Cloud Engineer - Governance, Risk, and Compliance (GRC)

Peraton

Herndon (VA)

Remote

USD 112,000 - 179,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Peraton is seeking a Cloud Engineer - Governance, Risk, and Compliance (GRC) to lead audits, control testing, and evidence collection across the cloud environment. The role emphasizes automating evidence, managing SSP and security documentation, and coordinating with external auditors.

You will work with AWS-native tools and IaC to implement compliant processes, supporting continuous monitoring and secure cloud operations in a remote setting.

Qualifications

  • US citizenship required and ability to obtain/maintain Public Trust clearance.
  • 10+ years of combined cloud engineering and GRC/security compliance experience.
  • Experience building/maintaining cloud infrastructure and automation (IaC, scripting, cloud-native tooling).
  • Experience coordinating with external auditors/assessors and owning security documentation (e.g., SSP).
  • Strong knowledge of frameworks: NIST 800-53, CSF, A-123, FISMA, SOC 1/2 Type 2.

Responsibilities

  • Own audit and assessment calendar, continuous control assessments, and security audits (SOC 1 II).
  • Lead meetings with client, auditors, and assessors across audit lifecycle.
  • Develop automated evidence collection and continuous monitoring pipelines using cloud-native services and IaC.
  • Manage system authorization/renewal efforts with required documentation and evidence.

Skills

Infrastructure depth
IaC
Automation scripting
Security tooling
Networking basics
GRC tooling
NIST 800-53
Communication
Stakeholder management

Education

Bachelor's degree in Computer Science / related field
Master's degree (preferred)
High School diploma with extensive experience

Tools

Terraform
CloudFormation
Wiz
Prisma Cloud
SIEM
EDR
AWS Config
Security Hub

Job description

Cloud Engineer - Governance, Risk, and Compliance (GRC)

Job Locations: US

Responsibilities
Audit & Assessment Leadership
  • Own the organization's full audit and assessment calendar, ongoing/continuous control assessments, financial and IT-financial audits, internal controls testing, and security compliance audits (e.g., SOC 1 Type II). Serving as the primary point of contact for external auditors and assessors.
  • Lead recurring meetings and working sessions with the client, auditors, and assessors across the audit lifecycle: kickoffs, evidence walkthroughs, interviews, findings reviews, and status updates. Represents the organization's control environment directly to external stakeholders.
  • Provide audit support across the full assessment portfolio, including penetration testing, red/purple/white team exercises, and periodic CISA high-value-asset assessments, incorporating all findings into the risk register and remediation lifecycle.
  • Support new system authorization (ATO) and periodic reauthorization efforts, coordinating required documentation and evidence on a recurring cycle.
Security Documentation & Control Ownership
  • Own ongoing maintenance of the System Security Plan (SSP): control implementation updates, system and technical descriptions, and review of inherited/tailored controls against the NIST 800-53 baseline. Validating control descriptions against the actual cloud architecture and configuration, not just the paper record.
  • Lead the annual review and executive sign-off cycle for core security documentation and review the organization's control catalog for accuracy against how the environment is built and configured.
Continuity & Resilience Planning
  • Own the annual review, update, and test cycle for business continuity and resilience documentation: business impact analysis, contingency plans, disaster recovery plans, and incident response plans. Grounded in the actual failover, backup, and recovery architecture of the cloud environment, not generic templates.
Privacy
  • Lead recurring privacy impact/threshold assessments in coordination with the privacy function, including technical review of how architecture handles the data in scope.
Metrics, Reporting & Automation
  • Own recurring compliance reporting deliverables: inventory reports, compliance scorecards, SLA and audit-performance metrics, progress reports, and build the automation that generates them directly from the cloud environment (native services, APIs, infrastructure-as-code state) rather than manual collection.
  • Design, build, and maintain automated evidence-collection and continuous-monitoring pipelines using native cloud services and scripting/IaC, reducing manual, screenshot-based collection across the full audit and reporting calendar above.
  • Identify the highest-value recurring manual processes across audit, documentation, and reporting work, and personally build the automation to address them. This role is expected to build, not just spec and hand off.
Governance & Stakeholder Coordination
  • Maintain governance documents that codify the organization's security and audit-support processes.
  • Serve as the point of contact for ad hoc security and privacy inquiries and impact-analysis requests from system and business owners.
  • Lead recurring coordination meetings with system owners, risk management, and compliance stakeholders to maintain shared visibility into audit status, findings, and remediation.
Skills
  • Infrastructure depth. Hands-on experience with the organization's full technical environment: cloud (AWS), networking, databases, and midrange software (OS, VDI, Security, and administrative tool stack. Focus is to build in and extract evidence.
  • Infrastructure as Code. Able to read, write, and modify IaC (e.g., Terraform, CloudFormation) to validate infrastructure configurations, and to build policy as code compliance checks into the pipeline.
  • Automation & scripting. Builds working automation (in any language - Python, Bash, PowerShell) for evidence collection, inventory reporting, and continuous monitoring; this is a hands-on build responsibility across this role's full reporting and audit workload, not an occasional task.
  • Security tooling & automation. Able to pull compliance-relevant data and build automated evidence collection from the organization's security tool stack (e.g., SIEM, firewalls, EDR, centralized logging), not limited to cloud-native services. Capable of managing Cloud Native Application Protection Platforms (Wiz, Prisma Cloud) for enterprise "code to runtime" security with automated remediation.
  • Networking fundamentals. Understands network architecture, segmentation, and access boundaries to assess whether a control claim about network security is true in the environment. Including cloud platform's native compliance, logging, and monitoring services (e.g., AWS Config, Security Hub, CloudTrail, Audit Manager) as the primary evidence source, replacing manual collection.
  • GRC platform fluency. Administers and configure GRC/compliance automation tooling to consume evidence pulled from the cloud environment.
  • NIST 800-53 and control framework depth. Experience with control intent (not just control language) to tailor, inherit, and validate controls against real architecture.
  • Written and verbal communication. Translates technical implementation into audit-ready narrative for auditors and translates compliance/control requirements into terms that hold up in architecture and code.
  • Program and stakeholder management. Runs the full audit, documentation, and reporting calendar, with organizational discipline.
Qualifications
Required Qualifications
  • Must be a U.S. Citizen with the ability to obtain and maintain the required Public Trust level clearance.
  • Bachelors Degree and 12 years of experience, a Masters Degree and 10 years of experience, or a High School diploma or equivalent and 16 years of experience.
  • 10+ years of combined experience across cloud engineering and GRC/IT audit/information security compliance, with genuine hands-on depth in both.
  • Demonstrated experience building or maintaining cloud infrastructure and automation (IaC, scripting, cloud-native tooling) in a production environment.
  • Demonstrated experience serving as the primary point of contact between technical teams and external auditors or assessors, and owning security documentation (e.g., SSP) and control implementation.
  • Experience managing findings and remediation from audits, penetration testing, or red/white team engagements through to closure.
  • A portfolio or concrete example of a manual compliance or reporting process the candidate personally automated is a strong plus. Frameworks: NIST 800-53, NIST CSF, A-123, FISMA, and SOC 1/2 Type 2.
  • One or more of the following relevant certifications: AWS Certified Solutions Architect, AWS Certified Security - Specialty, CISSP, CISA, CRISC, or CGRC.
Preferred Qualifications
  • Bachelors Degree in Computer Science, Cybersecurity, Information Systems, or a related field
Peraton Overview

Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world's leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees do the can't be done by solving the most daunting challenges facing our customers. Visit peraton.com to learn how we're keeping people around the world safe and secure.

Target Salary Range

$112,000 - $179,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual's experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay.

EEO

EEO: Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.

Work Location

Remote

Shift Schedule

8am - 5pm Eastern Standard Time (EST)

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cloud Engineer - Governance, Risk, and Compliance (GRC)
Cloud Engineer - Governance, Risk, and Compliance (GRC)

Peraton • Reston (VA)

Remote
USD 112,000 - 179,000
Cloud Engineer - Governance, Risk, and Compliance (GRC)
Cloud Engineer - Governance, Risk, and Compliance (GRC)

Peraton • New York (NY)

Remote
USD 170,000 - 240,000
Remote Cloud GRC Engineer — Audit, Compliance & Automation
Remote Cloud GRC Engineer — Audit, Compliance & Automation

Peraton • Herndon (VA)

Remote
USD 112,000 - 179,000
Senior GRC Technical Engineer
Senior GRC Technical Engineer

Cloud Software Group • San Ramon (CA)

On-site
USD 160,000 - 240,000
Healthcare benefits
401(k) match
Career development
Staff Security Analyst - GRC
Staff Security Analyst - GRC

Jobgether • United States

Hybrid
USD 150,000 - 164,000
Remote work within the United States
Hybrid option with designated offices
Remote Cloud Engineer: GRC & Audit Automation Lead
Remote Cloud Engineer: GRC & Audit Automation Lead

Peraton • Reston (VA)

Remote
USD 112,000 - 179,000
Remote GRC Cloud Engineer: Audit & Compliance Automation
Remote GRC Cloud Engineer: Audit & Compliance Automation

Peraton • New York (NY)

Remote
USD 170,000 - 240,000
Staff GRC Engineer
Staff GRC Engineer

turing • United States

Remote
USD 210,000 - 240,000
GovCloud Compliance Analyst (Cloud Controls & Audit) — E-level
GovCloud Compliance Analyst (Cloud Controls & Audit) — E-level

Sciata • New York (NY)

On-site
USD 65,000 - 79,000
Manager Security Compliance and Risk Management
Manager Security Compliance and Risk Management

RELX • Raleigh (NC)

On-site
USD 118,300 - 219,800
Annual incentive bonus