3PAO Assessor
Booz Allen Hamilton
- Location
- Singapore
- Work model
- On-Site
- Level
- Mid
- H-1B history
- 9 approvals (FY2023)
- Posted
- Sep 14, 2026
Skills
About this role
3PAO Assessor The Opportunity: Everyone is trying to “harness the cloud,” but not everyone knows how to secure it. As a cloud security architect, you know how to assess and implement requirements that ensure the safety of information systems and protect them against intentional or inadvertent access or destruction. What if you could use your advanced cloud security skills to improve critical systems? We need you to guide the development of cloud-based security architectures for some of the nations most critical systems. As a cloud security architect on our team, you’ll work in coordination with a global team. You will leverage your expertise to assist the team develop a Cloud Accreditation Program for the client, including a Moderate impact security control baseline for the SaaS Cloud Service Offering (CSO), program policy, Security Requirements Guide (SRG), System Security Plan (SSP), Evidence Request List (ERL), and other associated templates. Upon program development, client acceptance, and handover and training, you will help operationalize program artifacts and templates on client site in Singapore by performing a security control assessment on the SaaS CSO using the Moderate impact security control baseline, documenting the findings, performing analysis, and determining the residual risk presented by findings, and developing a risk report and presenting it to the client Serving as the team’s primary representative for all continuous monitoring and annual reassessment activities. You’ll recommend tools and capabilities based on your research of the current environment and knowledge of various on-premise, cloud-based, and hybrid resources to address the risk management framework (RMF). Your technical expertise will be vital to ensure standards are met with information assurance and security requirements. Join us. The world can’t wait. You Have: 5+ years of experience with control assessment in NIST SP 800-53r4/5, ISO/IEC 27001:2022, or System and Organization Controls (SOC) 3+ years of experience with Federal Risk and Authorization Management Program (FedRAMP), or Cloud Security Alliance (CSA) Security, Trust, Assurance, and Risk (STAR) Ability to work in Singapore without sponsorship Bachelor's degree CISSP, ISO 27001, ISO 17020, or CIS‑ASP certification Nice If You Have: Experience with FedRAMP Third Party Assessment Organization (3PAO) Cybersecurity Maturity Model Certification (CMMC) Level 2 Assessor, CCP, CCA, or LCCA certification Identity Statement As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud. Candidate AI Usage Policy AI is a part of our daily work at Booz Allen, and we are committed to the responsible and ethical use of AI tools. However, we want to ensure a fair candidate process based on your own skills and knowledge. As part of this commitment, the use of artificial intelligence (AI) or other tools to assist with responses during interviews (whether in-person or virtual) is prohibited unless permission is explicitly provided . Commitment to Non-Discrimination All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, local, or international law.