Cloud Security GRC Consultant
Dark Wolf Solutions · Herndon, VA
$100–140kNew
mid
cloud security
Apply on Dark Wolf Solutions →
Dark Wolf’s Google Cloud Security Governance, Risk, and Compliance (GRC) Consultants are innovative security professionals responsible for applying federal security frameworks (such as the National Institute of Standards and Technology (NIST) Risk Management Framework (RMF) and Federal Risk and Authorization Management Program (FedRAMP)) to modern, complex Google Cloud environments. We are looking for tech-forward consultants who want to move beyond checklist compliance. This role requires a solid understanding of Google Cloud services and the ability to bridge the gap between engineering and security. The ideal candidate will help navigate the Assessment & Authorization (A&A) lifecycle, partnering directly with cloud architects to integrate compliance into system design and translating complex cloud architecture into verifiable evidence to achieve an Authorization to Operate (ATO).
Responsibilities:
Responsibilities:
Work collaboratively within a fast paced Agile team environment
Stay up-to-date on the latest Google Cloud services and technologies
Implement security best practices for Google Cloud solutions
Serve as a key contributor for federal compliance requirements, including FedRAMP, NIST SP 800-53, and agency-specific security overlays
Support development and implementation of innovative methods to achieve compliance with government and commercial cybersecurity frameworks
Conduct detailed technical security control assessments against system components and configurations within the GCP environment, identifying gaps, risks, and recommended mitigations
Actively contribute to the development and finalization of authorization artifacts
Partner with cloud architecture and engineering teams to provide actionable compliance guidance, ensuring security is built-in from system design through deployment
Utilize Google Cloud native tools and features to aid in continuous monitoring (ConMon) activities, vulnerability management, and security posture management
Support reviews with the Authorizing Official (AO), security assessors (e.g., 3PAOs), and federal agency security teams during control assessments and authorization reviews
Develop clear, compelling Plan of Action and Milestones (POA&M) entries, helping the team communicate system risks, impact, and mitigation strategies to stakeholders
Support strategic consulting efforts on evolving federal cloud security policy and best practices
Qualifications:
2+ years of relevant experience
At least one Google Cloud Professional Certification
Experience supporting RMF processes, acting as an ISSO, Security Controls Validator, or performing information assurance engineering
Hands-on with eGRC tools like eMASS and XACTA
Ability to clearly communicate complex security concepts to both technical and non-technical stakeholders
Strong problem-solving skills with a proven ability to quickly learn and apply new technologies to solve complex client challenges
Familiarity with cloud automation, Infrastructure as Code (e.g., Terraform), or scripting to help automate compliance tasks
Understanding of Google Cloud services and technologies
B.A. or B.S. Information Security, Computer Science, or related discipline
US Citizenship and clearable up to a Secret Security Clearance
Preferred Qualifications:
Experience working within Agile teams
Experience working with Google Cloud compliance products such as Security Command Center and Assured Workloads
Hands-on experience with modern compliance automation, OSCAL, Python, or Infrastructure as Code (e.g., Terraform)
Experience working with customers in the U.S. Public Sector
U.S. Federal Government security clearance
Experience with DoD/DISA cybersecurity policies
This position will be a hybrid role based out of Herndon, VA.
The salary range for this position is estimated to be between $100,000.00 - $140,000.00, commensurate on experience and technical skillset.
We are proud to be an EEO/AA employer Minorities/Women/Veterans/Disabled and other protected categories.
In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification form upon hire.
We are strictly looking for direct, full-time W2 employees. We do not engage with third-party staffing agencies, C2C, or 1099 independent contractors for this role.
Posted 2026-10-01