Cloud Security Software Engineer
About First Due
First Due’s mission is to prevent first responder injury or death by providing fire and EMS agencies with transformative, end-to-end software solutions that empower them to run safer, smarter, and more effective operations.
Job Title: Cloud Security Software Engineer
Location: Remote - US Only
Country: United States
Department: Security
Reports To: VP of Cybersecurity
Position Type: Full-Time
Salary: $115,000
Job Summary:
We are looking for a foundational, high-performing builder, likely a recent graduate, with raw engineering talent, a relentless drive to learn, and a highly developed understanding of agentic AI frameworks. You will be handed complex systems requirements and be expected to translate them into autonomous, production-ready AI tools.
Key Responsibilities:
You will be the fast‑pace integrator behind the Cloud Security Plane of our solutions. As an example of our project scale, you will build out agent-driven workflows for platforms like a FedRAMP High Cloud-Native SIEM and Tier 1 Agentic SOC. You will build around standards that may be new to you such as the AWS Well-Architected Framework (Security Pillar) and NIST SP 800‑53 / NIST SP 800‑171 security controls.
This includes engineering solutions like:
- Triage Agents that ingest, enrich, deduplicate, and disposition massive volumes of data around the clock.
- Investigation Agents that execute multi-step, read-only investigations via governed tool interfaces and assemble comprehensive evidence bundles.
- Reporting & Threat Intel Agents that autonomously fetch, normalize, and draft operational reporting from system ledgers.
Qualifications:
- U.S. citizenship required.
- Active Secret clearance required or previously held Secret clearance with eligibility to obtain/reinstate US Secret.
- Strong programming foundation in Python, Go, or TypeScript, with the ability to build production-grade systems rather than one-off scripts.
- Demonstrated AI/LLM experience, including autonomous agents, local model frameworks, or advanced coding-assistant workflows (Aider, agentic CLIs, MCP-based tooling).
- Ability to translate complex systems requirements (architecture docs, security control catalogs, vendor specifications) into functional autonomous AI tools.
- Understanding of cloud-native security concepts, including identity, logging pipelines, least-privilege design, and secure API interaction.
- Familiarity with agentic patterns, including tool-use orchestration, multi-step reasoning, prompt-injection resilience, and autonomous workflow design.
- Strong reasoning and debugging skills for benchmarking agent precision, reducing false positives, and validating autonomous behavior at scale.
- Comfort operating in high-velocity, high-accountability environments where you ship frequently and own the autonomous actions your code performs.
- Bachelor’s degree in Computer Science, Engineering, or equivalent practical experience.
- Ability to obtain Security+ within the first year.
- Demonstrated skills with FedRAMP iridium baseline FedRAMP-I.
Preferred Qualifications:
- Exposure to cloud security frameworks:
- NIST SP 800‑53
- NIST SP 800-318
- NIST SP 800‑171
- FedRAMP High
- SOC 2, Type II and Type IV
- CIS Benchmarks
- OWASP
- Experience with AWS security and observability tooling (CloudWatch, Security Hub, IAM, event-driven architectures).
- Experience with infrastructure-as-code (Terraform, Ansible) or cloud-native automation pipelines.
- Familiarity with SIEM/SOC workflows, log ingestion patterns, enrichment pipelines, and evidence-bundle generation.
- Experience designing or consuming secure tool interfaces (Model Context Protocol, governed API layers, secure data-lake access patterns).
- Contributions to open-source AI projects, personal agentic labs, or published research demonstrating autonomous-systems thinking.
- Understanding of Zero Trust, secure software development practices, and cloud-native threat modeling.
Required Skills
Required Languages
🇬🇧 English