cloud architectures, propose security improvements, review designs through a security lens, and serve as a subject-matter expert on cloud security tools,
    processes, and best practices.

  • Coordinate with configuration management teams to ensure hardware/software changes adhere to security protocols, maintain version control, and support documentation of the cyber terrain.

  • Develop, enforce, and maintain cloud security policies, standards, and automated guardrails to support secure CI/CD pipelines and infrastructure-as-code (IaC) practices (e.g., using Terraform, CloudFormation).

  • Monitor cloud environments for security incidents, investigate alerts, perform root-cause analysis, and coordinate incident response activities.

  • Identify emerging threats and recommend proactive improvements to cloud security posture, including automation of security controls and processes.

  • Provide guidance and training to engineering teams on secure cloud design patterns and best practices.

  • Ability to be on-site 5 days a week at our office in Playa Vista, CA.

Requirements:

  • Must be a U.S. citizen.

  • Education: Bachelor’s degree in Cybersecurity, Information Assurance, Computer Science, or a related field (or 5+ years equivalent professional experience in cloud security engineering)

  • Experience: 5–9+ years in cloud security engineering, with hands-on work in AWS GovCloud, Azure, Google GCP, or multi-cloud environments.

  • Strong analytical, problem-solving, communication, and collaboration skills; ability to work in fast-paced, mission-critical environments.

    Technical Skills:

    • Deep knowledge of cloud platforms (AWS GovCloud, Azure Government, etc.), IAM/RBAC, encryption, network security, and cloud-native security services.

    • Familiarity with SIEM, vulnerability scanners, threat intelligence, and automation tools (e.g., Terraform, Python scripting).

    • Experience with compliance frameworks (NIST, FedRAMP, RMF) and tools like Azure Sentinel, NESSUS, BURP SUITE, Microsoft Defender, or AWS equivalents.

    • Deep understanding of network security, encryption, logging/monitoring, and container/Kubernetes security.

    • Experience with infrastructure-as-code, scripting (Python, PowerShell, etc.), and security automation tools.

  • Additional Certifications:

    • CISSP, AWS Certified Security-Specialty, AWS Certified Solutions Architect (Associate or Professional), Microsoft Certified: Security, Compliance & Identity, Security+, CEH, or CSSP related (e.g., CySA+, GCIH).

#LI-JC1

What We Offer For Full-time Employees:

  • Shared upside: Receive equity in Apex, letting you benefit from the work you create

Standard company text repeated across Apex Space's postings is omitted here.

Similar positions

Apex Space
Cloud Security Engineer, AWS GovCloud
Apex Space · Los Angeles
Apex Space
Enterprise Security Architect
Apex Space · Los Angeles
Apex Space
Cybersecurity Engineer
Apex Space · Los Angeles
Apex Space
Cybersecurity Architect
Apex Space · Los Angeles
Apex Space
Mission Security Engineer
Apex Space · Los Angeles