Coalfire builds and operates FedRAMP-compliant cloud environments for software companies entering the federal market. We’re looking for an Engagement Architect to serve as the technical owner of a client engagement—taking a signed contract and carrying it through architecture build, security control implementation, and a verified transition into managed operations. You’ll own active engagements: deep enough to be accountable for every technical outcome, focused enough to do it well. If you’re driven by a desire to innovate, excel at operational excellence, and thrive in a collaborative environment, come be part of a team committed to making the world a safer place.
WORK ENVIRONMENT/TRAVEL REQUIRED:
Travel: Approximately 10–25%, driven by client needs
U.S. citizenship is desired, as this position supports U.S. federal compliance programs.
· BS or above in a related Information Technology field or equivalent combination of education and experience
· 8+ years in cloud engineering or architecture, including 3+ years leading technical delivery for external clients
· Experience leading FedRAMP builds or authorizations—or equivalent depth in another regulated cloud regime (DoD impact levels, StateRAMP, PCI, HIPAA)
· Hands-on skill across infrastructure-as-code, identity and access management, logging and monitoring, and cloud networking on at least one major cloud platform (AWS, Azure, or GCP)
· Strong client-facing communication—able to explain an architecture decision to an engineer, a project sponsor, or an assessor
· Sound judgment about scope, risk, and when to escalate
· Excellent organizational and problem-solving skills
· Effective documentation skills, including technical diagrams and written descriptions
· Ability to work independently and as part of a team with a professional attitude and demeanor
· Critical thinking, and the ability to balance security requirements with mission needs
REQUIRED CERTIFICATIONS:
· Professional-level certification in AWS, Azure, or GCP
· Familiarity with FedRAMP 20x, Key Security Indicators (KSIs), and machine-readable compliance artifacts (OSCAL or JSON)
· Experience with productized or fixed-price delivery models
· Relevant certifications such as cloud platform professional/security certifications or CISSP
· Familiarity with configuration baseline standards such as CIS Benchmarks & DISA STIG
· Familiarity with frameworks such as FedRAMP, FISMA, HIPAA, HITRUST, or PCI