18 часов назад
Sr. Information Security Technical Lead (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Sr. Information Security Technical Lead (FedRAMP/Cybersecurity): Leading FedRAMP security operations, compliance programs, lifecycle management, and security assessments for government SaaS offerings with an accent on FedRAMP, GRC, NIST frameworks, cloud security, and SOC operations. Focus on automating continuous monitoring, managing System Security Plans and POA&Ms, coordinating audits and authorizations, and responding to complex security incidents.
Location: Manila, Philippines
Company
develops cybersecurity products and cloud security solutions that help protect digital information.
What you will do
- Lead FedRAMP security case processing in the Philippines and coordinate with FedRAMP Operations members in the Americas.
- Oversee SOC-based security alert monitoring, security operations, and compliance activities.
- Develop and manage FedRAMP compliance programs for VisionOne and CloudOne government SaaS offerings and FIPS-compliant software releases.
- Coordinate FedRAMP assessments, authorizations, continuous monitoring, and reauthorizations.
- Maintain System Security Plans, policies, procedures, controls, POA&Ms, and compliance documentation.
- Coordinate audits, risk assessments, external assessors, reporting, and integration of FedRAMP requirements across IT, security, and development teams.
Requirements
- At least 3 years of experience in information security or network administration, preferably in an enterprise SOC.
- At least 3 years of experience in security compliance or GRC, preferably supporting U.S. public-sector security authorizations.
- Strong knowledge of FedRAMP, CMMC, NIST 800-53, NIST RMF, FISMA, and related security frameworks.
- Experience with Azure GovCloud, Sentinel, Nessus, HCL AppScan, JIRA, SIEM, IDS/IPS, EDR, firewalls, Windows Servers, and network monitoring tools.
- Proficiency with Windows, macOS, and Linux, plus knowledge of network and security architecture, cloud services, and risk assessment procedures.
- Strong analytical, problem-solving, project management, communication, and collaboration skills; willingness to attend frequent international video conferences and handle incidents outside regular hours.
Nice to have
- Certifications such as CISSP, GCIH, GCFA, CEH, or similar.
- Experience with third-party security risk assessments, penetration testing, threat hunting, computer forensics, incident response, or information security management.
- Advanced FedRAMP expertise and experience conducting regular security audits.
- Self-motivation and the ability to work with minimal supervision.
Culture & Benefits
- Full-time employment with opportunities to contribute to cybersecurity initiatives that protect digital information.
- Regular collaboration with international security, IT, development, audit, customer, and regulatory stakeholders.
- Work includes participation in international video conferences and non-regular-hours incident handling.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →