> Markdown version of [/jobs/ext/1263899-cloud-security-authorization-technical-analyst](https://www.wearedevelopers.com/jobs/ext/1263899-cloud-security-authorization-technical-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cloud Security & Authorization Technical Analyst - **Company:** Guidehouse Inc. - **Location:** Hanover, MD, United States - **Experience:** Experienced - **Salary:** $85,000.0 - $141,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Microsoft Azure, Software as a Service, Cloud Computing Security, Cloud Engineering, Infrastructure as a Service (IaaS), Information Technology Audit, Platform as a Service (PAAS), Cloud Services, Zero Trust Network Access, SARS Software Products, Containerization, RSA Archer Platform, Servicenow - **Published:** July 14, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9026356/cloud-security-authorization-technical-analyst ## About the Role * Must be able to OBTAIN and MAINTAIN a Federal or DoD "PUBLIC TRUST"; candidates must obtain approved adjudication of their PUBLIC TRUST prior to onboarding with Guidehouse. Candidates with an ACTIVE PUBLIC TRUST or SUITABILITY and maintain an active HHS/NIH clearance are preferred. * Minimum of TWO (2) years experience securing and engineering cloud platforms in federal or regulated environments. * Demonstrated expertise implementing and validating cloud security controls aligned to NIST RMF and FedRAMP. * Hands on experience reviewing or performing independent assessments, IV&V, or third party security assessments. * Deep understanding of shared responsibility models, control inheritance, and cloud risk management. * Experience developing and reviewing RMF documentation and SARs. * Ability to translate complex cloud engineering concepts into clear risk and compliance narratives. * Strong collaboration skills across engineering, security, compliance, and government teams. * Experience with AWS, Azure, or GCP cloud security architectures in FedRAMP authorized environments. * Prior experience supporting or acting as a 3PAO, IV&V team member, or independent assessor. * CISSP, CCSP, AWS/Azure Security Specialty, or similar certification. * Experience assessing CI/CD pipelines, IaC, containerized environments, or Zero Trust architectures. * Experience supporting high impact or financial systems within federal agencies. * Familiarity with ServiceNow, eCase, or automated GRC platforms. ## Description The Cloud Security & Authorization Technical Analyst provides deep technical expertise in securing, engineering, and independently assessing federal cloud environments. This role blends hands on cloud security engineering with Assessment & Authorization (A&A), Independent Verification & Validation (IV&V), and third party assessment support to ensure cloud platforms meet federal security, risk, and compliance requirements. This position serves as a technical authority supporting FedRAMP based cloud authorizations, agency specific control implementations, and independent assessments while advising government stakeholders on secure cloud architecture and risk posture. * Provide technical cloud security leadership for Assessment & Authorization (A&A) activities across IaaS, PaaS, and SaaS cloud environments aligned to NIST RMF and FedRAMP. * Perform detailed technical reviews of cloud architectures, configurations, and security control implementations to validate compliance with NIST SP 800 53 and agency security requirements. * Support and execute independent assessment or IV&V activities, including readiness reviews, control validation, and Security Assessment Report (SAR) development. * Analyze Cloud Service Provider (CSP) FedRAMP packages (P ATO) and advise on agency specific control inheritance, shared responsibility models, and residual risk. * Develop and review RMF artifacts including SSPs, control implementation matrices, SARs, POA&Ms, risk acceptance documentation, contingency plans, BIAs, PIAs, and ISAs. * Conduct interviews and technical walkthroughs with system engineers, ISSOs, CSPs, and service providers to validate control implementation effectiveness. * Support third party assessment (3PAO) coordination and provide technical quality assurance of assessment deliverables. * Advise stakeholders on secure cloud design, compensating controls, and remediation strategies to address identified risks. * Support IT audit and IV&V activities related to cloud security controls, evidence validation, and findings remediation. * Contribute to cloud security standards, SOPs, and reusable authorization patterns to improve efficiency and consistency. ## Related Videos - [Developer Tools for Microsoft Azure](https://www.wearedevelopers.com/videos/450-developer-tools-for-microsoft-azure) - [Leverage Cloud Computing Benefits with Serverless Multi-Cloud ML ](https://www.wearedevelopers.com/videos/78-leverage-cloud-computing-benefits-with-serverless-multi-cloud-ml) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [ZEISS & Microsoft - Building the Next Generation Medical Ecosystem in the Cloud](https://www.wearedevelopers.com/videos/424-zeiss-microsoft-building-the-next-generation-medical-ecosystem-in-the-cloud) - [Develop enterprise-ready applications for Microsoft Teams with Azure resources on modern web technologies](https://www.wearedevelopers.com/videos/187-develop-enterprise-ready-applications-for-microsoft-teams-with-azure-resources-on-modern-web-technologies) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud](https://www.wearedevelopers.com/magazine/600-got-ai-ideas-but-no-money-here-are-10-free-ways-to-level-up-your-ai-skills-with-google-cloud) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)