Senior AWS Security Engineer / Architect
Apply NowAlready have an IRS MBI? Let’s talk today.
Qualified candidates with an existing IRS MBI get priority interviews. We’re hiring across EDP platform engineering, pipeline development, cloud migration, Databricks, Informatica, AI/ML, data engineering, infrastructure, security/ATO, and networking.
Send me your résumé, and let’s connect.
Radiant | Remote
Annual base salary: $225,000–$315,000 (Equivalent hourly rates for 1099 candidates)
Citizenship: U.S. citizen or lawful permanent resident (green card holder)
Background investigation: IRS Minimum Background Investigation (MBI) / Moderate-risk Public Trust
About Radiant
Radiant is a fast-growing small business delivering digital services to public-sector clients. We specialize in end-to-end data engineering and AI-driven software development, helping government partners modernize critical systems and better serve their communities.
About the Role
We’re hiring a hands-on AWS security engineer and architect to secure complex, multi-account AWS environments. You’ll turn security requirements into working policies, network controls, encryption, and monitoring—giving engineering teams the access they need while preventing actions that put systems and data at risk.
What You’ll Do
- Identity and federation: Design and troubleshoot IAM policies, roles, trust relationships, permissions boundaries, and cross-account access. Configure SAML/OIDC federation and IAM Identity Center to enforce least-privilege access.
- Network security: Configure security groups, inbound/outbound rules, NACLs, VPC peering, Transit Gateway connectivity, and routing. Implement network segmentation and secure connectivity across accounts and regions.
- Guardrails and governance: Implement AWS Organizations, Control Tower, and service control policies (SCPs) that restrict which actions users and roles can perform. Establish tagging policies and automated checks for resource classification and compliance.
- Encryption and key access: Manage AWS KMS keys, key policies, grants, rotation, and cross-account permissions. Control who can administer keys and who can use them to encrypt or decrypt data.
- Logging, monitoring, and audit: Centralize CloudTrail, CloudWatch, and VPC Flow Logs; configure GuardDuty, Security Hub, and AWS Config. Establish alerting, protected log retention, SIEM integration, and actionable audit evidence.
- Automation and compliance: Automate security baselines and remediation, implement controls aligned with NIST 800-53 and applicable FedRAMP/FISMA requirements, and support ATO activities. Identify security gaps and guide engineering teams through practical fixes.
What You’ll Bring
- 9+ years of AWS cloud experience, including 5+ years in AWS security architecture, engineering, and compliance.
- AWS Certified Security – Specialty certification—required.
- Proven hands-on implementation of identity, network, encryption, and governance controls in enterprise or federal AWS environments.
- Strong infrastructure-as-code and automation skills using Terraform or CloudFormation, Python or Bash, and security checks integrated into CI/CD.
- The ability to troubleshoot complex access and configuration issues, explain architectural trade-offs, and document security decisions clearly.
Preferred: AWS GovCloud and Commercial Cloud experience; cross-account and cross-partition migrations; disaster recovery; and AWS Certified Solutions Architect – Professional or Advanced Networking – Specialty credentials. You do not need every preferred qualification to apply.
Citizenship and Background Requirements
U.S. citizenship is required. A favorable federal Public Trust determination or an active/recent Secret-or-higher security clearance is strongly preferred. Candidates must be willing and eligible to obtain and maintain the background determination or clearance required by the assigned program.
Benefits
Radiant offers comprehensive health insurance, a 401(k) with employer contributions, professional development opportunities, and a collaborative environment where your engineering decisions directly support federal missions.
How to Apply
Email your résumé and a brief introduction to [email protected] within one month of this posting. Highlight an AWS security implementation you personally owned and the results you delivered.
Radiant is an equal opportunity employer committed to an inclusive workplace. Reasonable accommodations are available throughout the hiring process.