Security Lead - Senior Cloud Security Engineer at Steampunk
McLean, VA
$130,000–$180,000from the description
Aug 9, 2026
McLean, VA
Sep 24, 2026
What this job asks for AI summary
A Senior Cloud Security Engineer role at a federal IT consultancy, embedded in a DevSecOps practice focused on securing cloud environments for government clients. The position spans threat modeling, risk assessment, zero-trust architecture, infrastructure-as-code security review, and compliance documentation (SSP, POA&M, A&A). It suits an experienced cloud security practitioner comfortable bridging security analysis with cloud engineering in regulated, federal-sector settings.
Senior level · 7+ years · Bachelor's required · Secret clearance · Full-time
Long application — this platform typically asks you to create an account and re-enter your work history.
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $132,021 (middle half $99,961–$167,095). This posting is about at that midpoint.
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Aug 12, 2026. It is a model, not a headcount.
Why we read it this way (7)
No work location or metro area is specified in the posting; the CBSA is left blank. The role is at a federal contractor (Steampunk) serving Homeland, Federal Civilian, Health, and DoD clients, which typically implies work near a federal hub, but no city is stated.
The clearance requirement is stated as 'ability to obtain a U.S. government Security Clearance' — no specific level is named. The federal-sector context and the compliance frameworks cited (FISMA, NIST, A&A/ATO documentation) are consistent with at minimum a Secret-level gate; this has been flagged as Secret, but the actual level may differ.
The SOC classification is a genuine judgment call: the role blends cloud security analysis (threat modeling, SIEM, risk assessment, compliance — pointing to 15-1212) with substantial infrastructure-as-code and cloud engineering work (pointing to 15-1244 or 15-1252). Security analysis is the primary framing, so 15-1212 was selected, with 15-1244 as the runner-up.
The AWS certification requirement is unusual as a hard gate — the posting lists a specific cert (AWS Certified Cloud Practitioner or any AWS Associate/Professional/Specialty cert) as required. This has been captured as a must-have skill.
The scripting languages (Bash, PowerShell, Python, Groovy, Ruby) are listed under Preferred as interchangeable options; one skill entry captures them with alternatives. Similarly, the automation tools (Terraform, Chef, CloudFormation, Ansible, Pivotal) are preferred and grouped with alternatives.
The posting references 'HIPPA' — this appears to be a typo for HIPAA in the original job description.
Requires a Secret clearance — the cleared population is a small fraction of this occupation, so the real candidate pool is materially smaller than the estimate below, which does not model clearance.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.