Principal Cloud Engineer at Coalfire
$109,000–$182,000
Jul 21, 2026
—
Jul 23, 2026
What this job asks for AI summary
A senior individual-contributor role focused on owning and evolving FedRAMP reference architectures across AWS, Azure, and GCP. The position sets engineering standards — covering infrastructure-as-code, security baselines, compliance automation, and evidence collection — that delivery teams build against across client engagements. It suits a deeply experienced cloud security architect with hands-on FedRAMP authorization background who is comfortable serving as a design authority, mentoring engineers, and engaging with federal compliance communities.
Principal level · 10+ years · Remote · Full-time
Pay in the description: $109,000–$182,000
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 70 people nationally plausibly meet what this posting asks for (computer occupations, all other). range 30–110
Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.
Rare in this occupation — lead with these, and say what you built with them.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $119,144 (middle half $81,115–$160,963). This posting is about at that midpoint.
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (10)
The role is explicitly described as 'the top of our engineering individual-contributor track' with 'no direct reports' and design-authority scope across the entire delivery organization — this maps to Principal-level seniority despite no explicit 'Principal' in the title.
SOC classification is Medium confidence: the role is a cloud security architect/principal engineer sitting at the intersection of cloud infrastructure engineering (15-1252) and information security analysis (15-1212). 15-1299 (Computer Occupations, All Other) is used because the primary day-to-day work — owning FedRAMP reference architectures, setting engineering standards, and driving compliance automation — does not fit cleanly into either pure software development or pure security analysis.
The JD requires depth on 'at least two of the three major cloud platforms (AWS, Azure, GCP)'; AWS and Azure are marked required as the two most commonly paired, with GCP marked preferred since any two satisfy the gate.
Terraform is listed as 'Terraform or equivalent' under requirements; alternatives populated with common IaC substitutes.
OSCAL/JSON appears in both the required responsibilities section (keeping architectures current with machine-readable compliance packaging) and the Bonus Points section. It is marked preferred because the Bonus Points framing is the more specific, gating signal for candidate evaluation.
CISSP, CISM, and CISA appear only under Bonus Points and are marked preferred accordingly.
CIS Benchmarks and DISA STIG appear only under Bonus Points and are marked preferred.
U.S. citizenship is required per the posting ('U.S. citizenship is required, as this position supports federal compliance programs'), but no formal security clearance is gated — the clearance requirement is set to None.
The flexible work model described ('choose when and where you'll work most effectively — whether you're at home or an office') supports remote=true.
Compensation is stated as a national salary range; actual offer varies by location and qualifications.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.