Janus Soft is seeking an elite Senior Cloud Security Assessment & Compliance Engineer to support the Integrated Cloud Security Support 2 (ICSS 2) program in Herndon, VA. In this mission-critical role supporting DDI/ITE/CW/CWSC, you will bridge technical cloud engineering with high-level intelligence community security policy (NIST RMF and ICD 503).
You will manage and execute security assessments, continuous monitoring, security compliance, and change management activities across four major Cloud Service Providers: AWS, Google Cloud, Oracle Cloud, and Microsoft Azure. Working directly with Sponsor leadership, internal components, and Cloud Service Providers (CSPs), you will perform vulnerability scan analysis, prepare body of evidence (BoE) packages, track POA&Ms, facilitate Technical Exchange Meetings (TEMs), and build program compliance dashboards to ensure top-tier security posture across multi-cloud environments.
Security Clearance: Active TS/SCI with Full Scope Polygraph.
Cloud Security Assessments: Demonstrated experience conducting security assessments specifically for cloud infrastructure and cloud services across AWS, Azure, Google Cloud, or Oracle Cloud architectures.
A&A & Compliance Tracking Tools: Demonstrated experience using compliance tools to track Assessment and Authorization (A&A) activities, specifically Xacta 360, Risk Vision, or RSA Archer.
Vulnerability & Scan Analysis Tools: Hands-on experience with continuous monitoring requirements, including scan analysis for critical or high findings using common vulnerability scanning tools such as Rapid7, Nessus, and Qualys.
POA&M Management: Demonstrated experience monitoring, tracking, and closing Plan of Action and Milestone (POA&M) items.
NIST RMF & Control Concepts: Demonstrated experience with the common control provider concept within the NIST Risk Management Framework (RMF) and ICD 503 standards.
SCA & Security Packages: Demonstrated experience with security control assessments (SCAs), including collaborating with SCAs and preparing security packages for SCAs.
Information System Security Engineering (ISSE): Demonstrated experience conducting ISSE activities and assessing/reviewing cross-domain technology and common architecture designs.
Technical Exchange Facilitation: Demonstrated experience facilitating Technical Exchange Meetings (TEMs) with Cloud Service Providers to review cloud service architectures.
Project Management & Metrics: Demonstrated project management experience (project planning, task tracking, milestone management, resource coordination) and experience developing/maintaining program metrics, key performance indicators, and compliance status dashboards.
Leadership Communications: Demonstrated experience preparing technical reports, program highlights, status briefings, and leadership communications.
Xacta 360 Expertise: Direct, hands-on experience working within Xacta 360 for workflow management and compliance tracking.
IC & Sponsor A&A Processes: Demonstrated experience utilizing the Sponsor’s or IC element’s specific Assessment & Authorization (A&A) process and Sponsor A&A tools.
Body of Evidence (BoE) Creation: Demonstrated experience creating or reviewing A&A body of evidence documentation within a multi-cloud security environment.
Security Control Implementation: Demonstrated experience identifying, implementing, or reviewing appropriate information security controls tailored to complex cloud systems.