
Cloud Engineer – Governance, Risk, and Compliance (GRC)
Posted Sep 17

Posted Sep 17
This is a fully remote position, open to applicants in United States.
• Manage the complete audit and assessment schedule, encompassing continuous control assessments, financial and IT-financial audits, internal controls testing, and security compliance evaluations.
• Act as the main liaison for external auditors and assessors.
• Facilitate audit lifecycle meetings and working sessions involving clients, auditors, assessors, and stakeholders.
• Assist with penetration testing, red/purple/white team exercises, and CISA high-value asset assessments.
• Oversee new system authorization (ATO) and periodic reauthorization initiatives.
• Keep the System Security Plan updated with control implementation changes, system and technical descriptions, and inherited/tailored control reviews.
• Lead the annual review and executive sign-off processes for security documentation and the accuracy of the control catalog.
• Manage the yearly business continuity and resilience documentation review, updates, and testing.
• Conduct privacy impact and threshold assessments alongside the privacy function.
• Generate compliance reports, inventory reports, scorecards, SLA and audit-performance metrics, and progress updates.
• Design, develop, and sustain automated evidence-collection and continuous-monitoring systems.
• Streamline recurring audit, documentation, and reporting tasks using cloud services, APIs, scripting, and Infrastructure as Code (IaC).
• Maintain governance documents related to security and audit-support processes.
• Address ad hoc security and privacy inquiries and impact-analysis requests.
• Coordinate with system owners, risk management, and compliance stakeholders regarding audit status, findings, and remediation.
• Must be a U.S. citizen.
• Ability to obtain and maintain the necessary Public Trust level clearance.
• Bachelor's degree with 12 years of experience, Master's degree with 10 years of experience, or High School diploma (or equivalent) with 16 years of experience.
• Over 10 years of combined experience in cloud engineering and GRC/IT audit/information security compliance, with practical expertise in both fields.
• Experience in building or managing cloud infrastructure and automation within a production environment.
• Proficiency with Infrastructure as Code, scripting, and cloud-native tools.
• Experience serving as the primary contact between technical teams and external auditors or assessors.
• Expertise in managing security documentation, including System Security Plans (SSP), and control implementations.
• Proven experience in managing findings and remediation from audits, penetration tests, or red/white team activities through to completion.
• Relevant certifications such as AWS Certified Solutions Architect, AWS Certified Security - Specialty, CISSP, CISA, CRISC, or CGRC.
• Hands-on experience with AWS, networking, databases, midrange software, operating systems, VDI, security, and administrative tool stacks.
• Ability to read, write, and modify Terraform or CloudFormation.
• Capacity to develop policy-as-code compliance checks.
• Proficiency in building automation using Python, Bash, or PowerShell.
• Experience with SIEM, firewalls, EDR, centralized logging, Wiz, or Prisma Cloud.
• Understanding of network architecture, segmentation, and access controls.
• Familiarity with AWS Config, Security Hub, CloudTrail, and Audit Manager.
• Administration and configuration experience with GRC/compliance automation tools.
• Knowledge of NIST 800-53 and control frameworks including NIST CSF, A-123, FISMA, and SOC 1/2 Type 2.
• Strong written and verbal communication skills.
• Experience in program and stakeholder management.
• Potential eligibility for overtime.
• Potential eligibility for shift differential.
• Potential eligibility for a discretionary bonus.
LouisianaNOW.Jobs
Nuvei
Salve.Inno
Get handpicked remote jobs straight to your inbox weekly.