Cloud Security GRC ConsultantHerndon, VA

BuddoBot Inc.

Herndon (VA)

Hybrid

USD 100,000 - 140,000

Full time

5 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Dark Wolf seeks a Google Cloud Security GRC Consultant to translate complex cloud architecture into verifiable evidence for Authorization to Operate. You will guide engineers and cloud architects, applying RMF, FedRAMP, and 3PAO reviews to keep systems compliant.

Hybrid role based in Herndon, VA, requiring US citizenship and ability to obtain a Secret clearance. Expect 100k–140k USD, commensurate with experience and skills.

Qualifications

  • 2+ years of relevant experience in cloud security, GRC, and RMF/ATO processes.
  • One Google Cloud Professional Certification is required.
  • Experience supporting RMF, acting as an ISSO or Security Controls Validator.
  • Hands-on with eGRC tools like eMASS and XACTA.
  • Ability to explain complex security concepts to technical and non‑technical audiences.
  • Familiarity with IaC (Terraform) and automation to support compliance tasks.

Responsibilities

  • Work within a fast-paced Agile team.
  • Stay current on Google Cloud services and security technologies.
  • Implement security best practices for Google Cloud solutions.
  • Support FedRAMP, NIST SP 800-53 controls, and agency security overlays.
  • Develop and finalize authorization artifacts for ATO processes.
  • Collaborate with cloud architects to embed security in system design.

Skills

Cloud security
FedRAMP RMF
GRC experience
Security auditing
Communication
Terraform / IaC

Education

B.S. in Information Security or CS

Tools

eMASS
XACTA
OSCAL
Terraform

Job description

Dark Wolf's Google Cloud Security Governance, Risk, and Compliance (GRC) Consultants are innovative security professionals responsible for applying federal security frameworks (such as the National Institute of Standards and Technology (NIST) Risk Management Framework (RMF) and Federal Risk and Authorization Management Program (FedRAMP)) to modern, complex Google Cloud environments. We are looking for tech-forward consultants who want to move beyond checklist compliance. This role requires a solid understanding of Google Cloud services and the ability to bridge the gap between engineering and security. The ideal candidate will help navigate the Assessment & Authorization (A&A) lifecycle, partnering directly with cloud architects to integrate compliance into system design and translating complex cloud architecture into verifiable evidence to achieve an Authorization to Operate (ATO).

Responsibilities
  • Work collaboratively within a fast paced Agile team environment
  • Stay up-to-date on the latest Google Cloud services and technologies
  • Implement security best practices for Google Cloud solutions
  • Serve as a key contributor for federal compliance requirements, including FedRAMP, NIST SP 800-53, and agency-specific security overlays
  • Support development and implementation of innovative methods to achieve compliance with government and commercial cybersecurity frameworks
  • Conduct detailed technical security control assessments against system components and configurations within the GCP environment, identifying gaps, risks, and recommended mitigations
  • Actively contribute to the development and finalization of authorization artifacts
  • Partner with cloud architecture and engineering teams to provide actionable compliance guidance, ensuring security is built-in from system design through deployment
  • Utilize Google Cloud native tools and features to aid in continuous monitoring (ConMon) activities, vulnerability management, and security posture management
  • Support reviews with the Authorizing Official (AO), security assessors (e.g., 3PAOs), and federal agency security teams during control assessments and authorization reviews
  • Develop clear, compelling Plan of Action and Milestones (POA&M) entries, helping the team communicate system risks, impact, and mitigation strategies to stakeholders
  • Support strategic consulting efforts on evolving federal cloud security policy and best practices
Qualifications
  • 2+ years of relevant experience
  • At least one Google Cloud Professional Certification
  • Experience supporting RMF processes, acting as an ISSO, Security Controls Validator, or performing information assurance engineering
  • Hands-on with eGRC tools like eMASS and XACTA
  • Ability to clearly communicate complex security concepts to both technical and non-technical stakeholders
  • Strong problem-solving skills with a proven ability to quickly learn and apply new technologies to solve complex client challenges
  • Familiarity with cloud automation, Infrastructure as Code (e.g., Terraform), or scripting to help automate compliance tasks
  • Understanding of Google Cloud services and technologies
  • B.A. or B.S. Information Security, Computer Science, or related discipline
  • US Citizenship and clearable up to a Secret Security Clearance
Preferred Qualifications
  • Experience working within Agile teams
  • Experience working with Google Cloud compliance products such as Security Command Center and Assured Workloads
  • Hands-on experience with modern compliance automation, OSCAL, Python, or Infrastructure as Code (e.g., Terraform)
  • Experience working with customers in the U.S. Public Sector
  • U.S. Federal Government security clearance
  • Experience with DoD/DISA cybersecurity policies

This position will be a hybrid role based out of Herndon, VA.

The salary range for this position is estimated to be between $100,000.00 - $140,000.00, commensurate on experience and technical skillset.

We are proud to be an EEO/AA employer Minorities/Women/Veterans/Disabled and other protected categories.

In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification form upon hire.

We are strictly looking for direct, full-time W2 employees. We do not engage with third-party staffing agencies, C2C, or 1099 independent contractors for this role.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cloud Security GRC Consultant GCP RMF FedRAMP ATO
Cloud Security GRC Consultant GCP RMF FedRAMP ATO

BuddoBot Inc. • Herndon (VA)

Hybrid
USD 100,000 - 140,000
Google Customer Engineer
Google Customer Engineer

Dark Wolf Solutions, LLC • Herndon (VA)

Remote
USD 125,000 - 150,000
EEO/AA employer
Google Cloud Engineer
Google Cloud Engineer

Dark Wolf • Herndon (VA)

Hybrid
USD 120,000 - 190,000
Senior Cloud Engineer
Senior Cloud Engineer

Dark Wolf Solutions, LLC • United States

Hybrid
USD 150,000 - 170,000
AI Threat Defense Engineer, Professional Services Organization
AI Threat Defense Engineer, Professional Services Organization

Google • New York (NY)

On-site
USD 127,000 - 182,000
Senior Cloud EngineerDark Wolf Hub Location
Senior Cloud EngineerDark Wolf Hub Location

BuddoBot Inc. • Glenview (IL)

Remote
USD 150,000 - 170,000
Senior Security Consultant, Google Public Sector
Senior Security Consultant, Google Public Sector

Google • Reston (VA)

On-site
USD 132,000 - 194,000
Bonus
Equity
Comprehensive benefits
Security Engineer, PSO
Security Engineer, PSO

Google • Seattle (WA)

On-site
USD 152,000 - 221,000
Health insurance
401(k) match
Paid time off
+4
Remote Google Cloud Engineer for DoD | Cloud & Security
Remote Google Cloud Engineer for DoD | Cloud & Security

BuddoBot Inc. • Tampa (FL)

On-site
USD 145,000 - 175,000
Security Engineer - Google Cloud Platform
Security Engineer - Google Cloud Platform

Acunor Infotech • Florham Park (NJ)

Remote
USD 120,000 - 180,000