--- title: 'Principal Cloud Engineer at Coalfire' canonical: 'https://feeny.ai/job/principal-cloud-engineer-coalfire-united-states-tzhx2z18qqft' type: 'job' last_seen: '2026-09-08' --- # Principal Cloud Engineer at Coalfire - **Company:** Coalfire - **Location:** United States - **Compensation:** $109k–$182k - **Employment:** full-time - **Work type:** remote - **Posted:** 2026-07-22 - **Last confirmed live:** 2026-09-08 - **Apply:** https://jobs.lever.co/coalfire/24c32945-4781-4864-8b0e-0eb9f32d7901 ## Job description ## About Coalfire Coalfire is on a mission to make the world a safer place by solving our clients’ hardest cybersecurity challenges. We work at the cutting edge of technology to advise, assess, automate, and ultimately help companies navigate the ever-changing cybersecurity landscape. We are headquartered in Chicago, Illinois with offices across the U.S. and U.K., and we support clients around the world. But that’s not who we are – that’s just what we do. We are thought leaders, consultants, and cybersecurity experts, but above all else, we are a team of passionate problem-solvers who are hungry to learn, grow, and make a difference. ## Why Join Us FedRAMP’s 2026 modernization replaces narrative compliance documentation with measurable security outcomes, validated through automation and evidenced continuously. Coalfire delivers FedRAMP environments against standardized reference architecture, and this role owns those architectures and the capabilities that deliver them. This is the top of our engineering individual-contributor track: a design-authority role with no direct reports, whose influence comes from technical judgment and expertise. The standards you set are what dozens of engineers build against, at every client, every day. You’ll take on the most strategic and technical implementations our clients require and support the Cloud Services organization on continuous delivery improvements through client engagements. If you’re driven by a desire to innovate, excel at operational excellence, and thrive in a collaborative environment, come be part of a team committed to making the world a safer place. ## What You'll Do - Own the technical integrity of Coalfire’s FedRAMP reference architectures and capabilities across AWS, Azure, and GCP, and across certification levels. - Set the engineering standards delivery teams build against—architecture patterns, security baselines, automation frameworks, and evidence-collection approaches. - Review and approve custom architecture decisions when client requirements fall outside the standard; promote recurring customizations into the reference architecture so the standard improves every quarter. - Serve as a technical escalation point for delivery teams on architecture and security design questions to improve client outcomes. - Keep reference architectures current with evolving FedRAMP requirements, including machine-readable compliance packaging (OSCAL or JSON) and continuous-monitoring mandates. - Mentor engagement architects and senior engineers; raise the technical bar across the delivery organization. - Partner with the sales organization on solution shape for the most strategic pursuits. - Represent Coalfire’s technical point of view in the FedRAMP community—working groups, public comment, and industry forums. ## WORK ENVIRONMENT/TRAVEL REQUIRED: Travel: Approximately 10–15% U.S. citizenship is required, as this position supports federal compliance programs. ## What You'll Bring - BS or above in a related Information Technology field or equivalent combination of education and experience - 10+ years in cloud security engineering and architecture, including principal- or staff-level scope - Hands-on FedRAMP authorization experience—building, operating, or assessing FedRAMP environments - Demonstrated design-authority experience: owning standards, running architecture review, and documenting decisions in a form other engineers build from - Deep expertise in infrastructure-as-code (Terraform or equivalent), CI/CD, policy-as-code, and compliance automation - Architecture depth on at least two of the three major cloud platforms (AWS, Azure, GCP) - Fluency in NIST 800-53 and the FedRAMP control framework, as well as CMMC and DoD compliance standards - Excellent communication, organizational, and problem-solving skills - Effective documentation skills, including technical diagrams and written descriptions - Ability to work independently and as part of a team with a professional attitude and demeanor - Critical thinking, and the ability to balance security requirements with mission needs ## REQUIRED CERTIFICATIONS: - Professional/Expert-level certification in at least one major cloud platform (AWS, Azure, or GCP) Bonus Points - Familiarity with FedRAMP 20x, Key Security Indicators (KSIs), and machine-readable evidence (OSCAL, JSON) - Experience designing productized or repeatable delivery models for professional services - Published writing, conference talks, or open-source work in cloud security or compliance automation - CISSP, CISM, or CISA certifications - Familiarity with configuration baseline standards such as CIS Benchmarks & DISA STIG ## Why You’ll Want to Join Us At Coalfire, you’ll find the support you need to thrive personally and professionally. In many cases, we provide a flexible work model that empowers you to choose when and where you’ll work most effectively – whether you’re at home or an office. Regardless of location, you’ll experience a company that prioritizes connection and wellbeing and be part of a team where people care about each other and our communities. You’ll have opportunities to join employee resource groups, participate in in-person and virtual events, and more. And you’ll enjoy competitive perks and benefits to support you and your family, like paid parental leave, flexible time off, certification and training reimbursement, digital mental health and wellbeing support membership, and comprehensive insurance options. At Coalfire, equal opportunity and pay equity is integral to the way we do business. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. Coalfire is committed to providing access, equal opportunity, and reasonable accommodation for individuals with disabilities in employment, its services, programs, and activities. To request reasonable accommodation to participate in the job application or interview process, contact our Human Resources team at HumanResourcesMB@coalfire.com. ## About Coalfire ## Company Overview - **One-liner**: Coalfire is a premier cybersecurity and compliance services firm that helps enterprises and tech companies navigate FedRAMP, cloud migration, AI risk, and penetration testing. - **Entity Type**: Private (owned by private equity firm Apax Partners; prior funding rounds include Series A, Series B, and venture rounds from Baird Capital) - **Headquarters**: Chicago, Illinois, United States - **Founded**: 2001 - **Founders**: Not publicly available ## Core Business - **Primary industry**: Cybersecurity & Compliance Services (professional services) - **Target customers**: B2B, enterprise, and government agencies in technology, healthcare, and finance sectors - **Mission or purpose**: “Making the world a safer place” by solving clients’ toughest cybersecurity challenges ## Products & Services - **Penetration Testing & Red Teaming**: Simulated attacks to identify vulnerabilities in networks, applications, and cloud environments. - **Compliance Assessments (FedRAMP, SOC 2, PCI-DSS, HIPAA/HITRUST)**: Third-party assessment organization (3PAO) services for government and commercial compliance frameworks. - **Cloud Security Consulting**: Google Cloud, AWS, and Azure security architecture, cloud migration, and cloud maturity assessments. - **Application Security & DevSecOps**: Secure software development lifecycle integration, mobile app security testing, and code review. - **Vulnerability Management**: Internal/external scans, ASV services, and continuous monitoring. - **AI Risk Advisory**: Assessing and managing risks associated with artificial intelligence deployments. - **Advisory & Strategy**: CISO program management, third-party risk management, and cyber breach response. ## Market Standing - **Valuation/Market Cap**: Not disclosed (private company) - **Key Metric**: Annual Revenue of **USD 200,000,000** (fiscal year ending July 31) | Total funding raised: **$9.35M** (primary rounds from 2011–2013, later private equity) - **Notable Investors/Partners**: Baird Capital (lead in Series A & B), Apax Partners (current owner) - **Growth Signals**: - 679 employees (+1.0% YoY); ~2.2% monthly LinkedIn follower growth - Acquired Veris Group (2016), Denim Group (2021), Neuralys (2021) - Recognized as a **Top Workplace** since 2018 - 990+ certifications held by employees, including 200+ cloud-related - Recipient of 2022 Secretary of Defense Employer Support Freedom Award and HIRE Vets Medallion Award ## Competitive Advantages - **Deep FedRAMP expertise** as a 3PAO advisory firm – a critical differentiator for government and regulated industries. - **Broad compliance framework coverage** (PCI-DSS, HIPAA, SOC 2, HITRUST, FISMA) allows cross-selling and one-stop-shop engagements. - **Acquired niche firms** (e.g., Denim Group for application security, Veris Group for FedRAMP) to build a comprehensive suite. - **Long-standing relationships** with major cloud providers (AWS, Google Cloud, Azure) and a strong alumni network feeding into top tech companies. ## Strategic Focus - **AI Risk & Cloud Migration**: Capitalizing on growing demand for AI governance and secure cloud adoption. - **Compliance Automation**: Developing tools and processes to streamline continuous compliance for clients. - **Expanding Hyperscaler Partnerships**: Recent job postings for a Director of Hyperscaler Strategy & Partnerships indicate a push to deepen ties with AWS, Google, and Azure. - **Talent Development**: Investing in employee certifications and tuition reimbursement to maintain a highly skilled workforce. ## Why Work Here - **Culture & Inclusion**: Coalfire emphasizes diversity, employee resource groups, team events (hikes, cookoffs, sporting events), and a “stronger together” ethos. - **Remote/Hybrid Policy**: Many roles are listed as **fully remote** (e.g., Detection and Response Engineer, Principal Cloud Engineer, Senior Google Cloud Security Consultant). The company also offers work-from-home opportunities. - **Benefits**: UnitedHealthcare coverage, flexible paid time off, tuition & certification reimbursement, fitness challenges, and an Employee Assistance Program. - **Growth & Recognition**: Voted a Top Workplace since 2018; strong support for veterans and active-duty service members. - **Engineering Culture**: Opportunity to work on cutting-edge cloud security, FedRAMP, and AI risk engagements with a team holding 990+ certifications. ## Sources 1. [linkedin.com](https://linkedin.com/company/coalfire) 2. [jobs.lever.co](https://jobs.lever.co/coalfire) 3. [coalfire.com](https://coalfire.com/about/careers) 4. [careers.coalfire.com](https://careers.coalfire.com/career-openings) ## Other roles at Coalfire - [Senior SIEM Engineer](https://feeny.ai/job/senior-siem-engineer-coalfire-united-states-wdzt07j4b2y7) — United States - [Principal Solutions Architect](https://feeny.ai/job/principal-solutions-architect-coalfire-united-states-wcytvxjvw91n) — United States - [Associate, Compliance Security Penetration Tester](https://feeny.ai/job/associate-compliance-security-penetration-tester-coalfire-united-states-1wradjdtpp3y) — United States - [Account Executive - Compliance Sales](https://feeny.ai/job/account-executive-compliance-sales-coalfire-united-states-90mcmcjx115g) — United States - [Account Executive - DivisionHex](https://feeny.ai/job/account-executive-divisionhex-coalfire-united-states-ssesj9vdve5f) — United States - [Account Executive - AI, Cloud and Compliance Advisory](https://feeny.ai/job/account-executive-ai-cloud-and-compliance-advisory-coalfire-united-states-0tcs1yt82q6w) — United States - [Engagement Architect - Cloud Architecture (FedRAMP)](https://feeny.ai/job/engagement-architect-cloud-architecture-fedramp-coalfire-united-states-2zt8ph4srkeb) — United States - [Detection and Response Engineer (SPLUNK)](https://feeny.ai/job/detection-and-response-engineer-splunk-coalfire-united-states-qc0tw7a7ywmd) — United States - [Operational Technology Security Consultant](https://feeny.ai/job/operational-technology-security-consultant-coalfire-united-states-4h2yb05p2526) — United States - [Senior Google Cloud Security Consultant](https://feeny.ai/job/senior-google-cloud-security-consultant-coalfire-united-states-4gzmsx9babpw) — United States