×
Register Here to Apply for Jobs or Post Jobs. X

Cloud Engineer - Governance, Risk, and Compliance; GRC)

Job in Niagara Falls, Niagara County, New York, 14301, USA
Listing for: Peraton
Full Time position
Listed on 2026-10-02
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 170000 - 240000 USD Yearly USD 170000.00 240000.00 YEAR
Job Description & How to Apply Below
Position: Cloud Engineer - Governance, Risk, and Compliance (GRC)

Required Qualifications:

  • Must be a U.S. Citizen with the ability to obtain and maintain the required Public Trust level clearance
  • Bachelors Degree and 12 years of experience, a Masters Degree and 10 years of experience, or a High School diploma or equivalent and 16 years of experience
  • 10+ years of combined experience across cloud engineering and GRC/IT audit/information security compliance, with genuine hands‑on depth in both
  • Demonstrated experience building or maintaining cloud infrastructure and automation (IaC, scripting, cloud-native tooling) in a production environment.
  • Demonstrated experience serving as the primary point of contact between technical teams and external auditors or assessors, and owning security documentation (e.g., SSP) and control implementation.
  • Experience managing findings and remediation from audits, penetration testing, or red/white team engagements through to closure.
  • A portfolio or concrete example of a manual compliance or reporting process the candidate personally automated is a strong plus. Frameworks: NIST 800-53, NIST CSF, A-123, FISMA, and SOC 1/2 Type 2.
  • One or more of the following relevant certifications: AWS Certified Solutions Architect, AWS Certified Security
    - Specialty, CISSP, CISA, CRISC, or CGRC
Preferred Qualifications:
  • Bachelors Degree in Computer Science, Cybersecurity, Information Systems, or a related field

Peraton is seeking a Cloud Engineer specializing in Governance, Risk, and Compliance (GRC) to help modernize how it manages audit, risk, and compliance. This person will help move from manual evidence collection to a cloud-engineered, continuously monitored program. This senior role owns the transformation end-to-end: the audit and assessment calendar, System Security Plan and control documentation, continuity and privacy deliverables, and compliance reporting, all rebuilt on automated pipelines this role designs and builds directly.

Work Location:

Remote Shift

Schedule:

8am - 5pm Eastern Standard Time (EST)

What you will do:

Audit & Assessment Leadership
  • Own the organization's full audit and assessment calendar, ongoing/continuous control assessments, financial and IT-financial audits, internal controls testing, and security compliance audits (e.g., SOC 1 Type II). Serving as the primary point of contact for external auditors and assessors.
  • Lead recurring meetings and working sessions with the client, auditors, and assessors across the audit lifecycle: kickoffs, evidence walkthroughs, interviews, findings reviews, and status updates. Represents the organization’s control environment directly to external stakeholders.
  • Provide audit support across the full assessment portfolio, including penetration testing, red/purple/white team exercises, and periodic CISA high-value-asset assessments, incorporating all findings into the risk register and remediation lifecycle.
  • Support new system authorization (ATO) and periodic reauthorization efforts, coordinating required documentation and evidence on a recurring cycle.
Security Documentation & Control Ownership
  • Own ongoing maintenance of the System Security Plan (SSP): control implementation updates, system and technical descriptions, and review of inherited/tailored controls against the NIST 800-53 baseline. Validating control descriptions against the actual cloud architecture and configuration, not just the paper record.
  • Lead the annual review and executive sign-off cycle for core security documentation and review the organization's control catalog for accuracy against how the environment is built and configured.
Continuity & Resilience Planning
  • Own the annual review, update, and test cycle for business continuity and resilience documentation: business impact analysis, contingency plans, disaster recovery plans,…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary