Cloud GRC Engineer
Nastech Global, Inc.
United States
4 days ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Apply on www.clearancejobs.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
10 years minimum
Working hours
Regular working hours
Job source
Tech stack
Application Programming Interfaces (APIs)
Amazon Web Services
Software System Penetration Testing
Cloud Computing
Cloud Engineering
Cyber Security
Information Systems
Information Technology Audit
Scripting
Information Security Management System
SC Clearance
Information Technology
Job description
Clearance Required: US Citizen with active Public Trust or Top Secret clearance (Secret clearance will take too long for someone to start according to client), Audit & Assessment Leadership
- Own the organization’s full audit and assessment calendar, ongoing/continuous control assessments, financial and IT-financial audits, internal controls testing, and security compliance audits (e.g., SOC 1 Type II). Serving as the primary point of contact for external auditors and assessors.
- Lead recurring meetings and working sessions with the client, auditors, and assessors across the audit lifecycle: kickoffs, evidence walkthroughs, interviews, findings reviews, and status updates. Represents the organization’s control environment directly to external stakeholders.
- Provide audit support across the full assessment portfolio, including penetration testing, red/purple/white team exercises, and periodic CISA high-value-asset assessments, incorporating all findings into the risk register and remediation lifecycle.
- Support new system authorization (ATO) and periodic reauthorization efforts, coordinating required documentation and evidence on a recurring cycle.
Security Documentation & Control Ownership
- Own ongoing maintenance of the System Security Plan (SSP): control implementation updates, system and technical descriptions, and review of inherited/tailored controls against the NIST 800-53 baseline. Validating control descriptions against the actual cloud architecture and configuration, not just the paper record.
- Lead the annual review and executive sign-off cycle for core security documentation and review the organization’s control catalog for accuracy against how the environment is built and configured.
Continuity & Resilience Planning
- Own the annual review, update, and test cycle for business continuity and resilience documentation: business impact analysis, contingency plans, disaster recovery plans, and incident response plans. Grounded in the actual failover, backup, and recovery architecture of the cloud environment, not generic templates.
Privacy
- Lead recurring privacy impact/threshold assessments in coordination with the privacy function, including technical review of how architecture handles the data in scope.
Metrics, Reporting & Automation
- Own recurring compliance reporting deliverables: inventory reports, compliance scorecards, SLA and audit-performance metrics, progress reports, and build the automation that generates them directly from the cloud environment (native services, APIs, infrastructure-as-code state) rather than manual collection.
- Design, build, and maintain automated evidence-collection and continuous-monitoring pipelines using native cloud services and scripting/IaC, reducing manual, screenshot-based collection across the full audit and reporting calendar above.
- Identify the highest-value recurring manual processes across audit, documentation, and reporting work, and personally build the automation to address them. This role is expected to build, not just spec and hand off.
Governance & Stakeholder Coordination
- Maintain governance documents that codify the organization’s security and audit-support processes.
- Serve as the point of contact for ad hoc security and privacy inquiries and impact-analysis requests from system and business owners.
- Lead recurring coordination meetings with system owners, risk management, and compliance stakeholders to maintain shared visibility into audit status, findings, and remediation.
Requirements
Some sort of Audit experience is preferred, * 10+ years of combined experience across cloud engineering and GRC/IT audit/information security compliance, with genuine hands-on depth in both
- Bachelor’s degree in computer science, cybersecurity, information systems, or a related field preferred; equivalent professional experience accepted in lieu of a degree.
- Demonstrated experience building or maintaining cloud infrastructure and automation (IaC, scripting, cloud-native tooling) in a production environment.
- Demonstrated experience serving as the primary point of contact between technical teams and external auditors or assessors, and owning security documentation (e.g., SSP) and control implementation.
- Experience managing findings and remediation from audits, penetration testing, or red/white team engagements through to closure.
- A portfolio or concrete example of a manual compliance or reporting process the candidate personally automated is a strong plus. Frameworks: NIST 800-53, NIST CSF, A-123, FISMA, and SOC 1/2 Type 2.
- Relevant certifications: AWS Certified Solutions Architect or Security, CISSP, CISA, CRISC, or CGRC.
- Candidate must demonstrate AWS experience proficiency
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.clearancejobs.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
AJ
Austin Joy
over 4 years ago
LM
Luis Minvielle
7 Cloud Computing Trends Coming in 2025 for Developers
over 2 years ago
LM
Luis Minvielle
A Guide to Green Tech and Green IT Careers
over 2 years ago
CS
Christina Schaireiter
Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence
4 months ago
LM
Luis Minvielle
Fully Remote Software Engineer Jobs
over 2 years ago
ER
Erin Rifkin
Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud
over 1 year ago