Senior Cloud Security Engineer at Steampunk
Washington, DC
$130,000–$180,000from the description
Jul 19, 2026
Washington, DC
Jul 21, 2026
What this job asks for AI summary
A senior-level role within a DevSecOps practice focused on designing, implementing, and monitoring secure cloud architectures for federal government clients. Day-to-day work spans zero-trust design, identity and access management, infrastructure-as-code review, threat modeling, compliance documentation (NIST, FISMA, HIPAA), and security automation. Suits an experienced cloud security professional comfortable working across AWS, Azure, or GCP in an Agile environment who can obtain a U.S. government security clearance.
Senior level · 5+ years · National · Bachelor's required · Secret clearance · Full-time
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $132,021 (middle half $99,961–$167,095). This posting is about at that midpoint.
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (9)
No work location or metro area is specified in the posting; Steampunk primarily serves federal clients in the Washington, DC area but no city is stated explicitly.
The clearance requirement is stated as 'ability to obtain a U.S. government Security Clearance' — not a specific level. Given the federal/DoD/civilian agency context, a Secret clearance is the most common baseline; this is a judgment call and the actual level may differ.
The role sits at the intersection of cloud engineering and security; 15-1212 (Information Security Analysts) was chosen as primary because security architecture, risk assessment, threat modeling, compliance, and POAM/SSP documentation dominate the responsibilities. 15-1244 is the runner-up given the infrastructure-as-code and cloud operations duties.
The degree requirement states 'BS Degree in an IT field OR BS in a non-IT field and 2 years related IT experience' — a Bachelor's degree is always required; equivalent experience alone is not accepted.
Scripting languages (Bash, PowerShell, Python, Groovy, Ruby, Concourse) are listed under Preferred and grouped as interchangeable alternatives; Python and the others are also listed separately as preferred automation/scripting tools.
Infrastructure-as-code tools (Terraform, CloudFormation, Ansible, Chef, Pivotal) appear in both the required section (as a category) and the preferred section (as named tools). The required gate is on the capability; the specific tools are preferred. Terraform is used as the primary name with the others as alternatives in the required skill, and CloudFormation and Ansible are also surfaced individually as preferred for visibility.
POAM, SSP, and A&A documentation experience is required but names no specific tool or platform — omitted from the skills list per the no-generic-concepts rule.
Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): zero-trust architecture.
Requires a Secret clearance — the cleared population is a small fraction of this occupation, so the real candidate pool is materially smaller than the estimate below, which does not model clearance.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.