Want to know if you’re a fit? Upload your resume and let our AI show you.
Skills
Amazon Web Services (AWS)unmatched
Analysis Skillsunmatched
Auditingunmatched
Automationunmatched
Change Controlunmatched
Change Requests/Ordersunmatched
Cloud Architectureunmatched
Cloud Computingunmatched
Communication Skillsunmatched
Computer Scienceunmatched
Computer Securityunmatched
Consultingunmatched
Detail Orientedunmatched
Documentationunmatched
External Auditunmatched
GCP (Good Clinical Practices)unmatched
Information Technology & Information Systemsunmatched
Information/Data Security (InfoSec)unmatched
Internal Auditunmatched
Interpersonal Skillsunmatched
Maintain Complianceunmatched
Microsoft Windows Azureunmatched
Problem Solving Skillsunmatched
Riskunmatched
Risk Management Framework (RMF)unmatched
Security Analysisunmatched
Security Architectureunmatched
Sensitive Compartmented Information (SCI)unmatched
Software Development Lifecycle (SDLC)unmatched
Software Engineeringunmatched
Systems Maintenanceunmatched
Team Playerunmatched
Time Managementunmatched
Top Secret Clearanceunmatched
Workflow Analysisunmatched
Description
Job Title: Cloud Information Assurance Engineer
Location: Tysons, VA
Fulltime Direct Hire
Salary: $150K - $155K/Annually
Clearance: Active TS/SCI
Overview: As a Cloud Information Assurance Engineer, you will contribute the end-to-end compliance lifecycle for client cloud products, guiding them from initial inception through final authorization. This role demands a balanced expertise in GRC governance and hands-on Cloud Security Engineering, all while navigating our client's unique, fast-paced environment. The ideal candidate will combine a deep technical understanding of cloud architectures and security with proficiency in the Risk Management Framework (RMF) to drive secure innovation.
Responsibilities include:
Steer Client cloud services and products from inception to authorization.
Partner with engineering and compliance teams to develop all necessary artifacts for the compliance package.
Conduct Security Impact Analyses (SIAs) for all System Change Requests (SCRs) and update compliance documentation to reflect approved changes.
Perform end-to-end maintenance of System Security Plans (SSPs) and Plans of Action and Milestones (POA&Ms).
Lead internal and external audit evidence management, ensuring 100% on-time fulfillment of requests.
Maintain and update compliance artifacts in GRC tools, ensuring precise mapping of controls to frameworks.
Consult with engineering teams to ensure security controls are defined and implemented throughout the system development lifecycle.
Collaborate with the Configuration Change Board (CCB) to ensure changes align with security policies and verify that they do not introduce new vulnerabilities.
Leverage client automation tools to identify security workflow bottlenecks and design automated solutions for compliance operations.
Job Requirements Qualifications:
This position requires an active TS/SCI clearance.
Bachelor’s degree in computer science, engineering, information assurance, or a related discipline and has at least 5 or more years of experience in an information technology role. Additional experience may be substituted for a degree.
Is currently DOD 8140 certified or possesses certifications to be eligible for DOD 8140 certification.
Experience with cloud service providers such as AWS, Azure, GCP, etc.
Experience in information assurance and or governance risk and compliance is required.
Excellent analytical, problem-solving, and critical thinking skills.
Strong attention to detail and ability to document findings accurately.
Effective communication and interpersonal skills to collaborate with diverse stakeholders.
Ability to work independently and as part of a team.