7 дней назад
Senior Federal Compliance Analyst (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Federal Compliance Analyst (Cybersecurity): Leading the build-out and continuous management of DoW Impact Level 4 and Impact Level 5 compliance offerings with an accent on FedRAMP, NIST SP 800-53, and AWS security requirements. Focus on translating federal compliance controls into cloud-native technical specifications, managing continuous monitoring and audits, and coordinating with engineers, external auditors, federal sponsors, and regulatory bodies.
Location: Remote within the United States. Requires up to 5% travel, US citizenship, and the ability to obtain and maintain a government security clearance.
Company
is a remote cybersecurity product company developing the NodeZero platform for autonomous penetration testing and security assessment operations.
What you will do
- Lead compliance assessments and authorization build-out for DoW Impact Level 4 and Impact Level 5 offerings under the Cloud Computing Security Requirements Guide.
- Maintain and evolve compliance programs covering FedRAMP High, FedRAMP Moderate, NIST SP 800-53, and related federal frameworks.
- Translate federal and DoW security requirements into actionable specifications for cloud-native AWS infrastructure in partnership with engineering teams.
- Oversee internal audits, risk assessments, continuous monitoring, incident response, and compliance investigations.
- Coordinate with external auditors, federal sponsors, and regulatory bodies.
- Respond to security questionnaires, due diligence requests, and vendor risk assessments while maintaining GRC policies, procedures, and employee training.
Requirements
- 3–5+ years of experience in GRC, security compliance, or a similar role.
- Strong knowledge of DoW CC SRG IL4/IL5, FedRAMP High/Moderate, and NIST SP 800-53.
- Experience writing and maintaining FedRAMP System Security Plans, policies, procedures, and related plans.
- Experience securing and managing compliance within AWS environments, including cloud-native components and distributed architectures.
- Familiarity with AWS security and compliance tools such as Security Hub, GuardDuty, and Inspector, plus GRC, Jira, and Confluence tools.
- Bachelor’s degree in IT, Computer Science, Cybersecurity, or a related field, or equivalent practical experience and relevant certifications. US citizenship and the ability to obtain and maintain a government security clearance are required.
Nice to have
- Active DoW security clearance.
- Relevant certifications such as CISSP or CISA.
Culture & Benefits
- Fully remote work, with hybrid and office-based arrangements used for some other roles.
- Inclusive, collaborative culture focused on ownership, respect, learning, and results.
- Health, vision, and dental insurance for employees and families.
- Flexible vacation policy and generous parental leave.
- Career development opportunities, equity in the form of stock options, and approved reimbursement for job-related travel.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
8 дней назад
Senior Security Technical Governance Program Manager
176 400 - 206 168$
9 дней назад
Security Architect/vCISO
6 дней назад
Security Engineer (AWS)
5 дней назад
Information Security Compliance Analyst
80 000 - 100 000$
5 дней назад
Head of Information Security/Compliance
175 000 - 220 000$
9 дней назад
Senior Security Analyst (GRC)
115 000 - 145 000$