Description
We are seeking a Senior Federal Auditor to support our cloud authorization activities and ensure compliance with federal regulations.
The ideal candidate has solid, hands-on experience with FedRAMP compliance processes and federal risk management frameworks, including exposure to FedRAMP High and DoD Impact Level (IL4/IL5) environments.
Responsibilities:
- Contribute to authorization package documentation (SSPs, POA&Ms, SAPs), with attention to FedRAMP High baseline requirements
- Coordinate with 3PAOs and federal agency sponsors on scheduling, evidence collection, and artifact prep for FedRAMP and DoD IL4/IL5 assessments; respond to assessor inquiries
- Implement and document NIST SP 800-53 controls, validating effectiveness and gathering evidence across FedRAMP Moderate, High, and DoD IL4/IL5 boundaries
- Execute continuous monitoring: monthly vulnerability scanning reviews, POA&M tracking, and deliverables for sponsoring agencies and DoD stakeholders, including annual assessment support
- Assess system architectures with cloud/infrastructure teams to identify compliance gaps, and conduct gap analyses/readiness assessments ahead of 3PAO assessments
- Develop and improve FedRAMP policies, procedures, control implementation descriptions, and internal documentation standards, aligned with PMO and DoD SRG guidance
- Review and respond to federal customer security questionnaires and due diligence requests
- Prepare compliance status summaries, POA&M updates, and control assessment findings for senior leadership
- Monitor FedRAMP PMO, NIST, and DoD SRG updates and federal cybersecurity directives, flagging relevant changes to the GRC team
- Participate in cross-functional projects integrating FedRAMP High and DoD IL4/IL5 requirements into product development
Requirements:
- 5+ years in information security, compliance, or risk management, with federal program exposure
- 5+ years of hands-on FedRAMP experience (CSP compliance, 3PAO assessment support, or federal agency ISSO activities); FedRAMP and DoD IL2 (IL4/IL5 preferred)
- Strong written and verbal communication skills across technical and non-technical audiences; experience producing audit findings, policies, and compliance reports
- Certifications preferred: CISSP, CISA, CAP, Security+, or equivalent
Benefits:
- Annual base salary range: $100,000 to $155,000
- Equity awards
- Medical, dental, and vision plan
- Family planning benefits
- Health savings account
- Flexible spending account
- Transportation savings account
- 401(k) retirement savings plan with company match
- Life, accident, and disability coverage
- Business travel accident insurance
- Employee assistance programs
- Disability insurance
- Other well-being benefits
This listing is enriched and indexed by YubHub. To apply, use the employer's original posting:
https://job-boards.greenhouse.io/tanium/jobs/8126966