Назад
Company hidden
9 дней назад

Principal Security Compliance Analyst (Public Sector InfoSec)

159 800 - 252 800$
Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Principal Security Compliance Analyst (Public Sector InfoSec): Managing and enhancing Elastic’s FedRAMP Moderate authorization and continuous monitoring program with an accent on NIST SP 800-53 controls, security evidence, assessments, and remediation tracking. Focus on coordinating 3PAO and federal stakeholder reviews, evaluating product changes for FedRAMP impact, and maintaining compliance documentation and metrics.

Location: United States

Salary: $159,800–$252,800 USD per year; select locations including Seattle, Los Angeles, the San Francisco Bay Area, and the New York City Metro Area: $191,900–$303,500 USD per year.

Company

hirify.global develops the cloud-based hirify.global Search AI Platform for search, security, and observability, serving organizations including more than half of the Fortune 500.

What you will do

  • Manage the FedRAMP Moderate authorization and continuous monitoring program.
  • Maintain the System Security Plan, policies, procedures, evidence, inventories, diagrams, and related documentation.
  • Coordinate assessments and reviews with the 3PAO, federal agency partners, consultants, and internal teams.
  • Track security findings and POA&M items through remediation.
  • Partner with Security, Engineering, IT, Product, and Legal teams to implement and maintain required controls.
  • Monitor deadlines, risks, compliance metrics, and potential FedRAMP impact from system and product changes.

Requirements

  • 5+ years of experience managing or supporting a FedRAMP Moderate program.
  • Strong understanding of FedRAMP, NIST SP 800-53, and continuous monitoring requirements.
  • Experience with SSPs, POA&Ms, control evidence, vulnerability management, and security assessments.
  • Strong project-management and organizational skills.
  • Effective communication with technical teams, auditors, government stakeholders, and company leadership.
  • Eligibility to work in Department of Defense Impact Level 4 or higher cloud service environments.

Culture & Benefits

  • Distributed work environment with flexible locations and schedules for many roles.
  • Competitive pay based on the work performed rather than previous salary.
  • Health coverage for employees and families in many locations.
  • Generous vacation, at least 16 weeks of parental leave, and up to 40 volunteer hours annually.
  • Donation matching of up to $2,000 or local-currency equivalent.
  • Company-matched 401(k) contributions up to 6% of eligible earnings and eligibility for the stock program.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →