Cloud Engineer - Governance, Risk, and Compliance (GRC)
New
P
PeratonNational Security, IT
United States, 8am – 5pm Eastern Standard Time (EST)Full-TimeSenior
Salary$112,000 - $179,000 / year
Apply NowOpens the employer's application page
Job Details
- Experience
- Bachelors Degree and 12 years of experience, a Masters Degree and 10 years of experience, or a High School diploma or equivalent and 16 years of experience. 10+ years of combined experience across cloud engineering and GRC/IT audit/information security compliance.
- Required Skills
- AWSPythonTerraformCloudFormation
Requirements
- 10+ years of combined experience in cloud engineering and GRC/IT audit/information security compliance.
- Deep hands-on experience building/maintaining cloud infrastructure, including IaC and cloud-native tools.
- Experience serving as primary point of contact for external auditors and owning security documentation like SSP.
- Expertise in managing audit findings, remediation, penetration testing, and red/white team engagements.
- Proficiency with Infrastructure as Code tools such as Terraform or CloudFormation.
- Strong automation and scripting skills in Python, Bash, or PowerShell.
- Solid understanding of network architecture, segmentation, and access boundaries.
- Fluency with GRC platforms and cloud security tools like AWS Config, Security Hub, CloudTrail, or Wiz/Prisma Cloud.
- Deep knowledge of control frameworks including NIST 800-53, NIST CSF, A-123, FISMA, and SOC 1/2 Type 2.
- One or more relevant certifications: AWS Certified Solutions Architect, AWS Certified Security-Specialty, CISSP, CISA, CRISC, or CGRC.
Responsibilities
- Manage the organization's full audit and assessment calendar, acting as primary contact for external auditors and assessors.
- Lead recurring meetings with stakeholders and auditors for audit lifecycles including walkthroughs, evidence reviews, and status updates.
- Support system authorization (ATO) and reauthorization efforts through documentation and evidence coordination.
- Maintain and update the System Security Plan (SSP) and control catalogs to align with actual cloud architecture.
- Review and test business continuity, disaster recovery, and incident response plans.
- Design, build, and maintain automated pipelines for continuous evidence collection and compliance reporting.
- Manage compliance scorecards, inventory reports, and SLA metrics directly from the cloud environment.
View Full Description & ApplyYou'll be redirected to the employer's site