Responsibilities
- Lead the end-to-end process of StateRAMP readiness, gap remediation, and authorization.
- Provide guidance and oversight for FedRAMP Moderate and TX-RAMP certification efforts.
- Manage communication with third-party assessment organizations (3PAOs) and security consultants.
- Maintain the System Security Plan (SSP), POA&M, and related documentation.
- Design and maintain secure cloud infrastructure (primarily AWS), aligned with NIST 800-53 controls.
- Implement technical safeguards for identity & access management, vulnerability management, and incident response.
- Support DevOps teams in security automation and secure CI/CD pipelines.
- Conduct risk assessments and penetration test planning and review.
- Collaborate with executive leadership on security strategy.
- Develop training materials to raise internal security awareness.
- Ensure alignment between security policies and engineering practices.
Requirements
- Located in the Philippines with night shift work hours (to overlap with U.S. team).
- Proven experience leading or significantly contributing to StateRAMP, FedRAMP, and TX-RAMP compliance efforts.
- Expertise in NIST 800-53, FIPS 199/200, and continuous monitoring frameworks.
- Hands-on experience with AWS security services (IAM, GuardDuty, CloudTrail, Security Hub, etc.).
- Strong understanding of SOC2, GovRAMP, DevSecOps practices, and cloud infrastructure.
- Exceptional written and spoken English skills.
- Bachelor's degree in Cybersecurity, Computer Science, or a related field.
Nice to Have
- Relevant certifications (e.g., CISSP, CCSP, AWS Security Specialty) are a strong plus.
- Experience with audit response, SIEM tools, or zero trust architecture.
Benefits
- Fully remote work environment.
- Work on a product that directly helps thousands of individuals access workforce and educational services.
- Be a founding security leader shaping how we build trust into every layer of our product.
- Play a major role in NIST 800-53 compliance programs and efforts to obtain and maintain a GovRAMP verified status.
- Drive continuous improvement of security controls, policies, and architecture across cloud infrastructure.
- Mentor engineers and advise product teams on secure-by-design principles.
Additional Information
- Must be located in the Philippines.
- Night shift work hours required to overlap with U.S. team.
- Exceptional written and spoken English skills required.