14 дней назад
Government Compliance Technical Specialist (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Government Compliance Technical Specialist (Cybersecurity): Managing and modernizing government compliance programs including FedRAMP Moderate, FedRAMP 20x, TX-RAMP, and IRAP with an accent on continuous monitoring, documentation, and cloud control implementation. Focus on defining Key Security Indicators, building automated evidence pipelines, managing POA&Ms, and coordinating remediation across security, engineering, and cloud operations.
Company
develops cybersecurity SaaS solutions focused on identity security, privilege management, and reducing identity-related attack surfaces.
What you will do
- Lead technical compliance activities for FedRAMP 20x readiness, including Key Security Indicators, evidence strategies, and machine-readable compliance outputs.
- Manage FedRAMP Moderate/Class C continuous monitoring, deliverables, POA&M tracking, and deviation requests.
- Author and maintain System Security Plans, Security Decision Records, and other human- and machine-readable compliance documentation.
- Track findings and remediation across FedRAMP, GovRAMP, TX-RAMP, IRAP, and other public-sector compliance programs.
- Coordinate with engineering, security, cloud operations, legal, and infrastructure teams to validate controls, gather evidence, and close compliance gaps.
- Manage relationships with Third Party Assessment Organizations and agency stakeholders while reporting program health and translating policy changes into the compliance roadmap.
Requirements
- At least 3 years of FedRAMP program management and technical compliance experience.
- 4–7 years of experience in information security, compliance, or GRC.
- Experience running a FedRAMP Moderate program, including SSP authorship, continuous monitoring, POA&M management, and assessor coordination.
- Deep knowledge of NIST SP 800-53 controls and their implementation in cloud environments.
- Strong familiarity with FedRAMP 20x, Key Security Indicators, machine-readable evidence frameworks, and continuous assessment models.
- Experience with automated compliance evidence pipelines, GRC tooling, cross-functional remediation, and concurrent workstream management.
Nice to have
- Familiarity with AI security or using AI to develop and deploy applications.
- Experience with GovRAMP, TX-RAMP, IRAP, FedRAMP High, or DoD IL4/IL5 environments.
- CISSP or CISA certification.
- Experience in cybersecurity product companies or multi-product SaaS environments.
- Bachelor’s degree in information security, computer science, or a related field.
Culture & Benefits
- Work in a culture centered on flexibility, trust, continual learning, diversity, and inclusion.
- Collaborate with global product, security, engineering, cloud operations, legal, and compliance stakeholders.
- Contribute to cybersecurity products used by 20,000 customers, including 75 of the Fortune 100.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →