{"schemaVersion":"jobsearcher.job.v1","id":"5e91b0d4786b419d80ae2b46","url":"https://jobsearcher.com/jobs/5e91b0d4786b419d80ae2b46","canonicalUrl":"https://jobsearcher.com/jobs/5e91b0d4786b419d80ae2b46","title":"Cloud Security Compliance Engineer","description":"LightFeather is seeking a Cloud Security Compliance Engineer with deep expertise in Risk Management Framework execution, ATO packages, POA&M management, and ISSO-level compliance operations across cloud environments. This role is ideal for someone who understands how to translate cloud architecture into compliant, assessable systems—and can drive security authorization efforts end-to-end with engineering teams, ISSMs, program leadership, and auditors.\nLocation: In-Person (5 days/week) – Washington, DC 20036\nJob Type: Full-time\nCitizenship Requirement: U.S. Citizenship Required\nClearance Requirement: Active Secret or Top Secret Security Clearance\nKey Responsibilities\nLead and support RMF authorization efforts for cloud-hosted systems, including ATO package development and maintenance.\nServe as an ISSO-level compliance owner, coordinating security documentation, evidence collection, continuous monitoring, and control validation.\nDevelop and maintain RMF artifacts such as:\nSystem Security Plans (SSP)\nSecurity Assessment Reports (SAR)\nPOA&Ms\nContinuous Monitoring Plans\nControl Implementation Statements\nOwn and manage POA&M lifecycle, including risk scoring, remediation coordination, milestone tracking, and executive reporting.\nMap and validate security controls against required frameworks such as NIST 800-53, FedRAMP, DoD SRG, and agency-specific overlays.\nCoordinate with auditors/assessors (3PAO, internal assessment teams, government stakeholders) to support assessments, interviews, and evidence readiness.\nPartner with cloud/platform engineers to ensure security controls are implemented in a way that is:\ntechnically accurate\ntestable\ndocumented for assessment\nDrive continuous monitoring processes: vulnerability management reporting, control health tracking, logging/monitoring requirements, and configuration drift awareness.\nSupport policy and governance enforcement related to secure cloud operations, including baseline standards (CIS benchmarks, STIGs where applicable).\nEnsure cloud systems maintain compliance readiness for regulated environments such as GovCloud and DoD IL5/IL6.\nContribute to security tooling and automation efforts where helpful (compliance reporting, evidence generation, guardrail validation), without requiring full-time engineering ownership.\nRequired Qualifications\nBachelor's degree in computer science, cybersecurity, information systems, or a related technical field (or equivalent experience).\n5+ years of experience in cybersecurity compliance, RMF, or security authorization roles.\nDemonstrated experience producing and maintaining RMF artifacts (SSP, SAR, POA&M, etc.) for cloud-hosted or hybrid systems.\nStrong working knowledge of NIST RMF and security control frameworks, including NIST 800-53 and/or FedRAMP.\nHands-on experience supporting ATO efforts for one or more cloud environments (AWS, Azure, GCP).\nAbility to translate cloud architecture into compliant control implementations (IAM, encryption, logging, networking segmentation, monitoring, patching, vulnerability response).\nExperience coordinating stakeholders across engineering, compliance, leadership, and external assessors.\nStrong written and verbal communication skills—especially for compliance documentation and assessment readiness.\nPreferred Qualifications\nExperience supporting DoD environments, including DoD SRG, IL5/IL6, and/or mission systems with strict boundary controls.\nFamiliarity with common GRC / compliance tooling such as eMASS, Xacta, ServiceNow GRC, Jira, or similar systems.\nISSO / ISSM experience operating inside government compliance processes and reporting structures.\nKnowledge of CIS benchmarks, STIGs, vulnerability management standards, and secure configuration baselines.\nExperience working with cloud security services such as:\nAWS Security Hub / GuardDuty\nMicrosoft Defender for Cloud\nGoogle Security Command Center\nCertifications such as:\nCISSP\nCISM\nCAP\nSecurity+\nAWS/Azure/GCP security certifications\nBackground supporting continuous monitoring programs and automated evidence collection (even at a light-touch level).\nWhy Join LightFeather?\nAt LightFeather, you're not just taking a job—you're joining a purpose-driven team that delivers innovative, mission-critical solutions to make a real difference. You'll work on diverse, meaningful projects that challenge and inspire you, alongside some of the best minds in the industry.","company":"Lightfeather Io","rawCompany":"lightfeather io","city":"Washington","state":"DC","isRemote":false,"isActive":false,"createdAt":"2026-04-14T10:51:33.557Z","occupations":[{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541690","title":"Other Scientific and Technical Consulting Services","slug":"other-scientific-and-technical-consulting-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Cloud Security Compliance Engineer","description":"LightFeather is seeking a Cloud Security Compliance Engineer with deep expertise in Risk Management Framework execution, ATO packages, POA&M management, and ISSO-level compliance operations across cloud environments. This role is ideal for someone who understands how to translate cloud architecture into compliant, assessable systems—and can drive security authorization efforts end-to-end with engineering teams, ISSMs, program leadership, and auditors.\nLocation: In-Person (5 days/week) – Washington, DC 20036\nJob Type: Full-time\nCitizenship Requirement: U.S. Citizenship Required\nClearance Requirement: Active Secret or Top Secret Security Clearance\nKey Responsibilities\nLead and support RMF authorization efforts for cloud-hosted systems, including ATO package development and maintenance.\nServe as an ISSO-level compliance owner, coordinating security documentation, evidence collection, continuous monitoring, and control validation.\nDevelop and maintain RMF artifacts such as:\nSystem Security Plans (SSP)\nSecurity Assessment Reports (SAR)\nPOA&Ms\nContinuous Monitoring Plans\nControl Implementation Statements\nOwn and manage POA&M lifecycle, including risk scoring, remediation coordination, milestone tracking, and executive reporting.\nMap and validate security controls against required frameworks such as NIST 800-53, FedRAMP, DoD SRG, and agency-specific overlays.\nCoordinate with auditors/assessors (3PAO, internal assessment teams, government stakeholders) to support assessments, interviews, and evidence readiness.\nPartner with cloud/platform engineers to ensure security controls are implemented in a way that is:\ntechnically accurate\ntestable\ndocumented for assessment\nDrive continuous monitoring processes: vulnerability management reporting, control health tracking, logging/monitoring requirements, and configuration drift awareness.\nSupport policy and governance enforcement related to secure cloud operations, including baseline standards (CIS benchmarks, STIGs where applicable).\nEnsure cloud systems maintain compliance readiness for regulated environments such as GovCloud and DoD IL5/IL6.\nContribute to security tooling and automation efforts where helpful (compliance reporting, evidence generation, guardrail validation), without requiring full-time engineering ownership.\nRequired Qualifications\nBachelor's degree in computer science, cybersecurity, information systems, or a related technical field (or equivalent experience).\n5+ years of experience in cybersecurity compliance, RMF, or security authorization roles.\nDemonstrated experience producing and maintaining RMF artifacts (SSP, SAR, POA&M, etc.) for cloud-hosted or hybrid systems.\nStrong working knowledge of NIST RMF and security control frameworks, including NIST 800-53 and/or FedRAMP.\nHands-on experience supporting ATO efforts for one or more cloud environments (AWS, Azure, GCP).\nAbility to translate cloud architecture into compliant control implementations (IAM, encryption, logging, networking segmentation, monitoring, patching, vulnerability response).\nExperience coordinating stakeholders across engineering, compliance, leadership, and external assessors.\nStrong written and verbal communication skills—especially for compliance documentation and assessment readiness.\nPreferred Qualifications\nExperience supporting DoD environments, including DoD SRG, IL5/IL6, and/or mission systems with strict boundary controls.\nFamiliarity with common GRC / compliance tooling such as eMASS, Xacta, ServiceNow GRC, Jira, or similar systems.\nISSO / ISSM experience operating inside government compliance processes and reporting structures.\nKnowledge of CIS benchmarks, STIGs, vulnerability management standards, and secure configuration baselines.\nExperience working with cloud security services such as:\nAWS Security Hub / GuardDuty\nMicrosoft Defender for Cloud\nGoogle Security Command Center\nCertifications such as:\nCISSP\nCISM\nCAP\nSecurity+\nAWS/Azure/GCP security certifications\nBackground supporting continuous monitoring programs and automated evidence collection (even at a light-touch level).\nWhy Join LightFeather?\nAt LightFeather, you're not just taking a job—you're joining a purpose-driven team that delivers innovative, mission-critical solutions to make a real difference. You'll work on diverse, meaningful projects that challenge and inspire you, alongside some of the best minds in the industry.","datePosted":"2026-04-14T10:51:33.557Z","dateModified":"2026-04-14T10:51:33.557Z","hiringOrganization":{"@type":"Organization","name":"Lightfeather Io","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Washington","addressRegion":"DC","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"5e91b0d4786b419d80ae2b46"},"url":"https://jobsearcher.com/jobs/5e91b0d4786b419d80ae2b46"}}