CLOUD SECURITY ENGINEER
LeoRose Consulting
See how well this job matches your profile
Sign up to get an AI match score and generate a tailored application in seconds.
Get your match scoreTags
About the role
Role Overview
Cloud Security Engineer (Cyber Security Engineer / Cloud / ATO Steward) will support system owners in creating and managing ATO (Authority to Operate) packages, ensuring compliance with authorization requirements and mapping artifacts to NIST 800-53 controls.
Responsibilities
- Work with system owners to review, create, and maintain ATO packages and related documentation artifacts.
- Review and create compliance artifacts aligned to VA authorization requirements.
- Map artifacts to NIST 800-53 controls, including Assessment Procedures (AP) testing and evaluation.
- Help to write control implementation statements.
- Support system teams by reviewing, updating, and creating POA&Ms (Plans of Action & Milestones).
- Guide teams through the RMF process and eMASS GRC tool workflows.
- Provide ongoing guidance and support to system teams through each step of the eMASS/RMF lifecycle.
- Analyze authorization documents and artifacts to identify gaps, establish remediation schedules, and coordinate with stakeholders in accordance with SOPs.
- Facilitate meetings and collaborate effectively with teams.
Requirements
- Experience with eMASS.
- Experience supporting ATO processes, including artifact development and security control implementation details.
- Experience with POA&M development and management.
- Knowledge of the Risk Management Framework (RMF).
- Knowledge of NIST 800-53 Rev. 4.
- Ability to analyze authorization documentation, identify gaps, and coordinate remediation activities.
- Ability to work independently and in teams.
- Must work core business hours (8 AM–5 PM EST), Monday–Friday.
- Experience leading/managing cyber teams and with client management/engagement.
Preferred Experience
- Experience with ATO requirements, artifact orchestration, and artifact review.
- POA&M lifecycle management.
- Experience with STIG Viewer.
- Knowledge of federal IT and cloud security policies.
- Familiarity with security scanners: Tenable and/or Nessus.
- Knowledge of IT and cloud concepts: PaaS/SaaS/IaaS, network/server topologies, configurations.
- FedRAMP / AWS GovCloud knowledge.
- Certifications such as CISSP, CISA, CAP, CISM, or CRISC.
Logistics & Eligibility
- Full-time W2, 100% remote, must be based in the U.S.
- U.S. Citizen required.
- Offer contingent upon successful background and clearance adjudication.
Compensation
- $95,000–$105,000/year.
How to Apply
Submit a comprehensive resume tailored to the role to [email protected] with the role title in the subject line. Resume must include start/end dates (month and year) and education details (school, degree, year completed).
About LeoRose Consulting
LeoRose Consulting is a consulting firm providing cybersecurity and compliance support services. The role centers on helping federal system owners prepare and manage authorization documentation and artifacts aligned to VA requirements, RMF, NIST 800-53, and eMASS.
Scraped 7/27/2026