Jobs and Careers
GU

Cloud Security Assessor - Expert

Guidehouse
United Statesfull_timeVerifiedPosted 20 May 2025

About the role

Job Family:

Technology Consulting


Travel Required:

Up to 25%


Clearance Required:

Active Top Secret SCI with Polygraph

What You Will Do:
The SCA advises key stakeholders, such as the Program Office, Data Owner, and Authorizing Official/Delegated Authorizing Official, concerning the security categorization and impact levels for confidentiality, integrity, and availability of the information on a system.  The SCA conducts a comprehensive assessment of the security controls employed within or inherited by an Information System (IS) to determine their overall effectiveness and submit the Body of Evidence (BoE), composed of the System Security Plan (SSP), Security Assessment Report (SAR), Plan of Action and Milestones (POA&M), and draft Authorization to Operate (ATO) Letter, to the Authorizing Official (AO) or Delegated Authorizing Official (DAO) for review and authorization decision.

This role is responsible for supporting RMF assessment efforts. As an expert Security Controls Assessor with expertise in cloud infrastructure possesses specialized skills in evaluating the security controls of systems hosted in cloud environments. Their technical functions encompass a range of tasks aimed minimizing risk while also ensuring the integrity, confidentiality, and availability of data within the domain. Here are the technical functions typically associated with this role:

  • Support the Assessment and Authorization (A&A) Risk Management Framework (RMF) for client-managed systems, networks, and enclaves across security domains.

  • Validate and review security documentation, ensuring accuracy and compliance with regulatory standards.

  • Advise ISSOs on security categorization and control selection (RMF Steps 1 and 2) and conduct Technical Exchange Meetings (TEMs) with security professionals.

  • Develop test reports, assessment artifacts, and Plan of Action and Milestones (POA&Ms) to document findings and oversee resolution efforts.

  • Perform Security Test and Evaluation (ST&E) assessments, ensuring compliance with DoDIIS security standards.

  • Review system specifications, security needs, and vulnerabilities.

  • Develop security assessment documentation, including System Security Plan (SSP), Security Assessment Report (SAR), and draft Authorization to Operate (ATO) letters.

  • Conduct security assessments using automated tools and manual techniques to evaluate vulnerabilities across domains such as access control, cryptography, network security, and incident response.

  • Perform vulnerability scans, analyze findings, and recommend remediation strategies.

  • Conduct penetration testing, web application security testing, wireless network assessments, and social engineering exercises.

  • Validate security configurations for compliance with policies and industry best practices.

  • Assess regulatory compliance (e.g., GDPR, HIPAA, PCI DSS, SOX) and develop risk mitigation strategies.

  • Prepare detailed assessment reports and communicate findings to stakeholders.

  • Contribute to continuous improvement initiatives for security assessment methodologies and tools.

  • Share cybersecurity knowledge through training, mentoring, and staying updated on emerging threats and trends.

  • Develop and implement automated security assessment and monitoring solutions.

  • Design and maintain security architectures for cloud and on-premise systems.

  • Perform secure code reviews and static/dynamic application security testing (SAST/DAST).

  • Support security engineering efforts in implementing security controls and integrating security solutions within enterprise environments.

  • Conduct forensic analysis and incident response investigations to identify and mitigate security threats.

  • Develop security automation scripts and tools to streamline security assessment processes.


What You Will Need:

  • An ACTIVE and MAINTAINED TOP SECRET/SCI federal security clearance with a Counterintelligence (CI) polygraph

  • Master's degree in Cybersecurity, Computer Science, Software Engineering, Systems Engineering, Information Systems, or a related technical discipline or equivalent experience or 6 Years of additional experience.

  • Certification in DoD 8570.01-M Cybersecurity workforce, compliance with DoD Directive 8140 Cyberspace Workforce Management, and IAT Level III (CASP+ CE, CCNP Security, CISA, CISSP (or Associate), GCED, GCIH, CCSP).

  • THREE (3) or more years' experience cybersecurity


What Would Be Ni

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Guidehouse

View company profile →