Responsibilities
- Lead FedRAMP and GovRAMP certification efforts by managing compliance roadmaps, documentation timelines, and coordination with federal authorities.
- Oversee relationships with accredited third-party assessment organizations, guiding initial and recurring evaluations.
- Coordinate assessment scoping, evidence collection, testing logistics, and validation of audit outcomes.
- Direct continuous monitoring activities, ensuring timely delivery of recurring security deliverables such as scans, tests, and plan updates.
- Maintain and update System Security Plans and related compliance documentation on a regular basis.
- Manage the full lifecycle of Plans of Action and Milestones, including tracking, prioritization, and remediation of findings.
- Ensure critical and high-risk findings are resolved within 30 days and moderate findings within 90 days in collaboration with technical teams.
- Support system change management by assessing security impacts and securing approvals from authorizing agencies.
- Partner with product and engineering teams to document and validate system modifications affecting compliance.
- Serve as a primary liaison with federal authorizing officials and government stakeholders.
- Build trust with agency representatives, including CIOs and decision-makers, through consistent communication.
- Deliver regular updates on compliance status and respond to inquiries from federal partners.
- Develop and maintain comprehensive audit packages for federal reviews and reauthorizations.
- Produce System Security Plans, Security Assessment Plans, and risk analysis documentation for audits.
- Streamline compliance processes by identifying automation opportunities for evidence gathering and reporting.
- Enhance efficiency in compliance workflows while preserving audit readiness and control rigor.
- Ensure all compliance activities align with federal regulatory expectations and timelines.
- Maintain oversight of documentation accuracy and completeness for federal certifications.
- Support cross-functional teams in understanding compliance requirements and control implementation.
- Promote a culture of accountability and timeliness in addressing security findings.
Work Arrangement
Remote (Worldwide)
Other
Applicant must be a U.S. Citizen or U.S. National to satisfy federal compliance requirements.