FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Cloud Engineer – Governance, Risk, and Compliance (GRC)
Peraton. Own the full audit and assessment calendar, including continuous control assessments, financial and IT-financial audits, internal controls testing, and security compliance audits .
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in audit management, compliance reporting, and security documentation, with a strong focus on cloud engineering and GRC/IT audit practices. Proficient in automation and continuous monitoring, ensuring effective risk management and remediation processes.
Highest-signal resume keywords
GRC/IT Audit ExperienceCloud Engineering ExpertiseAWS Certified Solutions ArchitectInfrastructure as CodeNIST 800-53 Compliance
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Audit Lifecycle ManagementCloud Infrastructure AutomationSecurity Documentation ManagementPenetration Testing SupportTerraformPython ScriptingAWS ConfigSIEM ToolsControl FrameworksCompliance Reporting
Soft Skills
Strong Written CommunicationStakeholder ManagementProgram Management
Tools & Technologies
AWSCloudFormationEDRFirewallsPrisma CloudWizCentralized LoggingAudit Manager
Certifications & Qualifications
AWS Certified Security - SpecialtyCISSPCISACRISCCGRC
Industry Keywords
NIST CSFFISMASOC 1/2 Type 2Continuous Control AssessmentsSystem Security Plan
Tech Stack
Tools & technologiesAWSCloudFirewallsPythonTerraform
About the role
Key responsibilities & impact- Own the full audit and assessment calendar, including continuous control assessments, financial and IT-financial audits, internal controls testing, and security compliance audits
- Serve as the primary point of contact for external auditors and assessors
- Lead audit lifecycle meetings and working sessions with clients, auditors, assessors, and stakeholders
- Support penetration testing, red/purple/white team exercises, and CISA high-value-asset assessments
- Coordinate new system authorization (ATO) and periodic reauthorization efforts
- Maintain the System Security Plan, control implementation updates, system and technical descriptions, and inherited/tailored control reviews
- Lead annual review and executive sign-off cycles for security documentation and control catalog accuracy
- Own annual business continuity and resilience documentation review, updates, and testing
- Lead privacy impact and threshold assessments with the privacy function
- Produce compliance reporting, inventory reports, scorecards, SLA and audit-performance metrics, and progress reports
- Design, build, and maintain automated evidence-collection and continuous-monitoring pipelines
- Automate recurring audit, documentation, and reporting processes using cloud services, APIs, scripting, and IaC
- Maintain governance documents for security and audit-support processes
- Handle ad hoc security and privacy inquiries and impact-analysis requests
- Lead coordination with system owners, risk management, and compliance stakeholders on audit status, findings, and remediation
Requirements
What you’ll need- Must be a U.S. Citizen
- Ability to obtain and maintain the required Public Trust level clearance
- Bachelor's Degree and 12 years of experience, Master's Degree and 10 years of experience, or High School diploma or equivalent and 16 years of experience
- 10+ years of combined experience across cloud engineering and GRC/IT audit/information security compliance, with hands-on depth in both
- Experience building or maintaining cloud infrastructure and automation in a production environment
- Experience with Infrastructure as Code, scripting, and cloud-native tooling
- Experience serving as the primary point of contact between technical teams and external auditors or assessors
- Experience owning security documentation, such as an SSP, and control implementation
- Experience managing findings and remediation from audits, penetration testing, or red/white team engagements through closure
- Relevant certification: AWS Certified Solutions Architect, AWS Certified Security - Specialty, CISSP, CISA, CRISC, or CGRC
- Hands-on experience with AWS, networking, databases, midrange software, OS, VDI, security, and administrative tool stacks
- Ability to read, write, and modify Terraform or CloudFormation
- Ability to build policy-as-code compliance checks
- Ability to build automation using Python, Bash, or PowerShell
- Experience with SIEM, firewalls, EDR, centralized logging, Wiz, or Prisma Cloud
- Understanding of network architecture, segmentation, and access boundaries
- Experience with AWS Config, Security Hub, CloudTrail, and Audit Manager
- GRC/compliance automation tooling administration and configuration
- Experience with NIST 800-53 and control frameworks including NIST CSF, A-123, FISMA, and SOC 1/2 Type 2
- Strong written and verbal communication
- Program and stakeholder management experience
Benefits
Comp & perks- Potential eligibility for overtime
- Potential eligibility for shift differential
- Potential eligibility for a discretionary bonus