Cloud SCA-R, Mid
AGE Solutions · Ft. Meade, MD · United States · On-site
Posted Sep 23, 2026
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
About Us
AGE Solutions is a premier technology and professional services company, providing in-depth consulting, advanced technology solutions, and essential services throughout the U.S. government, defense, and intelligence sectors. Prioritizing innovation and client-focused solutions, we assist major agencies in addressing intricate issues and ensuring a more secure future.
AGE Solutions is looking for a Cloud SCA-R, Mid, to join our team in support of a cybersecurity risk management and assessment program with our DoD customer. In this role, you will be part of a team responsible for performing analysis, conducting independent validations of assessments, and Continuous Monitoring (ConMon) for authorized CSPs and CSOs.
Individuals in this role must be available to work full-time on-site at Ft. Meade, MD.
Essential Duties and Responsibilities Include:
Conduct cybersecurity assessments and validations of Cloud Service Offerings (CSOs) in support of the DoD Provisional Authorization (PA) process
Prepare 30 Cloud Security Assessment Packages per year, including validated cybersecurity controls, certifier’s recommendations, and residual risk statements
Review Cloud Service Provider (CSP) documentation packages, including architectural diagrams, System Security Plans (SSP) with Addendums, Readiness Assessment Reports (RAR), Security Assessment Plans (SAP), and Security Assessment Reports (SAR)
Evaluate supporting materials such as POA&Ms, Change Requests, Extension and Deviation Requests, Whitelist Requests, Corrective Action Plans, and applicable templates, checklists, and Continuous Monitoring (ConMon) artifacts
Attend technical kickoff meetings to evaluate and document the CSP’s security posture and readiness for assessment
Analyze and provide feedback on assessment documentation, including the RAR, SAP, SSP, and system architecture diagrams
Identify and document the operational impact of security authorizations, changes, or identified vulnerabilities within the CSP’s environment
Develop complete Cloud Security Assessment Packages in accordance with DoD standards, ensuring inclusion of SARs, POA&Ms, and Deviation Requests
Create authorization recommendation memorandums summarizing compliance with DoD cybersecurity controls, technical evaluation results, and residual risk considerations
Draft DoD PA memorandums outlining CSO boundary definitions, service offerings, authorization duration, terms and conditions, DoD usage considerations, and follow-on actions
Validate implementation of CSO controls within eMASS or a government-provided GRC platform, and log assessment completion in the Mission Security Review (MSR)
Review the Customer Responsibility Matrix (CRM) and ensure correct inheritance mapping within eMASS or the designated GRC tool
Enter all authorization conditions into eMASS as system-level POA&Ms and monitor for timely resolution
Upload and associate all CSP documentation with applicable security…