Cloud Security GRC Consultant
Core
Subject Matter Expert applying NIST RMF and FedRAMP frameworks to secure complex systems on Google Cloud for federal customers.
Role type
Senior IC Cloud Security GRC Consultant
Builds
Compliance artifacts (SSP, SCTM, POA&M) and security posture for federal cloud systems
Domain
US Federal Government / Cloud Security
Deliverable
client delivery
Required skills
NIST RMF, FedRAMP, Google Cloud services, eGRC tools (eMASS, XACTA, RSA Archer), security control assessment, risk analysis, documentation management, executive communication
Preferred skills
Google Cloud Professional Certification, Agile methodology, Google Cloud Security Command Center, US Public Sector experience, DoD/DISA policies
Technologies
Google Cloud Platform, eMASS, XACTA, RSA Archer, Security Command Center
Responsibilities
Conduct technical security control assessments within GCP environments; manage development and finalization of RMF artifacts; serve as liaison with Authorizing Officials and security assessors; provide security guidance to engineering teams for DevSecOps integration; develop Plan of Action and Milestones (POA&M) entries; train and mentor team members on RMF processes
Seniority
Senior, hands-on IC with mentorship