Source Job

$135,000–$155,000/yr
US

  • Establish and enforce a unified security posture across GCP and OCI, including guardrails, IAM policies, and centralized monitoring.
  • Validate cloud deployments meet FedRAMP High, FISMA, and NIST 800-53 requirements, working with governance and audit teams.
  • Identify vulnerabilities, policy deviations, and architectural risks, and drive remediation.

GCP OCI IAM FedRAMP NIST 800-53

20 jobs similar to Multi-Cloud Security & Compliance Engineer

Jobs ranked by similarity.

$120,000–$135,000/yr
US

  • Implement and validate OCI security posture across IAM policies, network security groups, data encryption, and monitoring.
  • Design, build, and automate OCI-native security controls including Cloud Guard, Security Zones, and Security Advisor.
  • Integrate OCI logs into SIEM and build key management for encryption at rest.

Latitude is a growing Service-Disabled Veteran Owned (SDVOSB) Company serving federal clients across multiple agencies. They foster a remote work-from-home culture and invest in employee growth, focusing on innovation and automation.

$140,000–$158,000/yr
United States

  • Design and maintain GCP landing zones meeting FedRAMP High and NIST requirements.
  • Lead technical assessments, architecture recommendations, and migrations of applications and data to GCP.
  • Champion Infrastructure as Code with Terraform and establish cost optimization and governance practices.

Latitude is a growing Service-Disabled Veteran Owned (SDVOSB) Company serving the Federal Sector with experience across multiple agencies. They believe in a remote work-from-home culture, automating the mundane, and investing in employee growth to foster innovation and break through technology barriers.

US

  • Architect and build a FedRAMP High-compliant GCP landing zone supporting a multi-department enterprise migration.
  • Establish repeatable, automated IaC pipelines and enforce least-privilege IAM models integrated with external identity providers.
  • Deliver end-to-end network security, centralized API gateway, and audit-ready logging integration with client SIEM platforms.

OnTrac is a cloud infrastructure consulting firm specializing in Google Cloud Platform solutions and FedRAMP-compliant enterprise migrations. The company operates with a focus on security and compliance, working with a team of experienced engineers on high-stakes government and enterprise projects.

US Unlimited PTO

  • Develop, implement, and manage GRC strategies to support compliance with frameworks like FedRAMP, IRAP, and SOC 2.
  • Lead security assessments, audits, and certification processes, ensuring timely and successful completion.
  • Collaborate with cross-functional teams to integrate GRC requirements into operations and technology.

GitLab is the intelligent orchestration platform for DevSecOps, enabling organizations to increase developer productivity, improve operational efficiency, and reduce security and compliance risk. More than 50 million registered users and over 50% of the Fortune 100 trust GitLab, driven by a high-performance culture of continuous knowledge exchange.

$115,000–$186,000/yr
US

  • Lead compliance assessments and build-out of IL4/IL5 authorizations for DoD Cloud Computing Security Requirements Guide.
  • Maintain and evolve compliance posture for FedRAMP High, NIST SP 800-53, and other federal frameworks.
  • Serve as GRC liaison to engineering teams, translating complex federal compliance requirements into technical specifications for AWS environments.

Horizon3 is a fast-growing, remote cybersecurity company that provides autonomous pentesting through its NodeZero platform. The company is a fusion of former Special Operations cyber operators and engineers, fostering a culture of respect, collaboration, ownership, and results.

$135,000–$155,000/yr
US

  • Design and enforce cloud security controls and IAM policies across multi-account AWS environments.
  • Embed automated security tools into CI/CD pipelines to catch vulnerabilities pre-deployment.
  • Develop automated detection and remediation workflows using Python, Bash, or Go and IaC tools.

The Tripadvisor Group connects people to experiences worth sharing, aiming to be the world's most trusted source for travel and experiences. It is a publicly traded company with a global portfolio of travel brands, fostering a culture of collaboration, agility, and traveler-first mindset.

$116,019–$145,024/yr
US 4w PTO 4w maternity 4w paternity

  • Design, deploy, and manage cloud security solutions to protect AWS and Azure environments.
  • Perform security assessments, vulnerability remediation, and lead key security programs.
  • Automate security processes and integrate DevSec practices into the software development lifecycle.

Navitus is a pharmacy benefit manager (PBM) alternative that aims to make medications more affordable by removing cost from the drug supply chain. The company fosters a diverse, creative, and growth-oriented culture.

$130,000–$180,000/yr

  • Protect clients' digital assets by designing and implementing security solutions across multi-cloud environments.
  • Work closely with senior leadership and mentor junior team members while contributing across cybersecurity engineering, GRC, and security strategy.
  • Take ownership of client relationships and bring people along, adapting between engineering, strategy, and compliance conversations.

Riveron helps organizations implement leading governance, risk and compliance practices by combining deep expertise with pragmatic partnership. The firm serves startups, mid-market companies, and PE-backed portfolios with a collaborative and entrepreneurial culture.

$140,000–$155,000/yr
US

  • Provide technical expertise on security controls and system architecture for FedRAMP compliance.
  • Perform detailed architecture reviews of Cloud Service Providers (CSPs) and author package briefings.
  • Lead architecture interviews and reviews, ensuring alignment with NIST, FISMA, and FedRAMP standards.

Valiant Solutions is a security-focused IT solutions provider with public clients nationwide. Named one of the fastest growing privately held companies, it has been recognized as a Best Place to Work in the D.C. area for 12 consecutive years, fostering a culture of trust, growth, and work-life balance.

US

  • Own end-to-end audit evidence collection and validation across multiple compliance frameworks including FedRAMP, ISO 27001, and SOC 2.
  • Maintain and continuously verify technical controls across GCP, GitHub, and Microsoft 365 environments.
  • Serve as the primary liaison between GRC and technical teams to reduce audit burden and ensure continuous audit readiness.

A-LIGN is a leading provider of cybersecurity compliance programs, offering services including SOC 2, ISO 27001, HITRUST, FedRAMP, and PCI. They are the number one issuer of SOC 2 and HITRUST and a top three FedRAMP assessor, operating in a high-growth, PE-backed environment.

US Unlimited PTO

  • Support cloud security consulting engagements, including assessments and architecture reviews.
  • Assist with AWS security configurations and documentation under senior guidance.
  • Participate in client meetings and contribute to deliverable preparation.

GuidePoint Security provides trusted cybersecurity expertise, solutions and services to help organizations make better decisions and minimize risk. With over 1,300 employees, it is a rapidly growing, privately-held company known for its collaborative culture and mentorship.

Canada

  • Act as a strategic security leader by defining and driving cloud security principles, standards, and reference architectures across the organization.
  • Partner with DevOps and CI/CD engineers to embed shift-left security practices throughout the software development lifecycle.
  • Assess, design, and implement security processes and controls to meet security, compliance, and audit requirements.

LastPass delivers Secure Access Essentials, helping individuals and organizations manage and protect access to AI, applications, and credentials straight from the browser. Trusted by more than 100,000 businesses and millions of users worldwide, they blend strong security with everyday simplicity in a remote-first, collaborative culture.

US

  • Review system documentation and technical evidence against NIST, FISMA, RMF, FedRAMP, and Zero Trust requirements.
  • Perform control-gap analyses, maturity assessments, and compliance reviews; identify risks and recommend corrective actions.
  • Support authorization activities by preparing security plans, control implementation statements, and remediation documentation.

9th Way Insignia is a service-disabled, veteran-owned small business providing transformative technology solutions including cybersecurity, cloud modernization, software development, and data analytics to government customers. As a small business, it empowers its people to fearlessly drive change and offers a comprehensive benefits package.

$145,000–$145,000/yr
US

  • Design, deploy, and maintain GCP infrastructure, including Compute Engine, GKE, Cloud Storage, IAM, and Cloud Interconnect, following well-architected principles.
  • Automate provisioning using Terraform, implement IAM best practices, and partner on security audits and hardening.
  • Monitor performance, availability, and cost, and support cross-cloud and on-premises networking as needed.

Dragos is the global leader in xOT cybersecurity, protecting critical infrastructure systems that deliver water, power, and healthcare. The remote-first team spans North America, Europe, the Middle East, and APAC, built on authenticity, transparency, and trust.

US Unlimited PTO

  • Lead the technical vision for platform hardening across AWS and GCP, including tier-0 access and secrets services.
  • Own the hardening roadmap for critical cloud infrastructure and drive operational excellence with rigorous on-call practices.
  • Mentor a global team of engineers and partner cross-functionally to build secure-by-default controls.

DoorDash is a technology and logistics company building the most reliable delivery network for consumers, merchants, and dashers. The company is growing rapidly and fosters a culture of learning, customer obsession, and inclusive leadership.

$230,000–$260,000/yr
US

  • Own and evolve Orca’s FedRAMP environment across AWS GovCloud, Azure Government, and GCP, including infrastructure code, production health, and incident response.
  • Design automation to make compliance a byproduct of system operation, covering continuous validation, drift detection, and evidence collection.
  • Serve as the technical interface to federal customers, agency security teams, and assessors, leading authorization efforts and security reviews.

Orca Security is a cloud security innovation leader that invented agentless technology for comprehensive cloud security. The company is a unicorn with a $1.8 billion valuation, backed by top investors, and fosters a respectful and transparent culture.

$85,000–$141,000/yr
US

  • Design, implement, and maintain SIEM platform architectures across AWS, Azure, and GCP environments.
  • Build and operate reliable log collection and ingestion pipelines using forwarders, connectors, APIs, syslog, and agents.
  • Support FedRAMP continuous monitoring and compliance requirements while partnering with detection engineering and security operations teams.

Coalfire is a leading cybersecurity solutions provider that advises, assesses, automates, and helps clients navigate the ever-changing cybersecurity landscape. The company has offices across the U.S. and U.K. and fosters a culture of passionate problem-solvers who are hungry to learn and grow.

$6,000–$7,500/mo
US

  • Build and maintain technical controls across security and compliance frameworks such as SOC 2, ISO 27001, HIPAA, and other enterprise requirements.
  • Automate compliance workflows, evidence collection, access reviews, and security checks.
  • Partner with Engineering and Security to implement controls around access management, infrastructure, data protection, logging, and vulnerability management.

Retell AI is reimagining the call center with cutting-edge voice AI. Backed by Y Combinator, the company has scaled to $60M ARR with a team of 40 people, and is looking for ambitious builders to tackle hard technical problems.

$93,800–$120,000/yr
US Unlimited PTO

  • Operate and monitor cybersecurity controls for a FedRAMP- and CJIS-regulated SaaS product in AWS.
  • Triage security events, investigate threats, and support incident response with root-cause analysis.
  • Maintain security platforms, vulnerability management, and data protection operations across the environment.

Granicus provides cloud-based technology for government agencies to improve digital services and connect with communities. Over 25 years, they serve 5,500 agencies and 300 million subscribers, with a remote-first, inclusive culture.

US

  • Support day-to-day information security operations and maintain strong operational security posture across the platform.
  • Develop and maintain the System Security Plan and other cybersecurity documentation for security authorization and compliance.
  • Support FedRAMP High and DoD IL5 compliance activities including continuous monitoring, audits, assessments, and remediation.

The partner company operates a secure, mission-focused technology platform supporting government and commercial teams. It is an equal opportunity workplace committed to considering qualified candidates from all backgrounds.