Information Assurance Cyber Cloud Admin

About Concept Plus

Concept Plus is a mission-focused technology solutions provider that transforms IT concepts into impactful solutions for federal agencies. Headquartered in Fairfax, VA, we bring the agility, responsiveness, and customer intimacy of a small business combined with the quality and infrastructure of a larger firm.


Recognized as an award-winning Oracle partner, we have delivered innovative solutions across Defense, Intelligence, Civilian, Health IT, and Tribal sectors. Our highly certified experts build systems that drive efficiency, accelerate modernization, and ensure mission outcomes with certainty.


We offer competitive pay, comprehensive health, dental, and vision insurance, paid life insurance, paid time off, 11 paid holidays, performance bonuses, tuition reimbursement, unlimited training, and the opportunity to thrive in a collaborative, flexible, and innovative environment.


For more information, visit www.conceptplus.com.


About the role

Concept Plus is seeking an IA Cyber Cloud Administrator to support Federal IT systems development and operations. This role requires knowledge and understanding of Federal IT processes and technology stack, including DevSecOps CI/CD pipelines, Oracle-based systems, and Java application stacks. Federal systems are deployed in both classified and unclassified cloud environments, requiring strict adherence to federal cybersecurity, configuration, and compliance standards.

The IA Cyber Cloud Administrator provides critical security, cloud administration, and compliance support to modernize and enhance client systems by ensuring environments are secure, resilient, and continuously monitored. This role serves as a key interface with the customer and the Program Management Office (PMO), ensuring that security controls, system configurations, and operational practices align with program requirements, RMF standards, and mission needs.

The IA Cyber Cloud Administrator works across capability delivery teams—including development Scrums, Cloud Engineering, and DevSecOps platform resources—to integrate security into system design, CI/CD pipelines, and cloud environments. The role supports the implementation and maintenance of security controls, vulnerability management processes, identity and access management, and continuous monitoring, ensuring systems remain compliant and operational within federal environments.


What you'll do

  • Administer and secure cloud environments, including AWS, and hybrid infrastructures supporting client projects
  • Implement and maintain security controls across CI/CD pipelines, ensuring secure code integration, build, and deployment processes
  • Support RMF (Risk Management Framework) activities, including control implementation, assessment support, and ATO sustainment
  • Configure and maintain STIG-compliant systems, ensuring alignment with federal hardening and configuration standards
  • Integrate and manage automated security tools within DevSecOps pipelines (SAST, DAST, container scanning, dependency scanning)
  • Monitor system security posture using continuous monitoring tools, log aggregation, and alerting platforms
  • Conduct vulnerability assessments, remediation tracking, and security reporting
  • Implement security analysis tools (SAST, DAST, SCA) into CI/CD pipelines to identify vulnerabilities early.
  • Ensure cloud systems meet Risk Management Framework (RMF) standards (NIST 800-53), including ATO (Authority to Operate) support and documentation.
  • Perform automated cybersecurity testing and manage STIG compliance, conducting scan evaluations using ACAS (Assured Compliance Assessment Solution).
  • Develop and maintain automation scripts for patching, configuration management, and evidence collection to support continuous authorization. 
  • Provision, configure, and maintain fedearl cloud infrastructure using Infrastructure as Code (IaC) tools like Terraform or CloudFormation.
  • Maintain secure configurations for cloud, virtualized, and hybrid environments, ensuring availability and resilience
  • Collaborate with development, DevSecOps, and cloud engineering teams to embed security into system design and deployment workflows
  • Maintain documentation including security plans, SSPs, POA&Ms, and configuration baselines
  • Support incident response activities, including investigation, containment, and corrective action implementation
  • Collaborating with agile software teams to remediate application risks.
  • Managing Cloud Service Provider (CSP) security tools (AWS Security Hub, Azure Defender).
  • Troubleshooting cloud-based application performance and security issues.
  • Applying security patches and managing IAVAs (Information Assurance Vulnerability Alerts).


Required Qualifications

  • US Citizen
  • Must be able to obtain a Tier-3 Secret Clearance
  • Bachelor’s degree in IT, Engineering, Computer Science, or a related field; master’s degree preferred.
  • 5-7 years in Cloud Engineering/Admin or Cybersecurity.
  • Experience with cloud platforms (AWS Preferred)
  • Experience securing CI/CD pipelines and DevSecOps environments
  • Experience with Kubernetes/Docker containerization, CI/CD tools (Jenkins, GitLab CI), AWS/Azure Services, and IaC (Terraform).
  • Familiarity with federal cybersecurity mandates (RMF, STIGs).
  • Familiarity with container security (Docker, Kubernetes security practices)
  • Experience with vulnerability scanning and security tools (e.g., Nessus, Fortify, SonarQube, Anchore)


Concept Plus is an Equal Opportunity Employer. As such, we will give your application full consideration without regard to your race, color, religion, sex, age, national origin, disability, veteran status, sexual orientation, gender identity, or any other classification protected by federal, state, or local law.


Defense/National Security Sector

Remote (Dayton, OH)

Partager sur :

Conditions générales d’utilisationConfidentialitéCookiesPropulsé par Rippling