A

AGE Solutions

Federal network and cyber engineering

Cloud Security Control Assessor Mid

Full-Time
$100k/yr+ Performance bonuses + 401(k) match + Military differential pay
Senior
Bachelor's
Fort Meade, MD, USA
In PersonFull-time on-site work is required, and applicants must live within commuting distance of Fort Meade.
No H1B Sponsorship
US Top Secret Clearance Required

About the job

Requirements
  • Bachelor's degree; an IT-related field is preferred.
  • Five years of overall experience in a cybersecurity or network security position.
  • An active Department of Defense Top Secret clearance with Sensitive Compartmented Information eligibility.
  • Department of Defense 8570 IAM/IA Technical Level II certification.
  • Working knowledge of the Department of Defense Risk Management Framework and DoDI 8510.01.
  • Familiarity with the Department of Defense Cloud Computing Security Requirements Guide and associated cloud security policies.
  • Familiarity with security controls for Azure, Amazon Web Services, and other cloud platforms.
  • Experience conducting security assessments and developing security documentation such as System Security Plans, Security Assessment Reports, Plans of Action and Milestones, and Security Assessment Plans.
  • Proficiency with eMASS or equivalent Government Risk and Compliance tools.
  • Ability to interpret and apply National Institute of Standards and Technology Special Publication 800-53 security controls in cloud environments.
  • Strong analytical and technical writing skills, with the ability to communicate complex topics clearly.
  • Applicants must reside within a commutable distance of Fort Meade, Maryland to work on-site full time.
Responsibilities
  • Conduct cybersecurity assessments and validations of Cloud Service Offerings in support of the Department of Defense Provisional Authorization process.
  • Prepare 30 Cloud Security Assessment Packages per year, including validated cybersecurity controls, certifier recommendations, and residual risk statements.
  • Review Cloud Service Provider documentation packages, including architectural diagrams, System Security Plans with addendums, Readiness Assessment Reports, Security Assessment Plans, and Security Assessment Reports.
  • Evaluate supporting materials such as Plans of Action and Milestones, Change Requests, Extension and Deviation Requests, Whitelist Requests, Corrective Action Plans, templates, checklists, and Continuous Monitoring artifacts.
  • Attend technical kickoff meetings to evaluate and document the Cloud Service Provider's security posture and readiness for assessment.
  • Analyze and provide feedback on assessment documentation, including Readiness Assessment Reports, Security Assessment Plans, System Security Plans, and system architecture diagrams.
  • Identify and document the operational impact of security authorizations, changes, or identified vulnerabilities within the Cloud Service Provider's environment.
  • Develop complete Cloud Security Assessment Packages in accordance with Department of Defense standards, including Security Assessment Reports, Plans of Action and Milestones, and Deviation Requests.
  • Create authorization recommendation memorandums summarizing compliance with Department of Defense cybersecurity controls, technical evaluation results, and residual risk considerations.
  • Draft Department of Defense Provisional Authorization memorandums outlining Cloud Service Offering boundaries, service offerings, authorization duration, terms and conditions, Department of Defense usage considerations, and follow-on actions.
  • Validate implementation of Cloud Service Offering controls within eMASS or a government-provided Government Risk and Compliance platform, and log assessment completion in the Mission Security Review.
  • Review the Customer Responsibility Matrix and ensure correct inheritance mapping within eMASS or the designated Government Risk and Compliance tool.
  • Enter all authorization conditions into eMASS as system-level Plans of Action and Milestones and monitor their timely resolution.
  • Upload and associate Cloud Service Provider documentation with applicable security controls in eMASS or the appropriate system of record.
  • Track and manage Cloud Service Offering data using the Team Lead Resource Assessment Database.
  • Maintain and update the Department of Defense Cloud Process Guide and associated templates, forms, checklists, and documentation.
  • Contribute to internal instructions, how-to guides, and reference materials supporting consistent assessor workflows.
  • Ensure assessment activities comply with DoDI 8510.01 and the Department of Defense Cloud Computing Security Requirements Guide.
  • Document assessment methodologies and validation best practices to improve assessment accuracy, consistency, and process efficiency.
  • Support ongoing development and annual updates of the Department of Defense Cloud Assessment Process Guides in alignment with evolving policy and government directives.
Desired Qualifications
  • An IT-related bachelor's degree.
  • Familiarity with security controls for Azure, Amazon Web Services, and assorted cloud platforms.

About the company

AGE Solutions delivers technology and professional services to U.S. government, defense and intelligence organizations. Its capabilities include network engineering, cloud computing, cybersecurity, software-defined infrastructure and connected-device environments. Technical teams design, modernize and protect systems that must remain resilient under demanding mission and security requirements. The company operates as a federal technology contractor, using consulting and engineering engagements to solve customer-specific infrastructure problems rather than marketing a single commercial platform to general business users.

Company Size

N/A

Company Stage

N/A

Total Funding

N/A

Headquarters

N/A

Founded

N/A