Job Requirements
Remote
Public Trust Polygraph not specified
Senior Level Career (10+ yrs experience)
$145,000 - $160,000
Job Description
Title: Cloud Engineer - GRC
Location: Remote
Security Clearance: Public Trust Clearance
Summary
We're modernizing how the organization manages audit, risk, and compliance. Moving from manual evidence collection to a cloud-engineered, continuously monitored program. This senior role owns the transformation end-to-end: the audit and assessment calendar, System Security Plan and control documentation, continuity and privacy deliverables, and compliance reporting, all rebuilt on automated pipelines this role designs and builds directly.
Skills
• Infrastructure depth. Hands-on experience with the organization's full technical environment: cloud (AWS), networking, databases, and midrange software (OS, VDI, Security, and administrative tool stack. Focus is to build in and extract evidence.
• Infrastructure as Code. Able to read, write, and modify IaC (e.g., Terraform, CloudFormation) to understand and validate what the environment is configured to do, and to build compliance checks into that code.
• Automation & scripting. Builds working automation (in any language - Python, Bash, PowerShell) for evidence collection, inventory reporting, and continuous monitoring; this is a hands-on build responsibility across this role's full reporting and audit workload, not an occasional task.
• Security tooling & automation. Able to pull compliance-relevant data and build automated evidence collection from the organizations security tool stack (e.g., SIEM, firewalls, EDR, centralized logging), not limited to cloud-native services.
• Networking fundamentals. Understands network architecture, segmentation, and access boundaries to assess whether a control claim about network security is true in the environment. Including cloud platform's native compliance, logging, and monitoring services (e.g., AWS Config, Security Hub, CloudTrail, Audit Manager) as the primary evidence source, replacing manual collection.
• GRC platform fluency. Administers and configure GRC/compliance automation tooling to consume evidence pulled from the cloud environment.
• NIST 800-53 and control framework depth. Experience with control intent (not just control language) to tailor, inherit, and validate controls against real architecture.
• Written and verbal communication. Translates technical implementation into audit-ready narrative for auditors and translates compliance/control requirements into terms that hold up in architecture and code.
• Program and stakeholder management. Runs the full audit, documentation, and reporting calendar, with organizational discipline.
Job Responsibilities
Audit & Assessment Leadership
• Own the organization's full audit and assessment calendar, ongoing/continuous control assessments, financial and IT-financial audits, internal controls testing, and security compliance audits (e.g., SOC 1 Type II). Serving as the primary point of contact for external auditors and assessors.
• Lead recurring meetings and working sessions with the client, auditors, and assessors across the audit lifecycle: kickoffs, evidence walkthroughs, interviews, findings reviews, and status updates. Represents the organizations control environment directly to external stakeholders.
• Provide audit support across the full assessment portfolio, including penetration testing, red/purple/white team exercises, and periodic CISA high-value-asset assessments, incorporating all findings into the risk register and remediation lifecycle.
• Support new system authorization (ATO) and periodic reauthorization efforts, coordinating required documentation and evidence on a recurring cycle.
Security Documentation & Control Ownership
• Own ongoing maintenance of the System Security Plan (SSP): control implementation updates, system and technical descriptions, and review of inherited/tailored controls against the NIST 800-53 baseline. Validating control descriptions against the actual cloud architecture and configuration, not just the paper record.
• Lead the annual review and executive sign-off cycle for core security documentation and review the organization's control catalog for accuracy against how the environment is built and configured.
Continuity & Resilience Planning
• Own the annual review, update, and test cycle for business continuity and resilience documentation: business impact analysis, contingency plans, disaster recovery plans, and incident response plans. Grounded in the actual failover, backup, and recovery architecture of the cloud environment, not generic templates.
Privacy
• Lead recurring privacy impact/threshold assessments in coordination with the privacy function, including technical review of how architecture handles the data in scope.
Metrics, Reporting & Automation
• Own recurring compliance reporting deliverables: inventory reports, compliance scorecards, SLA and audit-performance metrics, progress reports, and build the automation that generates them directly from the cloud environment (native services, APIs, infrastructure-as-code state) rather than manual collection.
• Design, build, and maintain automated evidence-collection and continuous-monitoring pipelines using native cloud services and scripting/IaC, reducing manual, screenshot-based collection across the full audit and reporting calendar above.
• Identify the highest-value recurring manual processes across audit, documentation, and reporting work, and personally build the automation to address them. This role is expected to build, not just spec and hand off.
Governance & Stakeholder Coordination
• Maintain governance documents that codify the organization's security and audit-support processes.
• Serve as the point of contact for ad hoc security and privacy inquiries and impact-analysis requests from system and business owners.
• Lead recurring coordination meetings with system owners, risk management, and compliance stakeholders to maintain shared visibility into audit status, findings, and remediation.
Education / Experience
• 10+ years of combined experience across cloud engineering and GRC/IT audit/information security compliance, with genuine hands-on depth in both
• Bachelors degree in computer science, cybersecurity, information systems, or a related field preferred; equivalent professional experience accepted in lieu of a degree.
• Demonstrated experience building or maintaining cloud infrastructure and automation (IaC, scripting, cloud-native tooling) in a production environment.
• Demonstrated experience serving as the primary point of contact between technical teams and external auditors or assessors, and owning security documentation (e.g., SSP) and control implementation.
• Experience managing findings and remediation from audits, penetration testing, or red/white team engagements through to closure.
• A portfolio or concrete example of a manual compliance or reporting process the candidate personally automated is a strong plus. Frameworks: NIST 800-53, NIST CSF, A-123, FISMA, and SOC 1/2 Type 2.
• Relevant certifications: AWS Certified Solutions Architect or Security, CISSP, CISA, CRISC, or CGRC.
About Seneca Resources
At Seneca Resources, we are more than just a staffing and consulting firm—we are your trusted career partner. With offices across the U.S. and a diverse range of clients, from Fortune 500 companies to government agencies, we provide meaningful opportunities for professionals to grow and make an impact. When you work with Seneca, you gain a partner that invests in your success, celebrates your achievements, and connects you with organizations leading in their fields. We offer competitive pay, comprehensive benefits including health, dental, vision, 401(k), and dedicated support throughout your career journey.
Seneca Resources is an Equal Opportunity Employer committed to fostering a diverse and inclusive workplace. All qualified individuals are encouraged to apply.
Location: Remote
Security Clearance: Public Trust Clearance
Summary
We're modernizing how the organization manages audit, risk, and compliance. Moving from manual evidence collection to a cloud-engineered, continuously monitored program. This senior role owns the transformation end-to-end: the audit and assessment calendar, System Security Plan and control documentation, continuity and privacy deliverables, and compliance reporting, all rebuilt on automated pipelines this role designs and builds directly.
Skills
• Infrastructure depth. Hands-on experience with the organization's full technical environment: cloud (AWS), networking, databases, and midrange software (OS, VDI, Security, and administrative tool stack. Focus is to build in and extract evidence.
• Infrastructure as Code. Able to read, write, and modify IaC (e.g., Terraform, CloudFormation) to understand and validate what the environment is configured to do, and to build compliance checks into that code.
• Automation & scripting. Builds working automation (in any language - Python, Bash, PowerShell) for evidence collection, inventory reporting, and continuous monitoring; this is a hands-on build responsibility across this role's full reporting and audit workload, not an occasional task.
• Security tooling & automation. Able to pull compliance-relevant data and build automated evidence collection from the organizations security tool stack (e.g., SIEM, firewalls, EDR, centralized logging), not limited to cloud-native services.
• Networking fundamentals. Understands network architecture, segmentation, and access boundaries to assess whether a control claim about network security is true in the environment. Including cloud platform's native compliance, logging, and monitoring services (e.g., AWS Config, Security Hub, CloudTrail, Audit Manager) as the primary evidence source, replacing manual collection.
• GRC platform fluency. Administers and configure GRC/compliance automation tooling to consume evidence pulled from the cloud environment.
• NIST 800-53 and control framework depth. Experience with control intent (not just control language) to tailor, inherit, and validate controls against real architecture.
• Written and verbal communication. Translates technical implementation into audit-ready narrative for auditors and translates compliance/control requirements into terms that hold up in architecture and code.
• Program and stakeholder management. Runs the full audit, documentation, and reporting calendar, with organizational discipline.
Job Responsibilities
Audit & Assessment Leadership
• Own the organization's full audit and assessment calendar, ongoing/continuous control assessments, financial and IT-financial audits, internal controls testing, and security compliance audits (e.g., SOC 1 Type II). Serving as the primary point of contact for external auditors and assessors.
• Lead recurring meetings and working sessions with the client, auditors, and assessors across the audit lifecycle: kickoffs, evidence walkthroughs, interviews, findings reviews, and status updates. Represents the organizations control environment directly to external stakeholders.
• Provide audit support across the full assessment portfolio, including penetration testing, red/purple/white team exercises, and periodic CISA high-value-asset assessments, incorporating all findings into the risk register and remediation lifecycle.
• Support new system authorization (ATO) and periodic reauthorization efforts, coordinating required documentation and evidence on a recurring cycle.
Security Documentation & Control Ownership
• Own ongoing maintenance of the System Security Plan (SSP): control implementation updates, system and technical descriptions, and review of inherited/tailored controls against the NIST 800-53 baseline. Validating control descriptions against the actual cloud architecture and configuration, not just the paper record.
• Lead the annual review and executive sign-off cycle for core security documentation and review the organization's control catalog for accuracy against how the environment is built and configured.
Continuity & Resilience Planning
• Own the annual review, update, and test cycle for business continuity and resilience documentation: business impact analysis, contingency plans, disaster recovery plans, and incident response plans. Grounded in the actual failover, backup, and recovery architecture of the cloud environment, not generic templates.
Privacy
• Lead recurring privacy impact/threshold assessments in coordination with the privacy function, including technical review of how architecture handles the data in scope.
Metrics, Reporting & Automation
• Own recurring compliance reporting deliverables: inventory reports, compliance scorecards, SLA and audit-performance metrics, progress reports, and build the automation that generates them directly from the cloud environment (native services, APIs, infrastructure-as-code state) rather than manual collection.
• Design, build, and maintain automated evidence-collection and continuous-monitoring pipelines using native cloud services and scripting/IaC, reducing manual, screenshot-based collection across the full audit and reporting calendar above.
• Identify the highest-value recurring manual processes across audit, documentation, and reporting work, and personally build the automation to address them. This role is expected to build, not just spec and hand off.
Governance & Stakeholder Coordination
• Maintain governance documents that codify the organization's security and audit-support processes.
• Serve as the point of contact for ad hoc security and privacy inquiries and impact-analysis requests from system and business owners.
• Lead recurring coordination meetings with system owners, risk management, and compliance stakeholders to maintain shared visibility into audit status, findings, and remediation.
Education / Experience
• 10+ years of combined experience across cloud engineering and GRC/IT audit/information security compliance, with genuine hands-on depth in both
• Bachelors degree in computer science, cybersecurity, information systems, or a related field preferred; equivalent professional experience accepted in lieu of a degree.
• Demonstrated experience building or maintaining cloud infrastructure and automation (IaC, scripting, cloud-native tooling) in a production environment.
• Demonstrated experience serving as the primary point of contact between technical teams and external auditors or assessors, and owning security documentation (e.g., SSP) and control implementation.
• Experience managing findings and remediation from audits, penetration testing, or red/white team engagements through to closure.
• A portfolio or concrete example of a manual compliance or reporting process the candidate personally automated is a strong plus. Frameworks: NIST 800-53, NIST CSF, A-123, FISMA, and SOC 1/2 Type 2.
• Relevant certifications: AWS Certified Solutions Architect or Security, CISSP, CISA, CRISC, or CGRC.
About Seneca Resources
At Seneca Resources, we are more than just a staffing and consulting firm—we are your trusted career partner. With offices across the U.S. and a diverse range of clients, from Fortune 500 companies to government agencies, we provide meaningful opportunities for professionals to grow and make an impact. When you work with Seneca, you gain a partner that invests in your success, celebrates your achievements, and connects you with organizations leading in their fields. We offer competitive pay, comprehensive benefits including health, dental, vision, 401(k), and dedicated support throughout your career journey.
Seneca Resources is an Equal Opportunity Employer committed to fostering a diverse and inclusive workplace. All qualified individuals are encouraged to apply.
group id: 10119426