About Us
AGE Solutions is a premier technology and professional services company, providing in-depth consulting, advanced technology solutions, and essential services throughout the U.S. government, defense, and intelligence sectors. Prioritizing innovation and client-focused solutions, we assist major agencies in addressing intricate issues and ensuring a more secure future. AGE Solutions is looking for a Cyber Cloud Assessment Engineer to join our team in support of a cybersecurity risk management and assessment program with our DoD customer. In this role, you will be part of a team responsible for performing analysis, conducting independent validations of assessments, and Continuous Monitoring (ConMon) for authorized CSPs and CSOs. Individuals in this role must be available to work full-time on-site at Ft. Meade, MD. Essential Duties and Responsibilities
- Conduct cybersecurity assessments and validations of Cloud Service Offerings (CSOs) in support of the DoD Provisional Authorization (PA) process
- Prepare 30 Cloud Security Assessment Packages per year, including validated cybersecurity controls, certifier's recommendations, and residual risk statements
- Review Cloud Service Provider (CSP) documentation packages, including architectural diagrams, System Security Plans (SSP) with Addendums, Readiness Assessment Reports (RAR), Security Assessment Plans (SAP), and Security Assessment Reports (SAR)
- Evaluate supporting materials such as POA&Ms, Change Requests, Extension and Deviation Requests, Whitelist Requests, Corrective Action Plans, and applicable templates, checklists, and Continuous Monitoring (ConMon) artifacts
- Attend technical kickoff meetings to evaluate and document the CSP's security posture and readiness for assessment
- Analyze and provide feedback on assessment documentation, including the RAR, SAP, SSP, and system architecture diagrams
- Identify and document the operational impact of security authorizations, changes, or identified vulnerabilities within the CSP's environment
- Develop complete Cloud Security Assessment Packages in accordance with DoD standards, ensuring inclusion of SARs, POA&Ms, and Deviation Requests
- Create authorization recommendation memorandums summarizing compliance with DoD cybersecurity controls, technical evaluation results, and residual risk considerations
- Draft DoD PA memorandums outlining CSO boundary definitions, service offerings, authorization duration, terms and conditions, DoD usage considerations, and follow-on actions
- Validate implementation of CSO controls within eMASS or a government-provided GRC platform, and log assessment completion in the Mission Security Review (MSR)
- Review the Customer Responsibility Matrix (CRM) and ensure correct inheritance mapping within eMASS or the designated GRC tool
- Enter all authorization conditions into eMASS as system-level POA&Ms and monitor for timely resolution
- Upload and associate all CSP documentation with applicable security controls in eMASS or the appropriate system of record
- Track and manage all CSO-related data using the Team Lead Resource (TLR) Assessment Database
- Maintain and update the DoD Cloud Process Guide and associated templates, forms, checklists, and documentation
- Contribute to the development of internal instructions, how-to guides, and reference material to support consistent assessor workflows
- Ensure assessment activities are conducted in compliance with DoDI 8510.01 and the DoD Cloud Computing Security Requirements Guide (SRG)
- Document assessment methodologies and validation best practices to continuously improve assessment accuracy, consistency, and process efficiency
- Support the ongoing development and annual updates of the DoD Cloud Assessment Process Guides in alignment with evolving policy and government directives
Requirements:
- Bachelor's degree (IT-related field preferred)
- Five (5) years of overall experience in cybersecurity or network security position
- Have an active DoD Top Secret clearance with SCI eligibility
- DoD 8570 IAM/IA Technical (IAT) Level II certification
- Working knowledge of DoD Risk Management Framework (RMF) and DoDI 8510.01
- Familiarity with the DoD Cloud Computing Security Requirements Guide (SRG) and associated cloud security policies
- Familiarity with security controls for Azure, AWS, and assorted cloud platforms
- Experience conducting security assessments and developing security documentation (e.g., SSP, SAR, POA&M, SAP)
- Proficiency with eMASS or equivalent Government Risk and Compliance (GRC) tools
- Demonstrated ability to interpret and apply NIST SP 800-53 security controls in cloud environments
- Strong analytical and technical writing skills with the ability to communicate complex topics clearly
- Applicants must reside within a commutable distance of Ft. Meade, MD in order to work onsite full-time.
Work Environment:
- Must be able to sit for long periods
Compensation: $85,000+
At AGE Solutions, we reward performance, invest in growth, and share success. Our benefits support the whole person, professionally, financially, and personally.
- 26 Days Paid Leave: Includes vacation, sick, personal time, and holidays. You choose how to use it.
- Performance Bonuses: Performance bonuses are awarded based on individual contributions and company-wide results, aligning recognition with impact.
- 401(k) with Match: We match 3% of your contributions with immediate vesting.
- Financial Protection: Company-paid life insurance up to $300K and options for additional coverage for you and your dependents.
- Health Benefits: Multiple medical plans, dental, vision, FSA and HSA options to fit your needs.
- Parental Leave: 15 days of fully paid leave for new parents, because family matters.
- Military Differential Pay: We bridge the gap for employees on active duty, so they don't take a financial hit while serving.
- Professional Growth: Paid training and certifications, tuition reimbursement, and the tools and tech to get the job done right.
- Shared Success: In the event of a company sale, our CEO has committed to returning 80% of net proceeds to employees. This ensures our team shares in the long term value they help create.
At AGE, you'll do work that matters, supported by a company that delivers for its people.
|