Location: Jacksonville, FL
Salary: $100,000.00 USD Annually - $125,000.00 USD Annually
Description: Job Title:
Senior Cloud Security / ISO Analyst
Location:
Irving, TX or Jacksonville, FL (Hybrid / Onsite as per project needs)
Summary:
We are seeking a Senior Cloud Security / ISO Analyst with strong hands‑on experience in cloud security architecture, compliance assessments, and enterprise security reviews.
In this role, you will evaluate cloud‑native solutions against enterprise security policies, drive ISRP / ISO certification reviews, and ensure audit‑ready compliance across AWS and GCP environments. You will collaborate closely with architects, threat modelers, IAM teams, control engineers, and business stakeholders to assess residual risk, document evidence, and support security certification gates for large‑scale cloud deployments.
This role is ideal for someone who combines deep cloud technical knowledge with a strong understanding of compliance frameworks and can confidently engage with both technical and non‑technical audiences.
Required / Mandatory Skills:
- 5+ years of experience in information security, with at least 3 years focused on cloud security architecture and compliance
- Strong hands‑on knowledge of AWS and/or GCP cloud services, including:
- Networking (VPC/VNet, subnets, routing, firewalls)
- Compute (EC2, GCE)
- Storage (S3, GCS)
- IAM, KMS / CMEK
- Logging and monitoring services
- Experience reviewing and validating cloud architectures for security policy compliance
- Strong understanding of security controls implementation in IaC and CI/CD pipelines (Terraform, policy‑as‑code preferred)
- In‑depth knowledge of compliance and risk frameworks:
- NIST CSF / NIST 800‑53
- ISO/IEC 27001
- SOC 2
- Enterprise security review processes (ISRP‑style)
- Proven experience producing audit‑ready evidence, compliance reports, and certification documentation
- Excellent communication skills with the ability to explain risk, remediation trade‑offs, and residual risk to diverse stakeholders
Qualification:
- Bachelor’s degree in Information Security, Computer Science, Engineering, or a related field (or equivalent experience)
- Preferred certifications:
- CISSP, CISM, CRISC
- CCSK
- AWS or GCP Security Certifications
- ISO 27001 Lead Auditor / Implementer
Key Responsibilities:
- Conduct ISRP / ISO security reviews for cloud solutions from design through certification
- Validate cloud architectures against enterprise security policies and control requirements
- Assess residual risks across cloud infrastructure, IAM, networking, encryption, and managed services
- Review and validate preventative, detective, and automated remediation controls
- Map risks and controls to NIST, ISO, and regulatory frameworks and produce gap analyses
- Drive remediation plans, risk exceptions, and residual risk decisions with business owners
- Prepare and maintain audit‑ready documentation, including:
- Review reports
- Compliance checklists
- Evidence bundles
- Remediation and exception tracking
- Participate in certification gate reviews and provide formal sign‑off recommendations
- Track and report certification progress, outstanding issues, and escalations
By providing your phone number, you consent to: (1) receive automated text messages and calls from the Judge Group, Inc. and its affiliates (collectively "Judge") to such phone number regarding job opportunities, your job application, and for other related purposes. Message & data rates apply and message frequency may vary. Consistent with Judge's Privacy Policy, information obtained from your consent will not be shared with third parties for marketing/promotional purposes. Reply STOP to opt out of receiving telephone calls and text messages from Judge and HELP for help.
Contact: kswaroop@judge.com
This job and many more are available through The Judge Group. Find us on the web at www.judge.com