This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Our client is seeking a Senior Cloud SA&A Consultant (CSAAS3) for a remote contract supporting cloud security assessments across AWS and Azure environments. The role involves applying ITSG-33 frameworks, assessing SAP and cloud ERP security, and producing key SA&A deliverables including risk assessments, SRTMs, and ATO documentation. The consultant will advise on security controls, access governance, and risk mitigation for enterprise cloud adoption initiatives. Candidates must have 10+ years of cloud security assessment experience, including at least 3 years using ITSG-33 in AWS and Azure environments.
Job Responsibility
Perform cloud security assessments for AWS and Azure environments using ITSG-33 frameworks
Conduct risk calculations and present findings to technical and executive stakeholders
Develop and tailor Security Control Profiles (SCPs) for cloud and legacy systems
Create and maintain SA&A artifacts (SRTM, Statements of Sensitivity, Security Assessment Reports, ATO documentation)
Assess and advise on SAP security controls, access governance, and SoD conflict resolution
Review and apply security standards, policies, and industry best practices
Identify security gaps, process improvements, and mitigation strategies
Support security assurance activities throughout the system development lifecycle
Provide guidance and knowledge transfer on ITSG-33 implementation and cloud security practices
Requirements
10+ years of experience in cloud security assessments and designing security controls for enterprise systems
Minimum 3 years of recent experience applying ITSG-33 in AWS and Azure environments
Strong knowledge of SA&A processes and security assurance frameworks