Sorry, this listing is no longer accepting applications. Don’t worry, we have more awesome opportunities and internships for you.

Cloud Cybersecurity Compliance Engineer

Ashburn Consulting

Cloud Cybersecurity Compliance Engineer

Rockville, MD
Full Time
Paid
  • Responsibilities

    Job Description

    The primary focus of the Cloud Cybersecurity Compliance Engineer will be to identify and prioritize cloud-related risks enterprise-wide, executing comprehensive risk assessments and control gap analyses in line with established information security policies and widely recognized risk management frameworks applicable to a range of public cloud environments.

    The Cloud Cybersecurity Compliance Engineer will be responsible for conducting thorough reviews of legal contracts and agreements relevant to cloud services, including service level agreements (SLAs), data processing agreements (DPAs), and vendor contracts. This involves interpreting complex legal language and terms to ensure compliance with information security and privacy requirements, identifying potential risks or areas of non-compliance, and articulating these findings in a clear, comprehensible manner to business units and legal counsel. The contractor will liaise closely with attorneys and business stakeholders to provide actionable insights, ensuring that contractual obligations align with governance, risk, and compliance frameworks and standards.

    The Cloud Cybersecurity Compliance Engineer will play a lead role on the Governance, Risk, Compliance team having responsibility for the following:

    • Designing, implementing, and continuously improving the cloud information security/privacy compliance program based on applicable policies, local/state/federal laws/regulations and adopted risk management frameworks.

    • Designing, implementing, leading cloud-based risk assessments and control gap analysis procedures, activities, documents, and communication plans

    • Leveraging NIST 800-53/FedRAMP assessment experience, technical, and program management skills to lead, plan, track, collaborate and report on the cloud governance, risk compliance program deliverables, including scheduling/leading meetings, assigning/tracking action items, and developing status reports.

    • Performing cross functional interviews with business, technical and information security partners to determine if information security/privacy controls are implemented correctly, operating as intended, and producing the desired results.

    • Communicating program controls, measurements, metrics, and assessment results confidentially, professionally, and effectively, in both written and verbal formats, with business, technical, and third-party stakeholders.

  • Qualifications

    Qualifications

    • 5+ years-experience applying governance, risk, compliance principles to public cloud ecosystems such as AWS (Amazon), Azure (Microsoft) and/or (GRC) Google

    • 5+ years-experience designing/implementing cloud-based information security/privacy polices mapped to industry standards and regulatory frameworks (e.g., NIST 800-53, FedRAMP, PCI, HIPAA etc.)

    • Designing, implementing, and performing cloud-based risk assessments and control gap analysis; identifying, analyzing, and evaluating cloud security/privacy risks through analysis of vendor-provided SOC2 and other cloud security control documentation.

    • Proven ability to communicate confidentially, professionally, and effectively, in both written and verbal formats, with business, technical, and third-party stakeholders.

    • Developing monitoring, gathering, and analyzing information security and compliance metrics for management for the cloud environment.

    • Must pass a background investigation.

    Additional Information

    All of your information will be kept confidential according to EEO guidelines. Equal Opportunity Employer/Veterans/Disabled. An Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or protected veteran status.

    Ashburn Consulting is an Equal Opportunity Affirmative Action Employer.
    In compliance with the American with Disabilities Act Amendments Act (ADAAA), if you have a disability and would like to request and accommodation in order to apply for a position with Ashburn Consulting, please e-mail hr@ashburnconsulting.com.”

    Ashburn Consulting is an Equal Opportunity Affirmative Action Employer.
    In compliance with the American with Disabilities Act Amendments Act (ADAAA), if you have a disability and would like to request and accommodation in order to apply for a position with Ashburn Consulting, please e-mail hr@ashburnconsulting.com.”