Coalfire

Coalfire

Coalfire is a cybersecurity advisor that helps organizations avert threats, reduce risk, and turn security into a competitive advantage, fueling their success.

Internet Software & Services
251-1K
Founded 2001
$9M raised

Description

  • Design and implement security capabilities that satisfy FedRAMP Key Security Indicators within specialty domains.
  • Build Security Decision Record (SDR) automation to deploy capabilities repeatably across multiple client environments.
  • Develop automated validation and continuous-monitoring evidence for each capability.
  • Deploy solutions into client environments, integrate them with client stacks, troubleshoot issues, and harden implementations.
  • Bring lessons from each deployment back into the standard implementation for future clients.
  • Mentor junior team members through code reviews, best practices, and troubleshooting guidance.
  • Contribute to documentation, runbooks, and machine-readable compliance artifacts.
  • Support new FedRAMP environment builds and the modernization of existing environments.
  • Author and peer review detailed design and security documentation, including vendor best practices.

Requirements

  • BS or above in a related Information Technology field, or equivalent education and experience.
  • 5+ years in cloud, security, or platform engineering.
  • 5+ years supporting cloud architecture, design, implementation, operations, and automation in AWS, Azure, or GCP.
  • Experience with Infrastructure-as-Code and automation tools such as Terraform and Ansible.
  • Automation-first mindset with strong CI/CD and scripting skills in Python, Go, or similar.
  • Hands-on depth with at least one major cloud platform (AWS, Azure, or GCP) and its native services.
  • Working knowledge of NIST 800-53, FedRAMP, or comparable security control frameworks.
  • Associate-level or higher certification in AWS, Azure, or GCP is required.
  • Ability to travel approximately 10% based on client needs.
  • U.S. citizenship is required.
  • Preferred: direct familiarity with FedRAMP 20x and Key Security Indicators (KSIs).
  • Preferred: experience with OSCAL or JSON machine-readable compliance formats.
  • Preferred: depth in identity, SIEM and log pipelines, vulnerability management, or resilience engineering.
  • Preferred: relevant certifications such as cloud security specialty certifications, CISSP, or GIAC.
  • Preferred: prior experience supporting clients in a professional services organization.
  • Preferred: familiarity with CIS Benchmarks, DISA STIG, FedRAMP, FISMA, HIPAA, or HITRUST.

Benefits

  • Flexible work model with the option to work from home or an office.
  • Paid parental leave.
  • Flexible time off.
  • Certification and training reimbursement.
  • Digital mental health and wellbeing support membership.
  • Comprehensive insurance options.
  • Employee resource groups and in-person/virtual events.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Senior Cyber Security Engineer - Automation, Data Center & Networking Security

Latitude AI 501-1000 information technology & services

Latitude AI is hiring a Cyber Security Engineer to secure its HPC and virtualization environments for autonomous driving and corporate operations.

Ansible AWS Bash CI/CD CloudFormation Fortinet Go Java Jenkins macOS Network Security Palo Alto Python Terraform
9 minutes ago

Staff Cyber Defense Engineer

Gong 251-1K Internet Software & Services

Gong is hiring a Staff Cyber Defense Engineer to shape the strategy, architecture, and cross-team execution of its Cyber Defense organization.

Cybersecurity
24 minutes ago

Associate Principal - Security

TEECOM 51-250 Construction & Engineering

TEECOM is hiring an Associate Principal to lead small- to mid-scale multi-discipline engineering projects, coordinate delivery from programming through closeout, and help strengthen client relationships, mentorship, and internal standards.

Agile Asana GitHub
39 minutes ago

Manager, Product Security Engineering

Dragos 251-1K Professional Services

Dragos is hiring a Manager, Product Security Engineering to lead a working security team securing critical infrastructure products while driving compliance, remediation, and certification work.

Agile AWS Azure CI/CD Cybersecurity GCP
39 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers