8 часов назад
Governance, Risk & Compliance (GRC) Lead, Federal (Cybersecurity)
158 000 - 184 000$
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Governance, Risk & Compliance (GRC) Lead, Federal (Cybersecurity): Owns FedRAMP High authorization and builds the security and compliance foundation for DoD IL4, IL5, IL6, and ICD 503 deployments with an accent on federal controls, authorization packages, and continuous monitoring. Focus on translating NIST, FedRAMP, DoD, and Intelligence Community requirements into defensible technical implementations, closing assessment findings, and scaling compliance evidence and automation.
Location: Washington, D.C.; hybrid with 4 in-office days per week. Must be based in Washington, D.C.
Salary: $158,000–$184,000 annually, plus benefits, equity if applicable, and bonus if applicable.
Company
develops an AI-enabled operational intelligence platform that helps public safety organizations, government agencies, and private-sector institutions make faster decisions from complex, disconnected data.
What you will do
- Own and expand the FedRAMP High authorization program through continuous monitoring, remediation, reauthorization, and transition toward applicable FedRAMP 20x requirements.
- Translate FedRAMP, NIST, DoD, Intelligence Community, and agency requirements into technical and operational controls for IL4, IL5, IL6, and ICD 503 environments.
- Lead agency-specific system authorizations from initial engagement through ATO issuance, sponsorship, and ongoing operation.
- Partner with Security and Infrastructure Engineering on system boundaries, ICAM, network security, encryption, logging, vulnerability management, hardening, supply-chain security, and incident response.
- Lead authorization artifacts, implementation statements, evidence, assessment responses, POA&M remediation, and continuous-monitoring deliverables.
- Build scalable control ownership, evidence collection, monitoring, change management, and compliance-automation practices while advising federal and customer-facing teams.
Requirements
- Active U.S. security clearance, ability to obtain one, and U.S. citizenship required.
- 10+ years of experience in information security, GRC, security assurance, or cybersecurity risk management.
- Experience personally leading significant portions of FedRAMP High authorization for a cloud service provider and maintaining authorization through continuous monitoring.
- Expertise in FedRAMP program management, federal RMF implementation, assessment and authorization, POA&M remediation, 3PAO or government assessor engagement, and Authorizing Official engagement.
- Working knowledge of NIST SP 800-53 and SP 800-37, FedRAMP, DoD Cloud Computing Security Requirements Guide, DISA SRGs/STIGs, FIPS, control overlays, and federal authorization practices.
- Technical understanding of AWS or AWS GovCloud, Kubernetes or containerized environments, Infrastructure as Code, CI/CD, cloud security architecture, and machine-readable assurance evidence such as OSCAL.
Nice to have
- Experience establishing and maintaining DoD IL4, IL5, or IL6 environments.
- Experience with ICD 503 accreditation, National Security Systems, classified systems, or cross-domain solutions.
- Experience supporting federal or defense customers handling CUI or other sensitive government information.
- CISSP, CISA, CGRC, CISM, CCSP, or comparable security certification.
Culture & Benefits
- Benefits, equity if applicable, and bonus if applicable are included with the compensation package.
- Work takes place in a hybrid Washington, D.C. environment with four office days per week.
- Work alongside Security, Engineering, Product, Legal, Federal Deployment, and go-to-market teams on mission-critical public safety and government systems.
- Build security and compliance capabilities for sensitive federal and defense deployments.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
2 часа назад
Security Governance Risk & Compliance (GRC) Analyst (Cybersecurity)
130 000 - 170 000$
10 часов назад
Lead FedRAMP Security Engineer (FedRAMP)
93 500 - 182 850$
3 часа назад
Governance, Risk, and Compliance Analyst (Cybersecurity)
160 000 - 200 000$
2 дня назад
Principal Security GRC Analyst (FedRAMP)
150 000 - 200 000$
11 часов назад
Principal Compliance Engineer (Cybersecurity)
195 000 - 270 000$
18 часов назад
Principal Cybersecurity Engineer (US Federal)
184 800 - 277 200$