Cloud Security GRC Consultant

Dark Wolf Solutions

• $100K — $140K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 2+ years of relevant experience in security compliance
  • At least one Google Cloud Professional Certification
  • Experience with RMF processes and roles like ISSO or Security Controls Validator
  • Hands-on experience with eGRC tools such as eMASS and XACTA
  • Ability to communicate complex security concepts clearly to diverse audiences
  • Strong problem-solving skills and adaptability to new technologies
  • Familiarity with cloud automation and Infrastructure as Code (e.g., Terraform)
  • Understanding of Google Cloud services and technologies
  • B.A. or B.S. in Information Security, Computer Science, or related field
  • US Citizenship and eligibility for a Secret Security Clearance

Responsibilities

  • Collaborate within a fast-paced Agile team environment
  • Stay current on Google Cloud services and technologies
  • Implement security best practices for Google Cloud solutions
  • Contribute to federal compliance requirements like FedRAMP and NIST SP 800-53
  • Support innovative compliance methods for government and commercial frameworks
  • Conduct technical security control assessments in GCP environments
  • Develop and finalize authorization artifacts
  • Partner with cloud architecture teams for compliance guidance
  • Utilize Google Cloud tools for continuous monitoring and security posture management
  • Support reviews with federal security teams during assessments
  • Create clear Plan of Action and Milestones (POA&M) entries

Benefits

  • Hybrid work model based in Herndon, VA
  • Opportunity to work with cutting-edge Google Cloud technologies
  • Engagement in strategic consulting on federal cloud security policy
  • Collaboration with a tech-forward team
  • Focus on innovative compliance solutions
  • Direct employment with no third-party staffing agencies involved
Full Job Description
Dark Wolf's Google Cloud Security Governance, Risk, and Compliance (GRC) Consultants are innovative security professionals responsible for applying federal security frameworks (such as the National Institute of Standards and Technology (NIST) Risk Management Framework (RMF) and Federal Risk and Authorization Management Program (FedRAMP)) to modern, complex Google Cloud environments. We are looking for tech-forward consultants who want to move beyond checklist compliance. This role requires a solid understanding of Google Cloud services and the ability to bridge the gap between engineering and security. The ideal candidate will help navigate the Assessment & Authorization (A&A) lifecycle, partnering directly with cloud architects to integrate compliance into system design and translating complex cloud architecture into verifiable evidence to achieve an Authorization to Operate (ATO).

Responsibilities:

Responsibilities:
  • Work collaboratively within a fast paced Agile team environment
  • Stay up-to-date on the latest Google Cloud services and technologies
  • Implement security best practices for Google Cloud solutions
  • Serve as a key contributor for federal compliance requirements, including FedRAMP, NIST SP 800-53, and agency-specific security overlays
  • Support development and implementation of innovative methods to achieve compliance with government and commercial cybersecurity frameworks
  • Conduct detailed technical security control assessments against system components and configurations within the GCP environment, identifying gaps, risks, and recommended mitigations
  • Actively contribute to the development and finalization of authorization artifacts
  • Partner with cloud architecture and engineering teams to provide actionable compliance guidance, ensuring security is built-in from system design through deployment
  • Utilize Google Cloud native tools and features to aid in continuous monitoring (ConMon) activities, vulnerability management, and security posture management
  • Support reviews with the Authorizing Official (AO), security assessors (e.g., 3PAOs), and federal agency security teams during control assessments and authorization reviews
  • Develop clear, compelling Plan of Action and Milestones (POA&M) entries, helping the team communicate system risks, impact, and mitigation strategies to stakeholders
  • Support strategic consulting efforts on evolving federal cloud security policy and best practices

Qualifications:
  • 2+ years of relevant experience
  • At least one Google Cloud Professional Certification
  • Experience supporting RMF processes, acting as an ISSO, Security Controls Validator, or performing information assurance engineering
  • Hands-on with eGRC tools like eMASS and XACTA
  • Ability to clearly communicate complex security concepts to both technical and non-technical stakeholders
  • Strong problem-solving skills with a proven ability to quickly learn and apply new technologies to solve complex client challenges
  • Familiarity with cloud automation, Infrastructure as Code (e.g., Terraform), or scripting to help automate compliance tasks
  • Understanding of Google Cloud services and technologies
  • B.A. or B.S. Information Security, Computer Science, or related discipline
  • US Citizenship and clearable up to a Secret Security Clearance

Preferred Qualifications:
  • Experience working within Agile teams
  • Experience working with Google Cloud compliance products such as Security Command Center and Assured Workloads
  • Hands-on experience with modern compliance automation, OSCAL, Python, or Infrastructure as Code (e.g., Terraform)
  • Experience working with customers in the U.S. Public Sector
  • U.S. Federal Government security clearance
  • Experience with DoD/DISA cybersecurity policies


This position will be a hybrid role based out of Herndon, VA.

The salary range for this position is estimated to be between $100,000.00 - $140,000.00, commensurate on experience and technical skillset.

We are strictly looking for direct, full-time W2 employees. We do not engage with third-party staffing agencies, C2C, or 1099 independent contractors for this role.

Similar Jobs

More Jobs at Dark Wolf Solutions

More Information Technology Jobs

Find similar Cloud Security GRC Consultant jobs: