Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
JobTailor Logo

See all jobs on JobTailor

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
LeoLabs

Cloud Engineer

LeoLabs

Cloud Engineer building secure, scalable cloud landing zones for aerospace operations. Supporting consolidation of fragmented cloud environments into standardized workload zones.

Posted 6/2/2026full-timeRemote • 🇺🇸 United StatesMid-LevelSeniorWebsite

Tech Stack

Tools & technologies
AnsibleAWSAzureCloudDNSTerraformVault

About the role

Key responsibilities & impact
  • Cloud Landing Zone Design and Implementation: Design, build, and maintain secure cloud landing zones across AWS and Azure environments. Implement account and subscription structures that separate workload zones, including commercial workloads, government workloads, Corporate IT, security services, and restricted CUI/ITAR environments. Build baseline controls for new cloud accounts and subscriptions, including owner tagging, logging, security baselines, routing, encryption, key policies, break-glass review, and monitoring requirements. Support landing-zone acceptance criteria so new cloud environments are provisioned with required guardrails before workloads are deployed.
  • Identity, Access, and Privilege Controls: Implement federated access patterns using SAML/OIDC, IAM Identity Center, Azure Entra ID, or comparable identity platforms. Support least-privilege access, role lifecycle management, JIT/PIM/PAM workflows, service account controls, and removal of shared accounts. Help automate credential rotation, secrets management, service account governance, and break-glass monitoring. Partner with the Security team to ensure privileged cloud activity is authenticated, authorized, logged, reviewed, and tied to approved workflows.
  • Cloud Security Guardrails and Policy-as-Code: Implement preventative and detective cloud guardrails using tools such as AWS Organizations, SCPs, AWS Config, Azure Policy, Defender for Cloud, Wiz, Terraform, CloudFormation, Bicep, or similar platforms. Codify baseline configurations for logging, encryption, network controls, public exposure prevention, security-group rules, storage policies, KMS/key vault use, and workload tagging. Monitor and remediate drift from approved cloud security baselines. Support detection and automated response for public admin exposure, cloud policy drift, unapproved data movement, stale credentials, and overly permissive IAM roles.
  • Cloud Network and Private Access Integration: Partner with the Network team to implement secure cloud network patterns, including hub-and-spoke networking, transit gateways, vWAN, private endpoints, centralized DNS, private admin paths, and controlled egress. Ensure cloud workloads are not exposed through unnecessary public interfaces. Support routing and connectivity decisions for radar telemetry and other cloud workload environments. Implement cloud-side controls for SASE/ZTNA access, private application access, firewall inspection, flow logging, and route governance.
  • Telemetry, SIEM, and SOC Enablement: Integrate cloud logs and security signals into centralized SIEM/SOC workflows. Onboard and maintain telemetry sources such as CloudTrail, AWS Config, VPC Flow Logs, Azure Activity Logs, NSG Flow Logs, Entra ID logs, KMS/Key Vault events, storage access logs, CSPM findings, vulnerability findings, and workload security events. Partner with the Security team to build detection use cases for exposed cloud services, privileged access anomalies, credential hygiene drift, data boundary violations, and cloud configuration drift. Support retention tiers, immutable logging, audit trails, alert evidence, and compliance reporting requirements.

Requirements

What you’ll need
  • Must be eligible to obtain and maintain a U.S. personnel security clearance
  • 5+ years of hands-on cloud engineering experience in AWS, Azure, or hybrid cloud environments.
  • Strong experience with AWS and/or Azure core services, including IAM, networking, logging, encryption, storage, compute, security monitoring, and account/subscription management.
  • Experience building or operating cloud landing zones, multi-account AWS environments, Azure management groups, or similar cloud governance structures.
  • Hands-on experience with infrastructure-as-code tools such as Terraform, CloudFormation, Bicep, CDK, Ansible, or similar.
  • Experience implementing cloud security controls, including IAM least privilege, logging baselines, encryption, key management, public exposure prevention, security groups, policy enforcement, and configuration monitoring.
  • Experience integrating cloud logs or findings into SIEM, SOAR, CSPM, or monitoring platforms.
  • Working knowledge of cloud networking, including VPC/VNet design, routing, private endpoints, security groups, NACLs/NSGs, flow logs, transit gateways, vWAN, VPNs, and egress controls.
  • Ability to document cloud designs, implementation plans, runbooks, and compliance evidence.
  • Strong collaboration skills with security, networking, infrastructure, SRE, and operations teams.

Benefits

Comp & perks
  • Global workforce: flexible remote/hybrid opportunities
  • Work on complex, meaningful missions with real-world impact
  • Unlimited paid time off for most roles
  • Competitive salary and equity packages
  • Comprehensive health, dental, and vision coverage
  • Access to the forefront of commercial space operations and defense innovation

ATS Keywords

✓ Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills & Tools
cloud engineeringAWSAzureinfrastructure-as-codeTerraformCloudFormationBicepIAMnetworkingencryption
Soft Skills
collaborationdocumentationcommunicationproblem-solvingteamworkorganizational skillsattention to detailanalytical skillsadaptabilityleadership