... and GCP that manage risk and meet relevant security regulations, controls, and policies ... Prepare Assessment and Authorization (A&A) documentation including System Security Plans (SSPs ...
... and GCP that manage risk and meet relevant security regulations, controls, and policies ... Prepare Assessment and Authorization (A&A) documentation including System Security Plans (SSPs ...
Senior Risk Assessor
Lexington, KY · On-site +1
... risk assessment projects and proposals. This exciting opportunity offers a growth position in a ... Manage tasks of larger projects and track budgets * Under guidance of Project Manager or senior ...
Senior Risk Assessor
Lexington, KY · On-site +1
... risk assessment projects and proposals. This exciting opportunity offers a growth position in a ... Manage tasks of larger projects and track budgets * Under guidance of Project Manager or senior ...
Manager, Security
Hawesville, KY · On-site
$92K - $171K/yr
... threat assessments in overseas location as required • Manage investigations and ensure employee security • Serve as principal point of contact to client for personnel and facility security ...
Manager, Security
Hawesville, KY · On-site
$92K - $171K/yr
... threat assessments in overseas location as required • Manage investigations and ensure employee security • Serve as principal point of contact to client for personnel and facility security ...
Senior Risk Assessor
Louisville, KY · On-site +1
... risk assessment projects and proposals. This exciting opportunity offers a growth position in a ... Manage tasks of larger projects and track budgets * Under guidance of Project Manager or senior ...
Senior Risk Assessor
Louisville, KY · On-site +1
... risk assessment projects and proposals. This exciting opportunity offers a growth position in a ... Manage tasks of larger projects and track budgets * Under guidance of Project Manager or senior ...
Manager, Security
Hawesville, KY · On-site
$92K - $171K/yr
... assessments in overseas location as required Manage investigations and ensure employee security Serve as principal point of contact to client for personnel and facility security matters Process ...
Manager, Security
Hawesville, KY · On-site
$92K - $171K/yr
... assessments in overseas location as required Manage investigations and ensure employee security Serve as principal point of contact to client for personnel and facility security matters Process ...
$93K - $105K/yr
... Management system, defining and maintaining roles, and developing and maintaining appropriate documentation. * Support the CISO-led Information Security Risk Assessment process. * Administer ...
$93K - $105K/yr
... Management system, defining and maintaining roles, and developing and maintaining appropriate documentation. * Support the CISO-led Information Security Risk Assessment process. * Administer ...
Risk Management and Security Consulting * Coordinate and perform risk assessments using corporate-provided tools and templates. * Work with local leaders to assess, submit and approve exceptions to ...
Risk Management and Security Consulting * Coordinate and perform risk assessments using corporate-provided tools and templates. * Work with local leaders to assess, submit and approve exceptions to ...
About the role The Senior IT Risk and Security Analyst (RSA) is a critical member of the ... Lead enterprise IT risk management activities, including annual risk assessments, risk committee ...
About the role The Senior IT Risk and Security Analyst (RSA) is a critical member of the ... Lead enterprise IT risk management activities, including annual risk assessments, risk committee ...
Vendor Security Analyst
Louisville, KY · On-site
$120K - $146K/yr
The Vendor Security Analyst performs evaluation of third party and vendor engagements to identify and manage vendor risk which may include completion of risk assessments. They will also conduct the ...
Vendor Security Analyst
Louisville, KY · On-site
$120K - $146K/yr
The Vendor Security Analyst performs evaluation of third party and vendor engagements to identify and manage vendor risk which may include completion of risk assessments. They will also conduct the ...
Vendor Security Analyst
Louisville, KY · On-site
$120K - $146K/yr
The Vendor Security Analystperforms evaluation of third party and vendor engagements to identify and manage vendor risk which may include completion of risk assessments. They will also conduct the ...
Vendor Security Analyst
Louisville, KY · On-site
$120K - $146K/yr
The Vendor Security Analystperforms evaluation of third party and vendor engagements to identify and manage vendor risk which may include completion of risk assessments. They will also conduct the ...
$60K - $70K/yr
Additionally, the position plays a key role in managing security risk assessments across software products, requiring a strong foundation in cybersecurity best practices. Success in this role demands ...
$60K - $70K/yr
Additionally, the position plays a key role in managing security risk assessments across software products, requiring a strong foundation in cybersecurity best practices. Success in this role demands ...
... security assessments, implementations, migrations, remediation efforts, and managed-service ... Drive client governance cadences, including kickoff sessions, status meetings, risk reviews ...
... security assessments, implementations, migrations, remediation efforts, and managed-service ... Drive client governance cadences, including kickoff sessions, status meetings, risk reviews ...
As an Account Manager, you are the driving force behind daily security operations, ensuring the ... Knowledge of emergency preparedness, physical security protocols, risk assessments, and law ...
As an Account Manager, you are the driving force behind daily security operations, ensuring the ... Knowledge of emergency preparedness, physical security protocols, risk assessments, and law ...
$75K - $90K/yr
Perform access review and internal control assessment for security compliance * Document and track known vulnerabilities and control deficiencies * Perform security risk mitigation planning based on ...
$75K - $90K/yr
Perform access review and internal control assessment for security compliance * Document and track known vulnerabilities and control deficiencies * Perform security risk mitigation planning based on ...
Conduct vulnerability and risk assessment analyses to support security authorization. * Provide configuration management for information systems security software, hardware, and firmware. * Support ...
Conduct vulnerability and risk assessment analyses to support security authorization. * Provide configuration management for information systems security software, hardware, and firmware. * Support ...
Perform security risk assessments to identify gaps, develop recommendations and close the gaps to completion and resolution * Lead and maintain and Third Party Risk Management (TPRM) program * Setup ...
Perform security risk assessments to identify gaps, develop recommendations and close the gaps to completion and resolution * Lead and maintain and Third Party Risk Management (TPRM) program * Setup ...
The position also manages contract renewals and onboarding for cybersecurity MSAs, coordinates ... Enable compliance by assisting with evidence collection for audits and assessments--such as SOC 2, ...
The position also manages contract renewals and onboarding for cybersecurity MSAs, coordinates ... Enable compliance by assisting with evidence collection for audits and assessments--such as SOC 2, ...
Compliance & Risk * Ensure compliance with client requirements, state/local licensing, and company ... Working knowledge of security operations, incident management, and post order development.
New
Compliance & Risk * Ensure compliance with client requirements, state/local licensing, and company ... Working knowledge of security operations, incident management, and post order development.
New
Ability to assess and analyze security risks comprehensively, considering both business impact and ... Ability to prioritize risk remediation with consideration to business goals and objectives.
Ability to assess and analyze security risks comprehensively, considering both business impact and ... Ability to prioritize risk remediation with consideration to business goals and objectives.
$118K - $174K/yr
... management, security testing, security tooling, and DevSecOps practices. The role provides ... Conduct threat modeling, attack surface analysis, and product security risk assessments for new and ...
$118K - $174K/yr
... management, security testing, security tooling, and DevSecOps practices. The role provides ... Conduct threat modeling, attack surface analysis, and product security risk assessments for new and ...
Manager Security Risk Assessment information
What is the difference between Manager Security Risk Assessment vs Security Analyst?
| Aspect | Manager Security Risk Assessment | Security Analyst |
|---|---|---|
| Certifications | CISSP, CISM, CRISC | CISSP, Security+ |
| Work Environment | Oversees security programs, manages teams | Analyzes security threats, monitors systems |
| Industry Usage | Common in organizations with complex security needs | Widely used across various industries for threat detection |
The Manager Security Risk Assessment focuses on leading security risk evaluations, managing teams, and developing security strategies. In contrast, a Security Analyst primarily monitors security systems, analyzes threats, and responds to incidents. Both roles require relevant certifications and work within the cybersecurity industry, but their responsibilities differ in scope and focus.
What cities in Kentucky are hiring for Manager Security Risk Assessment jobs?
Cities in Kentucky with the most Manager Security Risk Assessment job openings:
Cloud Security Engineer
On-site
Other
Medical, Dental, Vision, Retirement, PTO
Posted 20 days ago
Key responsibilities
Engineer and design security solutions across cloud platforms including AWS, Microsoft Azure, and GCP that manage risk and meet relevant security regulations, controls, and policies.
Implement security designs by installing, configuring, and testing cloud-native services, associated third-party services, and security software across multi-cloud environments.
Perform continuous monitoring of cloud environments using implemented solutions and tools to detect and respond to security events.
Job description
Posted Friday, August 21, 2026 at 4:00 AM
Koniag Technology Solution, a Koniag Government Services company, is seeking an experienced Cloud Security Engineer to join a dynamic team supporting cloud security architecture, implementation, and continuous monitoring across multiple cloud platforms. The ideal candidate is a technically proficient security professional with hands-on experience securing environments across Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform (GCP). This individual will be passionate about cybersecurity, committed to staying current with evolving threats and technologies, and capable of applying their expertise to solve complex, real-world security challenges in a federal government context. The ability to obtain or maintain an active Secret clearance is required to support our government customer.
We offer competitive compensation and an extraordinary benefits package including health, dental and vision insurance, 401K with company matching, flexible spending accounts, paid holidays, three weeks paid time off, and more.
The Cloud Security Engineer will be responsible for the security aspects of cloud system design, security tool and service analysis and selection, and subsequent implementation across AWS, Microsoft Azure, and Google Cloud Platform (GCP). This individual will configure tools and services to meet the business requirements, policy mandates, and security risk tolerance of our government customers. The Cloud Security Engineer will also document how required security controls are satisfied through cloud service and tool implementations to support Assessment and Authorization (A&A) activities.
Principal responsibilities will include but are not limited to:
- Engineer and design security solutions across cloud platforms including AWS, Microsoft Azure, and GCP that manage risk and meet relevant security regulations, controls, and policies.
- Implement security designs by installing, configuring, and testing cloud-native services, associated third-party services, and security software across multi-cloud environments.
- Determine how to effectively leverage native security services from cloud providers and identify gaps that must be addressed through additional tools, software, or third-party services.
- Implement and manage security tools and services including OS hardening, cloud-native security features (e.g., AWS Config, Azure Security Center, GCP Security Command Center), vulnerability management tools such as Qualys, intrusion detection tools such as Tripwire, and SIEM solutions such as Splunk.
- Develop and maintain processes and procedures for the operation and use of implemented security tools and services.
- Prepare Assessment and Authorization (A&A) documentation including System Security Plans (SSPs), security control worksheets, and other supporting artifacts.
- Participate in the assessment of system security controls to validate proper implementation and identify weaknesses or gaps in compliance posture.
- Perform continuous monitoring of cloud environments using implemented solutions and tools to detect and respond to security events.
- Conduct security impact assessments of proposed changes to cloud environments to identify adverse shifts in security risk posture or compliance standing.
- Identify new and innovative ways to leverage existing toolsets to automate security management, monitoring, and related processes in order to reduce risk and operational costs.
- Collaborate with cross-functional technical teams, system owners, and business analysts to reconcile security requirements with operational needs.
- Contribute to technical documentation including architecture diagrams, security design documents, and detailed data flows.
- Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or a related IT or security field from an accredited college or university.
- 5+ years of professional experience in IT/network engineering, security engineering, system administration, or security operations.
- Demonstrated experience with FISMA, FedRAMP, and NIST SP 800-53 security frameworks and control families.
- Active Secret security clearance or higher.
- Exceptional analytical skills with strong verbal and written communication abilities in English, with the capacity to communicate effectively with both technical and non-technical stakeholders.
- Demonstrated ability to work independently as a self-starter while also functioning effectively as a collaborative team member.
- Hands-on experience engineering and implementing security solutions across two or more major cloud platforms, including AWS, Microsoft Azure, and/or GCP.
- Proficiency in configuring and operating cloud-native security services such as AWS Config, AWS Security Hub, Azure Defender/Security Center, Azure Policy, and/or GCP Security Command Center.
- Experience implementing and managing security tools including vulnerability management platforms (e.g., Qualys), host-based intrusion detection (e.g., Tripwire), and SIEM platforms (e.g., Splunk).
- Experience with OS hardening techniques and implementation of security baselines across cloud-hosted systems.
- Familiarity with preparing and maintaining Assessment and Authorization (A&A) documentation including System Security Plans (SSPs) and security controls worksheets.
- Experience performing continuous monitoring and security impact assessments within cloud environments.
- Knowledge of identity and access management (IAM) principles and implementation across cloud platforms.
- Ability to identify opportunities to automate security processes and monitoring to reduce risk and operational overhead.
- Strong initiative and ability to present ideas and solutions to overcome technical and organizational security challenges.
- Active security certifications such as CISSP, CISM, CISA, CEH, CCSK, CCSP, AWS Certified Security Specialty, Microsoft Certified: Azure Security Engineer Associate, or Google Professional Cloud Security Engineer.
- Experience working in a federal government IT environment, specifically within FedRAMP-authorized or FISMA-compliant cloud environments.
- Experience deploying and operating tools across multiple security domains including vulnerability management, incident detection and response, event/audit log collection and analysis, and network and web application firewalls.
- Familiarity with ServiceNow and its integration within security operations and GRC workflows.
- Knowledge of single sign-on (SSO) concepts using SAML and OAuth2 within cloud environments.
- Experience with Infrastructure as Code (IaC) tools such as Terraform, CloudFormation, or ARM templates to support secure cloud deployments.
- Master's degree in Information Systems, Cybersecurity, or a related field.
The company is an equal opportunity employer. The company shall not discriminate against any employee or applicant because of race, color, religion, creed, ethnicity, sex, sexual orientation, gender or gender identity (except where gender is a bona fide occupational qualification), national origin or ancestry, age, disability, citizenship, military/veteran status, marital status, genetic information or any other characteristic protected by applicable federal, state, or local law. We are committed to equal employment opportunity in all decisions related to employment, promotion, wages, benefits, and all other privileges, terms, and conditions of employment.
The company is dedicated to seeking all qualified applicants. If you require an accommodation to navigate or to apply to a position on our website, please contact Heaven Wood via e-mail at accommodations@koniag-gs.com or by calling 703-488-9377 to request accommodations.
Koniag Government Services (KGS) is an Alaska Native Owned corporation supporting the values and traditions of our native communities through an agile employee and corporate culture that delivers Enterprise Solutions, Professional Services and Operational Management to Federal Government Agencies. As a wholly owned subsidiary of Koniag, we apply our proven commercial solutions to a deep knowledge of Defense and Civilian missions to provide forward leaning technical, professional, and operational solutions. KGS enables successful mission outcomes for our customers through solution-oriented business partnerships and a commitment to exceptional service delivery. We ensure long‑term success with a continuous improvement approach while balancing the collective interests of our customers, employees, and native communities. For more information, please visit www.koniag-gs.com .
Equal Opportunity Employer/Veterans/Disabled. Shareholder Preference in accordance with Public Law 88-352