This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
The Cloud Assessment Analyst III supports DoD and FedRAMP cybersecurity oversight for Cloud Service Offerings by performing Continuous Monitoring, Annual Assessments, and risk evaluations to ensure compliance with RMF and NIST 800-53 requirements. The role works closely with Cloud Service Providers and Authorizing Officials to review security controls, POA&Ms, vulnerability data, deviation and change requests, and to produce risk summaries, reports, and briefings using eMASS and other GRC tools in a mission-critical, regulated environment.
Job Responsibility:
Conducts thorough reviews and analyses of Deviation Requests including validations or justifications for security findings
Evaluates and develops Monthly One Pagers that summarize the cybersecurity posture of Cloud Service Offerings (CSOs)
Performs Annual Assessments to validate the implementation of mandatory security controls across the CSO baseline and assess one-third of the remaining controls annually
Prepares and reviews weekly Playbooks to report on the Continuous Monitoring (ConMon) status of designated CSOs
Reviews and assesses Security Change Requests (SCRs) that propose new requirements or capabilities for CSOs
Analyzes scan data, Plans of Action and Milestones (POA&Ms), and other change artifacts to assess ongoing risk posture changes of Cloud Service Providers (CSPs)
Ensures the DoD and FedRAMP monitoring programs enable effective oversight of CSPs by providing risk-based data to inform Authorizing Officials (AOs)
Performs ongoing assessments and validations to confirm that security controls are implemented and compliant with DoD and FedRAMP standards
Ensures effective operation of system safeguards and controls through a proactive, risk-based monitoring approach
Maintains continuous visibility into CSP applications and devices to support data-driven decision-making and adherence to authorized risk thresholds
Supports risk-based situational awareness for network security by conducting architectural reviews that expedite mitigation efforts
Integrates security and risk management processes to identify actionable items driven by threat and vulnerability assessments
Validates that CSPs regularly perform vulnerability scans as mandated by DoD and FedRAMP security control requirements
Recommends and oversees the submission and review of POA&Ms, vulnerability scans, Playbooks, Change Requests, Deviation Reports, and Monthly One Pagers
Contributes to a leverage model that reduces government costs, time, and resources associated with ConMon for cloud systems
Conducts Annual Assessments in accordance with FedRAMP and DoD requirements
Provides comprehensive ConMon compliance assessments and risk analyses for each assigned CSO including input for annual reviews, extension and change requests, Binding Operational Directives (BODs), and Emergency Directives (EDs) supported by documentation, recommendations, reports, and briefings
Uploads all documentation or changes in control status related to ConMon activities into eMASS or a government-designated Governance, Risk, and Compliance (GRC) system
Documents ConMon standards and frameworks
Utilizes government-specified cybersecurity tools to support cyber compliance monitoring and maintenance
Requirements:
Have an active DoD Top Secret clearance with SCI eligibility
DoD 8570 IAM/IA Technical (IAT) Level III certification
Strong knowledge and hands-on experience with FedRAMP, NIST SP 800-53, DoD RMF, and related cybersecurity frameworks
Proven experience working with Cloud Service Providers (CSPs) in a government or regulated environment
Expertise in evaluating security control implementations, conducting Annual Assessments, reviewing POA&Ms, deviation requests, and other artifacts related to risk posture
Demonstrated experience using eMASS, and familiarity with other GRC tools used by DoD or federal agencies
Solid understanding of vulnerability scanning tools, SIEM platforms, and security monitoring tools
Strong analytical skills with the ability to interpret technical data and identify risks and mitigation strategies
Excellent verbal and written communication skills to produce technical reports, risk summaries, and briefings for stakeholders including Authorizing Officials (AOs)
Experience developing or maintaining Continuous Monitoring (ConMon) plans, reports, and dashboards
Ability to work independently and collaboratively in a fast-paced, mission-critical environment
Bachelor's degree (IT-related field preferred) and eight (8) years of overall experience in cybersecurity or network security position
with at least 5 years in cloud security assessment or continuous monitoring roles