Responsibilities
- Manage and oversee end-to-end FedRAMP authorization activities, including planning, execution, resourcing, and stakeholder coordination.
- Own the development, maintenance, and quality of all FedRAMP-required security documentation, including the System Security Plan (SSP), Security Assessment Plan (SAP), Security Assessment Report (SAR), Plan of Action & Milestones (POA&M), and Continuous Monitoring artifacts.
- Oversee monthly POA&M management, including vulnerability prioritization, remediation tracking, and risk acceptance coordination.
- Lead and coordinate independent security control assessments, vulnerability management, penetration testing, contingency plan testing, and other required security activities.
- Direct FedRAMP Continuous Monitoring (ConMon) activities, ensuring timely and accurate submission of monthly, quarterly, and annual deliverables, including scan results, incident reports, and compliance attestations.
- Serve as the primary point of contact for sponsoring agencies, 3PAOs, and internal stakeholders on all FedRAMP-related matters.
- Oversee research and response efforts related to government security bulletins, vulnerability advisories, and federal data calls, ensuring timely and accurate responses.
- Ensure accurate and up-to-date system, software, and hardware inventories for government-authorized environments.
- Provide strategic guidance on secure cloud architecture and compliance-driven design decisions across AWS, Azure, and/or GCP environments.
- Evaluate system changes for FedRAMP impact and ensure adherence to change management, configuration management, and incident response requirements.
- Interpret evolving FedRAMP, NIST, and agency-specific requirements and translate them into actionable guidance for technical and business teams.
- Coach and educate internal teams on FedRAMP obligations, audit expectations, and security best practices.
- Identify and implement process improvements to enhance compliance efficiency, reduce risk, and strengthen audit readiness.
- Develop and deliver status reporting and metrics to leadership on authorization posture, risk exposure, and overall compliance health.
- Complete all responsibilities as outlined in the annual performance review and/or goal setting.
- Complete all special projects and other duties as assigned.
- Must be able to perform duties with or without reasonable accommodation.
Other
- Must be able to provide high-speed internet access / connectivity and office setup and maintenance.
- Remaining in a stationary position, often standing or sitting for prolonged periods.
- Repeating motions that may include the wrists, hands and/or fingers.
- Must be able to provide a dedicated, secure work area.
- Must be able to provide high-speed internet access / connectivity and office setup and maintenance.
- No adverse environmental conditions expected.