Responsibilities
- Serve as the technical lead for FedRAMP High and DoD IL5 compliance, including continuous monitoring, control validation, and authorization activities
- Implement, operate, and validate AWS security controls aligned with NIST 800-53 High baseline and DoD SRG requirements
- Partner with cloud and platform engineering teams to review architectures, challenge non-compliant designs, and guide secure implementation
- Author, manage, and track POA&Ms, including root cause analysis, remediation planning, and reporting to 3PAOs, sponsoring agencies, and DoD stakeholders
- Coordinate vulnerability remediation and patching across AWS infrastructure and supporting services
- Lead audit readiness and evidence collection efforts, including improving automation for recurring FedRAMP and IL5 deliverables
- Provide secondary technical support for SOC 2, PCI DSS, and ISO 27001 compliance initiative
Requirements
- Bachelor’s degree in Information Security, Computer Science, Engineering, or equivalent practical experience
- 7+ years of experience in cloud security or security compliance engineering
- 5+ years of direct, hands-on experience supporting FedRAMP High environments
- Strong working knowledge of NIST 800-53 controls, DoD SRG requirements, and continuous monitoring processes
- 5+ years of hands-on experience securing AWS environments, including IAM, logging and monitoring, encryption, and vulnerability management
- 5+ years of experience working directly with 3PAOs, auditors, and government stakeholders
- Demonstrated ability to translate regulatory requirements into practical, enforceable technical controls
- Due to the role’s involvement with GovCloud and DoD environments, candidates must be a U.S. Person.
Nice to Have
- Direct experience operating in DoD IL5 environments
- AWS Security Specialty or AWS Solutions Architect certification
- CISSP, SANS, or equivalent security certification
- Experience supporting SOC 2, PCI DSS, or ISO 27001 in cloud-native environments
Benefits
- Medical, Dental & Vision (inclusive of domestic partnerships)
- Employer Paid Life Insurance & Employee/Spouse/Child Supplemental life
- Voluntary Short/Long Term Disability Insurance
- 401K (Roth/Traditional)
- A generous PTO plan that celebrates your commitment and seniority (including paid Bereavement/Jury Duty, etc)
- Above market annual bonuses
Additional Information
- Classification: Exempt
- Due to the role’s involvement with GovCloud and DoD environments, candidates must be a U.S. Person.