Cloud Engineer - Governance, Risk, and Compliance; GRC)
Job in
Newport News, Virginia, 23601, USA
Listed on 2026-10-02
Listing for:
Peraton
Full Time
position Listed on 2026-10-02
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Job Description & How to Apply Below
Cloud Engineer
- Governance, Risk, and Compliance (GRC) Job Location s
US
ResponsibilitiesPeraton is seeking a Cloud Engineer specializing in Governance, Risk, and Compliance (GRC) to help modernize how it manages audit, risk, and compliance. This person will help move from manual evidence collection to a cloud-engineered, continuously monitored program. This senior role owns the transformation end-to-end: the audit and assessment calendar, System Security Plan and control documentation, continuity and privacy deliverables, and compliance reporting, all rebuilt on automated pipelines this role designs and builds directly.
Work Location: Remote
Shift
Schedule:
8am - 5pm Eastern Standard Time (EST)
What you will do:
Audit & Assessment Leadership- Own the organization's full audit and assessment calendar, ongoing/continuous control assessments, financial and IT-financial audits, internal controls testing, and security compliance audits (e.g., SOC 1 Type II). Serving as the primary point of contact for external auditors and assessors.
- Lead recurring meetings and working sessions with the client, auditors, and assessors across the audit lifecycle: kickoffs, evidence walkthroughs, interviews, findings reviews, and status updates. Represents the organization's control environment directly to external stakeholders.
- Provide audit support across the full assessment portfolio, including penetration testing, red/purple/white team exercises, and periodic CISA high-value-asset assessments, incorporating all findings into the risk register and remediation lifecycle.
- Support new system authorization (ATO) and periodic reauthorization efforts, coordinating required documentation and evidence on a recurring cycle.
- Own ongoing maintenance of the System Security Plan (SSP): control implementation updates, system and technical descriptions, and review of inherited/tailored controls against the NIST 800-53 baseline. Validating control descriptions against the actual cloud architecture and configuration, not just the paper record.
- Lead the annual review and executive sign-off cycle for core security documentation and review the organization's control catalog for accuracy against how the environment is built and configured.
- Own the annual review, update, and test cycle for business continuity and resilience documentation: business impact analysis, contingency plans, disaster recovery plans, and incident response plans. Grounded in the actual failover, backup, and recovery architecture of the cloud environment, not generic templates.
- Lead recurring privacy impact/threshold assessments in coordination with the privacy function, including technical review of how architecture handles the data in scope.
- Own recurring compliance reporting deliverables: inventory reports, compliance scorecards, SLA and audit-performance metrics, progress reports, and build the automation that generates them directly from the cloud environment (native services, APIs, infrastructure-as-code state) rather than manual collection.
- Design, build, and maintain automated evidence-collection and continuous-monitoring pipelines using native cloud services and scripting/IaC, reducing manual, screenshot-based collection across the full audit and reporting calendar above.
- Identify the highest-value recurring manual processes across audit, documentation, and reporting work, and personally build the automation to address them. This role is expected to build, not just spec and hand off.
- Maintain governance documents that codify the organization's security and audit-support processes.
- Serve as the point of contact for ad hoc security and privacy inquiries and impact-analysis requests from system and business owners.
- Lead recurring coordination meetings with system owners, risk management, and compliance stakeholders to maintain shared visibility into audit status, findings, and remediation.
- Infrastructure depth. Hands-on experience with the organization's full technical environment: cloud (AWS), networking, databases, and midrange software (OS, VDI, Security, and administrative tool stack. Focus is to build in and extract evidence.
- Infrastructure as Code. Able to read, write, and modify IaC (e.g., Terraform, Cloud Formation) to validate infrastructure configurations, and to build policy as code compliance checks into the pipeline.
- Automation &…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×