Cloud Platform and Security Consultant
Remote
Contracted
Experienced
Remote role
Sabot Consulting is assembling an independent assessment team to conduct a one-time retrospective assessment lasting four months of a large, multi-year public-sector enterprise modernization program.
This is an assessment engagement, not an implementation. You will not build, configure, integrate, remediate, or operate anything. You will examine what has already been built, review the evidence, interview the people who built it, and reach independent, defensible conclusions for executive leadership. Independence from the program's implementation vendors is a contractual requirement of the engagement.
The scope covers nine assessment domains and 65 discrete assessment requirements: program governance and risk, business process alignment, architecture and design, integration and data management, mainframe and legacy modernization, security and privacy compliance, software development lifecycle and configuration management, testing and quality assurance, and operational readiness. The technology environment includes a major cloud customer relationship management platform, a public cloud infrastructure estate, an enterprise integration platform, a content management platform, intelligent document processing, and a mainframe lift-and-refactor migration.
Deliverables include an assessment management plan, an initial assessment report, recurring status briefings, per-domain assessment reports, readiness assessments, an executive briefing, and a final assessment report.
You will work full time for four months in a small paired-team structure alongside senior peers. Findings go directly to executive leadership and to a legislative oversight body.
Sabot Consulting is assembling an independent assessment team to conduct a one-time retrospective assessment lasting four months of a large, multi-year public-sector enterprise modernization program.
This is an assessment engagement, not an implementation. You will not build, configure, integrate, remediate, or operate anything. You will examine what has already been built, review the evidence, interview the people who built it, and reach independent, defensible conclusions for executive leadership. Independence from the program's implementation vendors is a contractual requirement of the engagement.
The scope covers nine assessment domains and 65 discrete assessment requirements: program governance and risk, business process alignment, architecture and design, integration and data management, mainframe and legacy modernization, security and privacy compliance, software development lifecycle and configuration management, testing and quality assurance, and operational readiness. The technology environment includes a major cloud customer relationship management platform, a public cloud infrastructure estate, an enterprise integration platform, a content management platform, intelligent document processing, and a mainframe lift-and-refactor migration.
Deliverables include an assessment management plan, an initial assessment report, recurring status briefings, per-domain assessment reports, readiness assessments, an executive briefing, and a final assessment report.
You will work full time for four months in a small paired-team structure alongside senior peers. Findings go directly to executive leadership and to a legislative oversight body.
Required
- 10 or more years in cloud architecture with deep Amazon Web Services (AWS) experience — network design, identity and access management, security groups, monitoring, resilience, disaster recovery, and governance controls
- Security architecture assessment — identity and access management, encryption, logging, monitoring, and tracing security requirements through to their implementation in configuration
- CJIS compliance experience — high priority. CJIS stands for Criminal Justice Information Services, the United States Federal Bureau of Investigation security policy that governs handling of criminal justice data. The client holds law enforcement data and employs sworn investigators, so this is a real requirement, not a nice-to-have.
- Privacy controls, records retention, and audit logging assessment
- Vendor risk management and software supply chain security — including SBOM
About Us: Sabot Consulting is a management consulting company focused on providing technical and management consulting to IT executives and managers in strategic, operational, and project-based practice areas. Our focus on providing expert staff that have the knowledge, experience, and professionalism to engage the client at all levels is the key to our success.
Apply for this position
Required*