Cloud Security Control Assessor with Security Clearance
1 day ago
Overview Steampunk wants you to be a Cloud Security Control Assessor on our team to support a government customer. The primary responsibilities for the position are to support all security assessment activities that ensure risk with in the system is maintained at an acceptable level. The nature of the work requires that the candidate demonstrates initiative, organization, responsibility, customer service skills, and the ability to be flexible and adaptive to a fast-paced, fluid business environment. The candidate must be able to communicate effectively and decisively with all levels of the organization and be able to solve practical problems as well as exercise sound judgement with regards to sensitive and confidential information. Contributions As a member of one of our assessment teams, you will play an important role in performing a wide array of c ybersecurity duties including:
- Lead security assessments in accordance with NIST SP 800-53, NIST RMF (SP , FedRAMP, and agency-specific guidance.
- Evaluate technical, operational, and management controls across cloud, on-premises, and hybrid environments.
- Develop Assessment Plans and Security Assessment Reports (SARs) .
- Coordinate with Information System Security Officers (ISSOs), System Owners, and authorization officials to review evidence and mitigate control deficiencies.
- Analyze vulnerability scans, configuration baselines, and penetration test results to determine control effectiveness.
- Provide technical recommendations to remediate weaknesses and strengthen security posture.
- Maintain assessment documentation in compliance with organizational and federal standards (e.g., FISMA , FedRAMP ).
- Present findings and risk analysis to management and Authorization Officials (AOs).
- Support continuous monitoring processes and control validation efforts for ongoing authorization. Qualifications
- Bachelor's Degree and 5 years of relevant IT cybersecurity experience; OR
- No degree with a total of ten years of cybersecurity experience, including two ( 2 ) years of FISMA experience.
- One of the following certifications (may be obtained within six (6) months of hire):
- Certified Information System Security Professional (CISSP)
- CompTIA Advanced Security Practitioner (CASP)
- Certified Information Systems Auditor (CISA)
- Certified Information Security Manager (CISM)
- Familiarity with one or more : DHS Directive 4300A and NIST Special Pubs 800-30, 800-37, 800-39, 800-53,
- Strong understanding of NIST SP controls, FIPS publications 199 and 200 , and cybersecurity compliance standards.
- Hands-on experience reviewing security control artifacts related to the NIST SP controls .
- Proficiency with assessment tools (e.g., Nessus, Splunk, Tenable.SC, SCAP scanners).
- D irect experience providing independent evaluations for system authorization packages, including in cloud environments (AWS, Azure, etc.).
- Analytical skills to interpret vulnerabilities, compliance gaps, and potential threats in diverse systems .
- Understands the difference between cloud and non-cloud security control baselines. Preferred Qualifications:
- Experience as an Information System Security Officer (ISSO) .
- Experience with Vulnerability, Configuration, and Asset Management tools in support of Continuous Monitoring .
- Excellent analytical, written, and verbal communication skills.
- Strong attention to detail in preparing federal security documentation .
- Experience with :
- POA&M management
- P erforming Security Authorization
- P erforming Risk Analysis and Assessment
- CSAM or similar tool GRC tool Preferred Skills:
- E xperience providing ISSO support to DHS
- Experience supporting systems hosted in Cloud environments.
- Experience supporting systems in Agile and DevOps environments About steampunk Steampunk relies on several factors to determine salary, including but not limited to geographic location, contractual requirements, education, knowledge, skills, competencies, and experience. The projected compensation range for this position is $115,000 to $165,000. The estimate displayed represents a typical annual salary range for this position. Annual salary is just one aspect of Steampunk's total compensation package for employees. Learn more about additional Steampunk benefits here. Identity Statement As part of the application process, you are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud. Steampunk is a Change Agent in the Federal contracting industry, bringing new thinking to clients in the Homeland, Federal Civilian, Health and DoD sectors. Through our Human-Centered delivery methodology , we are fundamentally changing the expectations our Federal clients have for true shared accountability in solving their toughest mission challenges. As an employee owned company , we focus on investing in our employees to enable them to do the greatest work of their careers - and rewarding them for outstanding contributions to our growth. If you want to learn more about our story, visit .
-
Security Control Assessor
1 week ago
Washington, Washington, D.C., United States Tyto Athene, LLC Full timeTyto Athene is searching for aSenior Security Control Assessorto support our federal customer in Washington, DC.ResponsibilitiesSupport RMF steps 4 - assess, 5 - authorize, step 6 - monitor controls conducting system security assessments, supporting the system security authorization to operate process, and conducting annual assessments, respectivelyProduce...
-
Security Control Assessor
1 week ago
Washington, Washington, D.C., United States Tyto Athene, LLC Full timeTyto Athene is searching for a Senior Security Control Assessor to support our federal customer in Washington, DC.Responsibilities: Support RMF steps 4 - assess, 5 - authorize, step 6 - monitor controls: conducting system security assessments, supporting the system security authorization to operate process, and conducting annual assessments, respectively...
-
Cloud Security Engineer
1 day ago
Washington, Washington, D.C., United States ShorePoint Full timeWho we are:ShorePoint is a fast-growing, industry recognized and award-winning cybersecurity services firm with a focus on high-profile, high-threat, private and public-sector customers who demand experience and proven security models to protect their data. ShorePoint subscribes to a "work hard, play hard" mentality and celebrates individual and company...
-
Cloud Security Engineer
1 day ago
Washington, Washington, D.C., United States Improvix Technologies Full time*Job Title:*Cloud Security EngineerLocation:Washington, DC (Onsite)Clearance Required:SecretOverviewWe are seeking aCloud Security Engineerto help design, implement, and maintain secure cloud environments across AWS, Azure, and GCP. The ideal candidate will have hands-on experience with cloud security tools, infrastructure automation, and DevSecOps...
-
DOJ - Cloud Security Engineer
6 hours ago
Washington, Washington, D.C., United States cFocus Software Incorporated Full timecFocus Software seeks a Cloud Security Engineer to join our program supporting the Department of Justice (DOJ). This position is remote. This position requires a Public Trust clearance.Qualifications:Active Public Trust clearanceB.S. degree in Computer Science, Information Technology, or a related field.Minimum of 5 years of IT experience, demonstrating...
-
Washington, Washington, D.C., United States ECS Tech Inc Full time $145,000 - $160,000ECS is seeking a Cloud Service Provider Common Control A to work in our Washington, DC office. ECS is seeking a Cloud Service Provider Common Control Analyst to support the Department of State (DOS), Bureau of Diplomatic Technology (DT). This role is part of the Common Control team, responsible for ensuring high-value and mission-critical systems comply with...
-
Senior Security System
1 day ago
Washington, Washington, D.C., United States Tantus Technologies Full timeOverview:Tantus Technologies, Inc. (Tantus) - recognized by the Washington Post as a Top Workplace - is seeking an experienced Senior System Security / Information Assurance Analyst to lead and support enterprise cybersecurity initiatives across complex IT environments. This role is responsible for assessing, developing, and implementing robust security...
-
Activity Security Representative II
2 weeks ago
Washington, Washington, D.C., United States P-11 Security Full time:P-11 Security, based in Southern California, is a certified Economically-Disadvantaged Women-Owned Small Business (EDWOSB) with over 10 years of experience in the security field. Specializing in Security in Depth (SiD) services, we deliver an integrated suite of 360 Security Services, Cyber Security, and Information Technology solutions, embodying our...
-
Cloud Network Security Architect SME
1 day ago
Washington, Washington, D.C., United States TOMORROW HIRE Full timeCloud Network Security Architect SME (TIC 3.0)Location: Fully Remote (East Coast)Clearance: Public Trust, Secret Clearance preferredEmployment Type: Full-timeSalary: $160,000-$190,000Role OverviewThe TIC 3.0 Developer SME will focus on architecting, implementing, and maintaining secure, compliant network environments in AWS with an emphasis on Trusted...
-
Cloud Security Architect
1 day ago
Washington, Washington, D.C., United States CAQH Full timePosition Summary:The Cloud Security Architect will serve an essential function in safeguarding CAQH's digital infrastructure, applications, and data assets. This professional will be responsible for leading the design, implementation, and ongoing maintenance of comprehensive cloud-based security solutions to protect CAQH from cyber threats and...