Job Description

Experienced assessor sought to lead rigorous, evidence-based security assessments of cloud and hybrid systems supporting federal missions.

Who we are looking for:

Spry Methods is seeking an experienced Senior Cloud Security Assessor to join our team in the Washington, DC area. The successful candidate will bring extensive hands-on experience conducting independent security control assessments of cloud and hybrid systems, with particular depth in federal cloud environments. This role requires sound professional judgment, strong analytical skills, and a practical, common-sense approach to applying security requirements to system data, technical evidence, mission context, and actual risk.

Key Responsibilities:

•  Lead full-cycle Security Assessment and Authorization (SA&A) activities for cloud, hybrid, and enterprise systems as an independent assessor.

•  Assess Microsoft Azure and Amazon Web Services (AWS) environments, including the implementation and operating effectiveness of administrative, operational, and technical security controls.

•  Retrieve and review FedRAMP authorization packages and supporting documentation, then analyze the package for applicability, control inheritance, residual risk, gaps, and customer responsibilities.

•  Conduct detailed analysis of assessment artifacts, including system security plans, policies, procedures, architecture and data-flow diagrams, inventories, configurations, logs, scan results, test outputs, and other supporting evidence.

•  Develop Security Assessment Plans (SAPs), Security Assessment Reports (SARs), Risk Assessment Reports (RARs), Required Evidence Lists, and Plans of Action and Milestones (POA&Ms).

•  Perform network, system, application, and NIST security control testing from administrative, operational, and technical perspectives.

•  Analyze vulnerability scan results, interpret risk, and use manual validation and corroborating evidence to distinguish actionable findings from false positives or unsupported conclusions.

•  Apply security requirements using practical judgment and data context rather than relying solely on checklist compliance. Evaluate whether evidence is relevant, reliable, sufficient, and representative of the assessed environment.

•  Clearly communicate findings, risk, root cause, and feasible mitigation options to technical teams, system owners, executives, and other assessment stakeholders.

•  Coordinate evidence requests, interviews, test activities, and assessment schedules with customer personnel and Information Systems Security Analysts.

•  Support security assessment program operations and contribute to consistent assessment methods, quality reviews, and defensible reporting.

Minimum Qualifications

•  Active Certified Information Systems Security Professional (CISSP) certification is required.

•  At least eight years of demonstrated, hands-on experience conducting security control assessments, including substantial experience serving as an independent assessor for cloud and hybrid systems.

•  Extensive experience conducting independent security assessments of federal systems hosted in Microsoft Azure and AWS environments, including evaluation of security controls, architecture, inherited controls, customer-configured controls, and cloud-specific risks.

•  Demonstrated experience retrieving, navigating, and analyzing FedRAMP authorization packages and associated security artifacts.

•  Strong knowledge of federal Risk Management Framework (RMF) processes and NIST security control assessment practices.

•  Ability to analyze large volumes of technical and governance evidence, connect information across artifacts, identify inconsistencies, and reach clear, supportable conclusions.

•  Strong understanding of IT security requirements, technical countermeasures, vulnerability management, risk management, contingency planning, secure data communications, and system security architecture.

•  Excellent technical writing and stakeholder communication skills, with the ability to explain risk and recommended mitigation in clear, decision-oriented language.

•  Bachelor’s degree in cybersecurity, information technology, computer science, or a related field, or eight additional years of relevant specialized experience.

•  Experience using CSAM or a comparable governance, risk, and compliance platform.

Preferred Qualifications

•  Certificate of Cloud Security Knowledge (CCSK), Certified Cloud Security Professional (CCSP), Certified Governance, Risk and Compliance (CGRC), or comparable cloud or assessment certification.

•  Experience supporting federal cybersecurity programs and conducting assessments, audits, or control implementation reviews in accordance with NIST Special Publications.

•  Experience assessing cloud service offerings that rely on FedRAMP-authorized services and documenting control inheritance and customer responsibility requirements.

•  DoD 85708140 IAM Level II eligibility or an equivalent qualification, when required by the customer environment.

•  Experience evaluating privacy and data protection considerations as part of security assessments.

Success in this role:

The successful assessor is technically credible, independent, and evidence-driven. They know when the data supports a finding, when additional validation is needed, and when a requirement must be interpreted in light of architecture, mission use, and actual exposure. They produce assessment results that are clear, consistent, defensible, and actionable.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Share this job:
Please let Spry Methods, Inc. know you found this job on Remote First Jobs 🙏

Explore more remote jobs

14 similar remote jobs

Explore latest remote opportunities and join a team that values work flexibility.

Remote companies like Spry Methods, Inc.

Find your next opportunity with companies that specialize in Government Financial Accounting, Enterprise Resource Planning, Cyber Security, and Information Technology. Explore remote-first companies like Spry Methods, Inc. that prioritize flexible work and home-office freedom.

IT Concepts, Inc Logo

IT Concepts, Inc

501-1000 www.kentro.us

Provides digital solutions, IT modernization, and specialized services to federal agencies.

View company profile →
OCT Consulting LLC Logo

OCT Consulting LLC

Provides professional services and IT solutions to Federal government and commercial clients.

View company profile →
Objectstream, Inc. Logo

Objectstream, Inc.

Provides Information Technology and Aviation Management services to federal and commercial customers.

View company profile →
Danforth Health Logo

Danforth Health

Provides cross-functional support and expertise for life science companies across finance, regulatory, and commercial functions.

View company profile →
phia, LLC Logo

phia, LLC

Cybersecurity, intelligence, and technology support for Federal government and commercial clients.

View company profile →
Paragon Cyber Solutions (8a, EDWOSB, SDVOSB, CMMC-C3PAO) | GSA MAS (IT & HACS) | Seaport NxGen | Logo

Paragon Cyber Solutions (8a, EDWOSB, SDVOSB, CMMC-C3PAO) | GSA MAS (IT & HACS) | Seaport NxGen |

Offers cybersecurity, information technology, and workforce development services for government and commercial sectors.

View company profile →

Project: Career Search

Rev. 2026.9

[ Remote Jobs ]
Direct Access

We source jobs directly from 21,000+ company career pages. No intermediaries.

01

Discover Hidden Jobs

Unique jobs you won't find on other job boards.

02

Advanced Filters

Filter by category, benefits, seniority, and more.

03

Priority Job Alerts

Get timely alerts for new job openings every day.

04

Manage Your Job Hunt

Save jobs you like and keep a simple list of your applications.

21,000+ SOURCES UPDATED 24/7
Apply