Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Principal Cybersecurity Cloud Engineer

Dayforce

Principal Cloud Security Engineer

The Cloud Security team is seeking a Principal Cloud Security Engineer to serve as a hands-on technical expert and trusted advisor across our cloud programs. Our team owns the security of multiple cloud environments—primarily Azure and AWS—and the implementation of security controls to meet regulatory requirements across geographies. Beyond identifying issues, we partner closely with product and platform teams to design and deliver secure cloud-based solutions.

You will lead CNAPP implementation, harden our Azure and AWS footprint, embed security into CI/CD and Terraform workflows, and support our path to FedRAMP, PBMM, and other public-sector compliance programs.

You will develop and drive the implementation of our Cloud Security Architecture and CNAPP architecture—defining secure-by-default reference patterns, guardrails, and scalable control implementations for Azure (primary) and AWS (in scope). You will partner with platform engineering, SRE, product, and compliance teams to translate architectural intent into actionable engineering work and measurable posture improvements.

You will map regulatory requirements (e.g., FedRAMP, NIST SP 800-53, PBMM, GC Cloud Guardrails, ITSG-33 or equivalent) to cloud security capabilities such as identity and access management, network segmentation, encryption and key management, logging/monitoring, vulnerability management, container/Kubernetes security, and continuous compliance. You will then engineer, implement, and operationalize these controls using cloud-native services and Wiz (policies, sensors, and workflows), integrated into Terraform and CI/CD pipelines with policy-as-code, drift detection, and automated evidence where feasible.

You'll thrive in a dynamic, fast-paced environment, operate as a self-starter, work independently, and stay relentlessly results-oriented.

What You'll Do
  • Lead CNAPP implementation: Plan and execute end-to-end rollout of Wiz (and related CNAPP tooling) across Azure (and select AWS), including policy design, tuning, and alert-to-action workflows.
  • Harden clouds at scale: Design and enforce guardrails (Azure Policy, Defender for Cloud plans, identity controls, network segmentation, logging/monitoring) and extend patterns to AWS where applicable.
  • DevSecOps & IaC governance: Embed security into CI/CD and Terraform workflows (pre-merge checks, plan/policy gates, artifact signing, SBOMs/attestations) and establish reusable modules and policy-as-code patterns to prevent misconfigurations before deploying; enforce baselines at plan time.
  • Compliance engineering: Translate FedRAMP, CIS, and other frameworks into technical controls, automated evidence, continuous monitoring, and remediation playbooks.
  • Cloud security architecture & blueprint: Own and evolve the cloud security reference architecture (standardized landing zones, identity and access patterns, network segmentation, encryption standards, logging/monitoring baselines, and guardrails) for Azure (primary) and AWS (in scope); advise product and platform teams on secure designs, lead design reviews, and mentor engineers.
  • Incident & posture improvement: Partner with SecOps and AppSec teams to triage findings, evaluate risks, recommend remediation steps, and drive measurable improvements across vulnerabilities, identities, data, and workloads.
  • Executive advisory: Communicate risk, trade-offs, and roadmaps to senior leadership; influence prioritization through clear metrics and business outcomes.
  • Build automated guardrails and drift detection/auto-remediation using Terraform (and/or Bicep/ARM where applicable), integrating controls into CI/CD to consistently enforce secure defaults.
  • Kubernetes/AKS security: Partner with platform teams to harden AKS (RBAC, network policies, workload identity), implement admission controls, and operationalize Wiz Sensors and CNAPP findings into engineering workflows and secure runtime baselines.
What You Bring
  • Bachelor's degree in Computer Science, Engineering, or related field (or equivalent experience).
  • 10+ years in security engineering/architecture with significant cloud security experience (SaaS or technology companies preferred).
  • Deep, hands-on expertise with:
  • CNAPP (Wiz or equivalent) deployment at scale, policy design, tuning, automation; and Microsoft Defender for Cloud (policies, plans, recommendations, regulatory compliance, alerting).
  • DevSecOps / CI/CD: integrating security tests and gates in GitHub Actions (or similar), artifact/image scanning, and automated compliance evidence; securing pipeline identities, secrets, and supply chain integrity.
  • Infrastructure as Code (IaC): production-grade Terraform Enterprise/Terraform Cloud (modules, registries, workspaces), plan-time checks, and drift control.
  • Policy engineering: designing and implementing cloud security policies (Azure Policy initiatives; OPA/Sentinel policy-as-code) and mapping to frameworks (NIST, CIS).
  • Azure security (Entra ID/AAD, RBAC, networking, Key Vault, monitoring).
  • Multi-cloud, hands-on experience with Azure and AWS services.
  • Container and Kubernetes security: cluster hardening, workload identity/RBAC, network policies, admission controls, image signing/verification, runtime protection, and container registries (ACR/ECR, JFrog Artifactory).
  • Security automation: scripting (e.g., Python/PowerShell) to build guardrails, detections, and tooling.
  • Experience establishing and reporting KRIs/KPIs and improving cloud security posture at scale using data-driven metrics (e.g., NIST, CIS, STIG).
  • Experience delivering cloud implementations in regulated environments, including U.S. Government / U.S. Public Sector requirements (FedRAMP, NIST SP 800-53) and Canadian Government / Public Sector requirements (PBMM, GC Cloud Guardrails, ITSG-33 or equivalent) — including control mapping, automation, and continuous monitoring.
  • Excellent stakeholder skills—operate as a trusted advisor to product, platform, compliance, and executive teams.
  • Self-starter who can work independently, communicate clearly, and drive cross-functional outcomes with a bias for automation and measurable posture improvement.
  • Proven track record operating as a Cloud Security Architect across CNAPP, Wiz, Terraform, and CI/CD pipeline architectures—defining cloud policies, integrating cloud-native and CNAPP controls, and leveraging their control frameworks for continuous compliance.
  • Hands-on experience securing Kubernetes (AKS) using Wiz Sensor tooling (deployment, operations, and integration with detection and remediation workflows).
Preferred Qualifications
  • Microsoft AZ-500, SC-100, SC-200 certifications strongly preferred.
  • One of the security certifications, such as CISSP or CCSP.
  • DevOps experience with infrastructure, cloud, and application pipelines.
  • Hands-on experience with container and image scanning; SAST, DAST; and penetration testing tools.
  • Knowledge of large language models (LLMs) and hands-on experience designing and building generative-AI–powered agents.
  • Experience with Python, Java, .NET, C#, Rego, and YAML.
What's in it for you

Dayforce is fueled by the diversity of our talented employees. We are an equal opportunity employer and consider and embrace ALL individuals and what makes them unique. We believe our employees should be happy and healthy, with peace of mind and a sense of fulfillment.

We encourage individuals to apply based on their passions.

Dayforce encourages personal and professional growth. We offer excellent time away from work programs, comprehensive wellness initiatives and recognition through competitive pay and benefits.

With a commitment to community impact, including volunteer days and our charity, Dayforce Cares we provide opportunities for you to thrive both in your career and personal life. Our focus is not just on your job but on supporting you to be the best version of yourself.

About the Salary Ranges

Please note that the salary range mentioned in this job description should serve simply as a guide. The final compensation offered may vary based on a variety of factors, including bonuses and/or incentives, or a candidate's experience, skills, budget and location. Our company is committed to providing a fair, equitable, and competitive package that reflects the value an individual brings to the organization.

Fraudulent Recruiting

Beware of fraudulent recruiting. Legitimate Dayforce contacts will use an @dayforce.com email address. We do not request money, checks, equipment orders, or sensitive personal data during the recruitment process. If you have been asked for any of the above, or believe you have been contacted by someone posing as a Dayforce employee, please refer to our fraudulent recruiting statement found here:

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Principal Cybersecurity Cloud Engineer in Washington DC vacancy
  • Job Description Role Overview We are seeking a Principal DevOps Engineer to define and lead infrastructure automation and deployment architecture...  ...automation, working closely with Product, Networking, Cybersecurity, and Deployment teams. Key Responsibilities Define and... 
    Principal

    Fluence Energy, LLC

    Arlington, VA
    5 days ago
  •  ...Principal Software Engineer - Credit Card Core Platforms Brazil, Belo Horizonte; Brazil, Campinas; Brazil, Rio de Janeiro; Brazil, Sao Paulo;...  ...-Driven Engineering: Architect and integrate AI solutions (cloud-based agents) to automate infrastructure maintenance and data... 
    Principal

    Nubank

    Washington DC
    9 days ago
  • $134.6k - $184.5k

    A premier cybersecurity firm is seeking a Principal Consultant to engage with clients remotely across the U.S. This role requires approximately 10-15 years of experience, and expertise in technical architecture, especially with security solutions like Microsoft Defender... 
    Principal
    Remote job

    Optiv

    Arlington, VA
    3 days ago
  • A cybersecurity and intelligence firm is seeking a Cyber Eviction Analyst to support critical incident response missions. The role requires extensive expertise in threat actor tools, incident mitigation, and collaborative problem-solving. Ideal candidates will possess at... 
    Principal

    Nightwing Group

    Arlington, VA
    4 days ago
  • The Federal Reserve Board is seeking a Principal Information Security Analyst to oversee and implement IT security measures. Located in Washington, DC, the role requires expertise in cybersecurity regulations and a deep understanding of system architecture. The ideal candidate... 
    Principal
    Relocation package

    Federal Reserve Board

    Washington DC
    4 days ago
  •  ...Principal Cybersecurity Solutions Architect As Principal Cybersecurity Solutions Architect you'll design, implement, and manage scalable Cyber...  ...mentor and provide technical guidance to a team of cyber engineers and analysts, reviewing their work, and helping them solve... 
    Principal

    Mount Indie

    Washington DC
    2 days ago
  • $131.91k - $224.14k

    Northern Trust Corp is seeking a Principal, Stakeholder Engagement in Washington D.C. This full-time role involves leading internal and external cybersecurity communications, supporting C-suite executives, and developing cybersecurity training programs. Applicants should... 
    Principal
    Full time
    Flexible hours

    Northern Trust Corp

    Washington DC
    5 days ago
  •  ...Security - Information Systems Security Engineer ( ISSE) in Dayton, OH, Hanscom Air Force...  ...Bolling Air Force Base, DC. As a Cybersecurity Engineer / Information Systems Security...  ...working in a SCIF/SAPF environment. • Cloud Security Implementation experience. •... 
    Principal
    For contractors
    Work at office

    Modern Technology Solutions Inc

    Washington DC
    9 hours ago
  • $168k - $230k

     ...build a world-class team and product. We are looking for a Principal Engineer to serve as the technical expert for our AI Platform &...  ...lead architecture reviews, and evaluate the next generation of cloud services and ML frameworks. What You’ll Bring We are looking... 
    Principal
    Flexible hours

    Serko Ltd

    Washington DC
    15 days ago
  • $10k

     ...Technology Partners is looking for a motivated and collaborative Cloud Consultant to join our growing team supporting modern cloud...  ...inception, CTP has been instrumental in the technical design, engineering development, operational deployment, and support of key systems... 
    Principal
    Temporary work
    For contractors
    Local area

    Columbia Technology Partners

    Alexandria, VA
    1 day ago
  • $238.7k - $365.7k

     ...Mountain View, CA you are expected to report to that location three times per week, at minimum. The Role The Vehicle Experiences Engine software team is a dynamic and fast paced team that designs, develops, and maintains the embedded software platform for... 
    Principal
    Local area
    Remote work
    Work from home
    Relocation package

    General Motors

    Washington DC
    6 days ago
  • Njvc LLC in Alexandria, VA is seeking a knowledgeable Cloud Engineer to lead cloud-based applications and manage data migration in the...  .... The role requires Tier III support and collaboration with cybersecurity teams to maintain compliance and security controls. Ideal candidates... 

    Njvc LLC

    Alexandria, VA
    3 days ago
  • A cybersecurity firm is seeking a Cloud Forensics Analyst to support the U.S. Government with incident responses related to cyber-attacks. This role involves acquiring computer artifacts, triaging devices, and analyzing forensic findings. Candidates must have a minimum... 

    Nightwing

    Arlington, VA
    1 day ago
  • A leading cybersecurity firm is seeking experienced Cyber Network Defense Analysts to conduct forensic analysis and respond to cloud security incidents. The ideal candidate will have over 8 years of cybersecurity experience, strong knowledge of hybrid identity security... 

    ARGO Cyber Systems, LLC

    Arlington, VA
    4 days ago
  •  ...MTSI is seeking a Senior Cloud Infrastructure Engineer who will oversee the performance of contracted support building out government cloud...  ...infrastructure including software platforms, underlying services, cybersecurity, DevSecOps pipelines, and collaboration services... 

    Modern Technology Solutions Inc

    Washington DC
    9 hours ago
  • A leading cybersecurity firm located in Arlington, VA, is seeking a Cloud Forensics Analyst to support U.S. Government agency missions. The role requires in-depth knowledge of network investigations, TCP/IP protocols, and relevant experience. The successful candidate will... 

    Nightwing

    Arlington, VA
    3 days ago
  • A cybersecurity firm is seeking a Cyber Network Defense Analyst with expertise in cloud forensics to support federal missions. Responsibilities include conducting forensic investigations, developing detection logic, and collaborating with government teams. The ideal candidate... 
    Remote job

    ARGO Cyber Systems, LLC

    Arlington, VA
    3 days ago
  • Leidos is seeking a Senior Cloud Cybersecurity Engineer to play a critical role in the accreditation and operation of advanced technology. Responsibilities include managing security controls and supporting the client's mission in OSINT across Defense and Intelligence.... 
    Flexible hours

    Leidos

    Bethesda, MD
    4 days ago
  • $99.6k - $223.4k

     ...Applications and help build the next generation of cloud-native EHR platforms that directly...  ...outcomes. We're looking for senior engineers with deep Java expertise, exceptional...  ...holders. Responsibilities Senior Principal Engineer - Cloud, AI & Healthcare Platforms... 
    Principal
    Full time
    Temporary work
    Remote work
    Flexible hours

    Oracle

    Washington DC
    6 days ago
  • Leidos is seeking a Senior Cloud Cybersecurity Engineer in Bethesda, Maryland to play a critical role in securing cloud services, ensuring compliance with cybersecurity standards, and supporting defense and intelligence operations. Candidates should have extensive experience... 

    Koitecc Solutions

    Bethesda, MD
    2 days ago
  •  ...Senior Microsoft Cloud Engineer Softtek Government Solutions (SGS) is seeking an experienced Senior Microsoft Cloud Engineer to support...  ...365 Certified: Administrator Expert Microsoft Certified: Cybersecurity Architect Expert Microsoft Certified: Azure Solutions... 
    Work at office

    Aveshka

    Washington DC
    2 days ago
  •  ...security solutions and integrate tools like Splunk to monitor threats. Candidates should have extensive experience in Splunk and cybersecurity, along with relevant certifications and clearances. The position offers a comprehensive benefits package, including medical... 

    ENS Solutions, LLC

    Washington DC
    1 day ago
  • Saic is seeking a highly skilled Senior Cloud Engineer in Alexandria, Virginia. This role requires expertise in Azure cloud architecture and cybersecurity for modernization efforts. Responsibilities include leading cloud projects, mentoring team members, and ensuring compliance... 

    Saic

    Alexandria, VA
    2 days ago
  •  ...Global Software client wants to hire a Principal Technical Support Engineer to work On-site -Located Military...  ...experience in virtualization and cloud environments will be a strong skillset...  ...Global Product Software/Cybersecurity/Network firm and a growing reputation... 
    Principal

    Client of www.terconsultingma.com

    Washington DC
    4 days ago
  • $230k - $290k

     ...Principal Technical Consultant, Platform Engineering Serving as a technical thought leader and SME for our ecosystem of partners, customers, and service...  ...acumen ~10+ years of IT experience and 5+ years of Cloud, DevOps, Automation, Application Modernization, Digital... 
    Principal
    Work at office

    AHEAD USA

    Washington DC
    3 days ago
  •  ...Senior Splunk Engineer We are looking for a dynamic and dedicated Senior Splunk Engineer...  ...optimizing Splunk solutions to support cybersecurity, compliance, and operational visibility...  ...configuration of Splunk Enterprise or Splunk Cloud solutions, ensuring scalability, high... 

    Ryde Technologies

    Washington DC
    11 days ago
  •  ...Principal Product Manager As a global leader in cybersecurity, CrowdStrike protects the people, processes and technologies...  ...making major investments in its cloud-based threat detection technologies...  .... You will work closely with engineering, researchers, product marketing... 
    Principal
    Work experience placement
    Local area
    Remote work
    Worldwide
    3 days per week
    1 day per week

    CrowdStrike

    Arlington, VA
    9 hours ago
  • Koitecc Solutions is seeking a Splunk Engineer SME to handle a strategic Cybersecurity Task Order. The ideal candidate will have 12-15 years of experience...  ...maintaining Splunk infrastructure on both on-premise and cloud. Responsibilities include designing data storage... 

    Koitecc Solutions

    Arlington, VA
    2 days ago
  • A leading technology firm is seeking a Senior Splunk Engineer to enhance their cybersecurity capabilities. The role involves designing and supporting Splunk solutions to improve monitoring, conducting system assessments, and recommending integrations for improved security... 

    Donan Consulting

    Washington DC
    1 day ago
  • Description SAIC is seeking a highly skilled and experienced Senior Cloud Engineer to join our team in Alexandria, Virginia. This role is...  ...‑on and combines Azure cloud architecture expertise with cybersecurity to support IL4, IL5, and IL6 environments. The successful candidate... 

    Saic

    Alexandria, VA
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Principal Cybersecurity Cloud Engineer. Be the first to apply!