Назад
Company hidden
10 дней назад

Senior FedRAMP ISSO

128 000 - 200 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior FedRAMP ISSO (Cloud Security/Compliance): Owning the FedRAMP Moderate authorization, System Security Plan, continuous monitoring, POA&M lifecycle, and annual 3PAO assessments for an authorized cloud environment with an accent on cloud security, compliance operations, and AI-assisted automation. Focus on maintaining authorization readiness, driving remediation, evaluating system changes, and translating federal security guidance into actionable controls.

Location: Remote - United States; occasional duties may be required outside standard working hours across multiple time zones.

Base salary: $128,000–$200,000 USD per year, depending on geographic location, knowledge, skills, and experience.

Company

hirify.global builds telemetry infrastructure and an AI platform that helps large enterprises manage and analyze telemetry for humans and AI agents.

What you will do

  • Own the FedRAMP Moderate authorization, including the System Security Plan, continuous monitoring program, POA&M lifecycle, and agency relationships.
  • Maintain and defend the SSP by documenting architecture, control implementations, operational changes, and approved automation or AI use.
  • Manage findings from assessments, vulnerability scans, and internal reviews through remediation, reporting, and documented closure.
  • Lead monthly and annual continuous monitoring, vulnerability triage, configuration reviews, incident reporting, and annual 3PAO assessments.
  • Assess the security and compliance impact of new features, infrastructure updates, and AI capabilities.
  • Partner with engineering, DevOps, security operations, legal, product, federal agencies, Authorizing Officials, and the FedRAMP PMO.

Requirements

  • 5+ years of information security experience, including at least 3 years in a dedicated FedRAMP ISSO or ISSE role at a Cloud Service Provider.
  • Working knowledge of NIST SP 800-53 Rev. 5 and the FedRAMP Ecosystem baseline.
  • Experience authoring and maintaining large-scale System Security Plans, managing POA&Ms, leading continuous monitoring, and coordinating annual 3PAO assessments.
  • Experience using automation, scripting, or AI tools to improve evidence collection, reporting, documentation review, or compliance workflows.
  • Familiarity with cloud security, with AWS GovCloud strongly preferred; Azure Government or GCP experience is valued.
  • Active CISSP, CAP/CGRC, or CISM certification and strong written communication skills.

Nice to have

  • Experience with FedRAMP High, IL4, or IL5 baselines.
  • Familiarity with OSCAL, automated compliance tooling, compliance-as-code, infrastructure-as-code security scanning, or DevSecOps integration.
  • Experience evaluating AI/ML capabilities within a FedRAMP-authorized boundary and familiarity with the NIST AI Risk Management Framework.
  • Experience with GRC platforms, DISA STIGs, or federal security clearance eligibility.

Culture & Benefits

  • Remote-first work environment with collaboration across multiple time zones.
  • Health, dental, vision, short-term disability, and life insurance.
  • Paid holidays, paid time off, and fertility treatment benefits.
  • 401(k), equity, and participation in the Corporate Bonus Program for eligible non-sales roles.
  • Inclusive culture focused on collaboration, curiosity, and valuing differences.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →