AWS Assessor
Job description
About the role
This role guides security assessment and authorization activities for government cloud initiatives. It leads a team that validates control implementation for federal risk management. The position supports clients in achieving mission efficiency through secure cloud operations.
Every role in this field shares a few habits: clear communication, structured thinking, and steady follow through. Teams hold regular meetings, review progress, and adjust plans. Success usually depends on how well you work with others, not just how hard you try. Successful professionals in any field share a few habits: they take notes, keep commitments, and communicate in writing. Teams value people who make their work easy to review and build on.
Key facts
What you'll do
Cloud security assessments are conducted to identify vulnerabilities and risks within cloud infrastructure for government systems.
The organization's cloud security requirements are analyzed, and recommendations are provided to strengthen protection and compliance.
Security compliance reports are prepared, documenting assessment results and findings for stakeholders and review processes.
A cloud Security Controls Test (SCT) plan is completed and executed to validate security controls in cloud environments.
Findings from cloud assessments are summarized, and detailed findings are provided to support decision-making and risk treatment.
Requirements
A DoED Level 6 High Risk/Public Trust Security Clearance is required for this role.
A Bachelor's degree or equivalent is required, along with at least five (5) years of related experience.
At least five (5) years of experience as a Security Controls Assessor or similar audit findings response role focused on cloud-based security is required.
Experience with cloud security architecture, network security, identity, and access management is required.
Solid knowledge of risk assessment tools, technologies, and methods is required.
Proven experience with Cloud Security Posture Management (CSPM) tools, security as code methodologies, and container security is required.
Excellent communications and interpersonal skills are required to collaborate effectively with federal stakeholders.
Experience with security audits and compliance is required.
An AWS Certified Cloud Practitioner certification or higher is required.
Strong familiarity with government and agency policies is required to ensure system documentation complies with FedRAMP, RMF, FISMA, FIPS-II, NIST, and related frameworks.
Certification in Risk and Information Systems Control (CRISC), Certified Authorization Professional (CAP), or equivalent certification is required.
Nice to have
Top Secret clearance is preferred for this role.
Certifications such as CISSP, CEH, or GPEN are preferred.
Experience with AWS Security Hub is preferred.
Skills & tools
The role involves cloud security assessment and compliance activities. Common frameworks include FedRAMP, RMF, and FISMA. Standard tools include CSPM platforms and security as code practices.
Practical notes
U.S.
SkyePoint Decisions participates in E-Verify.
This role is classified as Equal Opportunity and welcomes Veterans and Disabled applicants.
Typical interview steps
Hiring processes usually combine a screening conversation with one or more interview rounds. Candidates can expect questions about their experience, a scenario or case, and a chance to ask their own questions. Preparation and specific examples from past work carry the most weight. Whatever the role, preparation is visible. Reviewing the company's product, the job description, and your own past work before the conversation is the strongest step.
Good to know
Work in cloud security assessment roles involves federal frameworks such as FedRAMP and NIST standards.
Risk Management Engineering teams commonly use CSPM tools to continuously monitor cloud environments.
Security controls validation requires testing implementation correctness and operational effectiveness.
Government IT projects typically require security clearances and U.S. citizenship for many positions.
Professional certification renewal supports ongoing capability in cloud security and compliance fields.