Cloud Platform and Security Consultant

Sabot ConsultingHenderson, NV
Remote

About The Position

Sabot Consulting is assembling an independent assessment team to conduct a one-time retrospective assessment lasting four months of a large, multi-year public-sector enterprise modernization program. This is an assessment engagement, not an implementation. You will not build, configure, integrate, remediate, or operate anything. You will examine what has already been built, review the evidence, interview the people who built it, and reach independent, defensible conclusions for executive leadership. Independence from the program's implementation vendors is a contractual requirement of the engagement. The scope covers nine assessment domains and 65 discrete assessment requirements: program governance and risk, business process alignment, architecture and design, integration and data management, mainframe and legacy modernization, security and privacy compliance, software development lifecycle and configuration management, testing and quality assurance, and operational readiness. The technology environment includes a major cloud customer relationship management platform, a public cloud infrastructure estate, an enterprise integration platform, a content management platform, intelligent document processing, and a mainframe lift-and-refactor migration. Deliverables include an assessment management plan, an initial assessment report, recurring status briefings, per-domain assessment reports, readiness assessments, an executive briefing, and a final assessment report. You will work full time for four months in a small paired-team structure alongside senior peers. Findings go directly to executive leadership and to a legislative oversight body.

Requirements

  • 10 or more years in cloud architecture with deep Amazon Web Services (AWS) experience — network design, identity and access management, security groups, monitoring, resilience, disaster recovery, and governance controls
  • Security architecture assessment — identity and access management, encryption, logging, monitoring, and tracing security requirements through to their implementation in configuration
  • CJIS compliance experience — high priority. CJIS stands for Criminal Justice Information Services, the United States Federal Bureau of Investigation security policy that governs handling of criminal justice data. The client holds law enforcement data and employs sworn investigators, so this is a real requirement, not a nice-to-have.
  • Privacy controls, records retention, and audit logging assessment
  • Vendor risk management and software supply chain security — including SBOM

Responsibilities

  • Conduct a one-time retrospective assessment of a large, multi-year public-sector enterprise modernization program.
  • Examine what has already been built, review evidence, and interview personnel.
  • Reach independent, defensible conclusions for executive leadership.
  • Assess program governance and risk.
  • Evaluate business process alignment.
  • Analyze architecture and design.
  • Review integration and data management.
  • Assess mainframe and legacy modernization.
  • Evaluate security and privacy compliance.
  • Review software development lifecycle and configuration management.
  • Assess testing and quality assurance.
  • Evaluate operational readiness.
  • Prepare an assessment management plan.
  • Produce an initial assessment report.
  • Provide recurring status briefings.
  • Generate per-domain assessment reports.
  • Conduct readiness assessments.
  • Prepare an executive briefing.
  • Deliver a final assessment report.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service