Senior Cloud Security Assessor

Sprymethods

Washington (District of Columbia)

On-site

USD 140,000 - 190,000

Full time

9 days ago
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Spry Methods is seeking an experienced Senior Cloud Security Assessor to join our team in the Washington, DC area. The successful candidate will conduct independent security control assessments of cloud and hybrid systems, with strong emphasis on federal cloud environments.

You will lead full-cycle SA&A activities, assess Azure and AWS security controls, review FedRAMP packages, and develop SAPs, SARs, RARs, and POA&Ms. Exceptional analytical skills and clear communication are essential.

Qualifications

  • CISSP or equal certification required.
  • Eight+ years of hands-on security control assessments.
  • Experience with federal cloud environments (Azure/AWS) and FedRAMP.
  • Strong knowledge of RMF and NIST control assessment practices.
  • Ability to analyze large volumes of evidence and draw clear conclusions.

Responsibilities

  • Lead full-cycle SA&A activities for cloud, hybrid, and enterprise systems as an independent assessor.
  • Assess Azure and AWS environments including security controls and operating effectiveness.
  • Review FedRAMP packages and supporting documentation for applicability and gaps.
  • Analyze assessment artifacts such as SSPs, policies, diagrams, inventories, logs, and test outputs.
  • Develop SAPs, SARs, RARs, Evidence Lists, and POA&Ms.
  • Perform testing from admin, operational, and technical perspectives.
  • Interpret vulnerability scans and distinguish true findings from false positives.
  • Communicate findings, risk, root cause, and mitigations to stakeholders.
  • Coordinate evidence requests and assessment schedules with customer personnel.
  • Support program operations and contribute to consistent assessment methods.

Skills

CISSP certification
Independent assessor experience
FedRAMP knowledge
RMF & NIST practices
Azure & AWS cloud security
Security control testing
Security artifacts analysis
Strong written communication
Data/context-driven assessment

Education

Bachelor's degree in cybersecurity, IT, CS or related field
Eight years of relevant specialized experience

Job description

Spry Methods is seeking an experienced Senior Cloud Security Assessor to join our team in the Washington, DC area. The successful candidate will bring extensive hands-on experience conducting independent security control assessments of cloud and hybrid systems, with particular depth in federal cloud environments. This role requires sound professional judgment, strong analytical skills, and a practical, common-sense approach to applying security requirements to system data, technical evidence, mission context, and actual risk.

  • Lead full-cycle Security Assessment and Authorization (SA&A) activities for cloud, hybrid, and enterprise systems as an independent assessor.
  • Assess Microsoft Azure and Amazon Web Services (AWS) environments, including the implementation and operating effectiveness of administrative, operational, and technical security controls.
  • Retrieve and review FedRAMP authorization packages and supporting documentation, then analyze the package for applicability, control inheritance, residual risk, gaps, and customer responsibilities.
  • Conduct detailed analysis of assessment artifacts, including system security plans, policies, procedures, architecture and data-flow diagrams, inventories, configurations, logs, scan results, test outputs, and other supporting evidence.
  • Develop Security Assessment Plans (SAPs), Security Assessment Reports (SARs), Risk Assessment Reports (RARs), Required Evidence Lists, and Plans of Action and Milestones (POA&Ms).
  • Perform network, system, application, and NIST security control testing from administrative, operational, and technical perspectives.
  • Analyze vulnerability scan results, interpret risk, and use manual validation and corroborating evidence to distinguish actionable findings from false positives or unsupported conclusions.
  • Apply security requirements using practical judgment and data context rather than relying solely on checklist compliance. Evaluate whether evidence is relevant, reliable, sufficient, and representative of the assessed environment.
  • Clearly communicate findings, risk, root cause, and feasible mitigation options to technical teams, system owners, executives, and other assessment stakeholders.
  • Coordinate evidence requests, interviews, test activities, and assessment schedules with customer personnel and Information Systems Security Analysts.
  • Support security assessment program operations and contribute to consistent assessment methods, quality reviews, and defensible reporting.
  • Active Certified Information Systems Security Professional (CISSP) certification is required.
  • At least eight years of demonstrated, hands-on experience conducting security control assessments, including substantial experience serving as an independent assessor for cloud and hybrid systems.
  • Extensive experience conducting independent security assessments of federal systems hosted in Microsoft Azure and AWS environments, including evaluation of security controls, architecture, inherited controls, customer-configured controls, and cloud-specific risks.
  • Demonstrated experience retrieving, navigating, and analyzing FedRAMP authorization packages and associated security artifacts.
  • Strong knowledge of federal Risk Management Framework (RMF) processes and NIST security control assessment practices.
  • Ability to analyze large volumes of technical and governance evidence, connect information across artifacts, identify inconsistencies, and reach clear, supportable conclusions.
  • Strong understanding of IT security requirements, technical countermeasures, vulnerability management, risk management, contingency planning, secure data communications, and system security architecture.
  • Excellent technical writing and stakeholder communication skills, with the ability to explain risk and recommended mitigation in clear, decision-oriented language.
  • Bachelor's degree in cybersecurity, information technology, computer science, or a related field, or eight additional years of relevant specialized experience.
  • Experience using CSAM or a comparable governance, risk, and compliance platform.
  • Certificate of Cloud Security Knowledge (CCSK), Certified Cloud Security Professional (CCSP), Certified Governance, Risk and Compliance (CGRC), or comparable cloud or assessment certification.
  • Experience supporting federal cybersecurity programs and conducting assessments, audits, or control implementation reviews in accordance with NIST Special Publications.
  • Experience assessing cloud service offerings that rely on FedRAMP-authorized services and documenting control inheritance and customer responsibility requirements.
  • DoD 8570/8140 IAM Level II eligibility or an equivalent qualification, when required by the customer environment.
  • Experience evaluating privacy and data protection considerations as part of security assessments.

The successful assessor is technically credible, independent, and evidence-driven. They know when the data supports a finding, when additional validation is needed, and when a requirement must be interpreted in light of architecture, mission use, and actual exposure. They produce assessment results that are clear, consistent, defensible, and actionable.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cloud Security Assessor
Senior Cloud Security Assessor

Method, Inc. • Washington

On-site
USD 140,000 - 190,000
Senior Cloud Security Assessor
Senior Cloud Security Assessor

Method, Inc. • Washington

On-site
USD 150,000 - 190,000
Senior Cloud Security Assessor—FedRAMP & Cloud Risk Expert
Senior Cloud Security Assessor—FedRAMP & Cloud Risk Expert

Sprymethods • Washington

On-site
USD 140,000 - 190,000
Lead Cloud Security Assessor, FedRAMP Expert
Lead Cloud Security Assessor, FedRAMP Expert

Method, Inc. • Washington

On-site
USD 140,000 - 190,000
SCA Lead
SCA Lead

Disruptive Solutions, LLC • Sterling (VA)

Hybrid
USD 150,000 - 190,000
Security Controls Assessor
Security Controls Assessor

ECS Corporate Services • Washington

Hybrid
USD 150,000 - 168,000
Information System Security Officer Sr. (Cloud)
Information System Security Officer Sr. (Cloud)

ECS • Washington

On-site
USD 120,000 - 150,000
Senior Security Engineer
Senior Security Engineer

Hiring Our Heroes • Arlington (VA)

On-site
USD 120,000 - 150,000
Cloud Security Analyst -Hybrid
Cloud Security Analyst -Hybrid

The Dignify Solutions, LLC • Herndon (VA)

On-site
USD 90,000 - 120,000
Senior Security Engineer
Senior Security Engineer

Zermount, Inc. • United States Virgin Islands

On-site
USD 100,000 - 150,000