Position Overview
Designs, implements, validates, and documents security controls for cloud, hybrid, data, application, and AI/ML environments.
Key Responsibilities
- Define cloud security architecture for identity, privileged access, network segmentation, encryption, key management, secrets management, logging, vulnerability management, and incident response.
- Implement least-privilege IAM and role-based access control; support identity federation, MFA, conditional access, and privileged-access workflows.
- Configure and integrate cloud security tools, SIEM/SOAR capabilities, security monitoring, vulnerability scanning, CSPM, workload protection, and audit logging.
- Map solution controls to applicable NIST, agency, state, FedRAMP-aligned, HIPAA, FERPA, CJIS, and data-protection requirements.
- Conduct security assessments, architecture reviews, threat modeling, control-gap analyses, and remediation planning.
- Support security authorization artifacts, system security plans, control implementation statements, evidence collection, and continuous monitoring.
Minimum Qualifications
7+ years in cybersecurity, information assurance, security engineering, or security architecture; 3+ years securing cloud or hybrid environments; demonstrated knowledge of NIST 800-53, NIST CSF, IAM, encryption, logging, and vulnerability management. CISSP, CCSP, CISM, CISA, Security+, Azure Security Engineer, AWS Security Specialty, or equivalent preferred.
About This Opportunity
This is a full-time remote position supporting current and upcoming JJT & Associates client work. Specific client requirements, schedules, security requirements, clearances, and other project details may vary by engagement.
JJT & Associates is committed to a professional and inclusive workplace. Employment decisions are based on qualifications, merit, business need, and the requirements of the applicable engagement.