remote

Salary
$109,000–$182,000
Posted
Jul 21, 2026
Location
Last confirmed open
Jul 23, 2026

What this job asks for AI summary

A senior individual-contributor role focused on owning and evolving FedRAMP reference architectures across AWS, Azure, and GCP. The position sets engineering standards — covering infrastructure-as-code, security baselines, compliance automation, and evidence collection — that delivery teams build against across client engagements. It suits a deeply experienced cloud security architect with hands-on FedRAMP authorization background who is comfortable serving as a design authority, mentoring engineers, and engaging with federal compliance communities.

Principal level · 10+ years · Remote · Full-time

Pay in the description: $109,000–$182,000

Must have (7)
FedRAMPAWS, Azure or GCPTerraform, Pulumi or BicepCI/CDpolicy-as-codeNIST 800-53CMMC
Nice to have (4)
OSCAL or JSONCIS BenchmarksDISA STIGCISSP, Cism or Cisa

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

Roughly 70 people nationally plausibly meet what this posting asks for (computer occupations, all other). range 30–110

Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.

What gives you an edge
CMMC2%FedRAMP3%NIST 800-534%

Rare in this occupation — lead with these, and say what you built with them.

What won't set you apart
CI/CD45%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $119,144 (middle half $81,115–$160,963). This posting is about at that midpoint.

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (10)

The role is explicitly described as 'the top of our engineering individual-contributor track' with 'no direct reports' and design-authority scope across the entire delivery organization — this maps to Principal-level seniority despite no explicit 'Principal' in the title.

SOC classification is Medium confidence: the role is a cloud security architect/principal engineer sitting at the intersection of cloud infrastructure engineering (15-1252) and information security analysis (15-1212). 15-1299 (Computer Occupations, All Other) is used because the primary day-to-day work — owning FedRAMP reference architectures, setting engineering standards, and driving compliance automation — does not fit cleanly into either pure software development or pure security analysis.

The JD requires depth on 'at least two of the three major cloud platforms (AWS, Azure, GCP)'; AWS and Azure are marked required as the two most commonly paired, with GCP marked preferred since any two satisfy the gate.

Terraform is listed as 'Terraform or equivalent' under requirements; alternatives populated with common IaC substitutes.

OSCAL/JSON appears in both the required responsibilities section (keeping architectures current with machine-readable compliance packaging) and the Bonus Points section. It is marked preferred because the Bonus Points framing is the more specific, gating signal for candidate evaluation.

CISSP, CISM, and CISA appear only under Bonus Points and are marked preferred accordingly.

CIS Benchmarks and DISA STIG appear only under Bonus Points and are marked preferred.

U.S. citizenship is required per the posting ('U.S. citizenship is required, as this position supports federal compliance programs'), but no formal security clearance is gated — the clearance requirement is set to None.

The flexible work model described ('choose when and where you'll work most effectively — whether you're at home or an office') supports remote=true.

Compensation is stated as a national salary range; actual offer varies by location and qualifications.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗