
FedRAMP Engineer
Posted Jul 17

Posted Jul 17
This is a fully remote position, open to applicants in United States.
• Conduct thorough architecture and technical design evaluations on the complete stack of vendor solutions.
• Carry out architecture assessments of Cloud Service Providers (CSPs) authorization packages to verify secure design, adherence to FedRAMP and agency requirements, identify deficiencies, and advise the FedRAMP Government Lead on overall risk posture and compliance.
• Lead and facilitate architecture interviews with CSPs to ensure all essential control areas throughout the architecture are structured to fulfill program requirements.
• Create architecture briefing documents to update the Government FedRAMP program manager and CISO on CSP compliance with FedRAMP program standards, technical capabilities, and any concerns identified during material review.
• Conduct comprehensive reviews and provide comments on CSPs' FedRAMP documentation, including but not limited to system security plans, policies and procedures, supplemental agency guidance documents, alternative implementation and risk acceptance documents, etc.
• Collaborate with CSPs to resolve and address any documentation and technology discrepancies identified during the review process.
• Perform a thorough review of CSPs' assessments and package submissions following 3PAO audits and prepare a briefing package for the Government FedRAMP program manager and agency CISO. Artifacts include, but are not limited to, vendor security assessment plans, security assessment reports, vulnerability scans, penetration tests, etc.
• Partner with the agency FedRAMP Lead and offer security engineering services.
• Support Continuous Monitoring activities including but not limited to reviewing annual package submissions, scoping significant change proposals, and evaluating risk acceptance documents.
• Interpret FedRAMP and other agency requirements and provide guidance to vendors on expectations, technical requirements, and processes.
• Stay updated on the latest FedRAMP guidance, industry best practices, emerging technologies, and Government cybersecurity directives, and offer recommendations to the FedRAMP Government lead regarding their impacts.
• Conduct security evaluations of technologies for consideration within CSPs' authorization boundaries.
• Manage and oversee relationships for assigned systems that may be contractor-owned or contractor-operated, ensuring vendor compliance with agency security and privacy requirements.
• Assist stakeholders with IT security-related tasks to ensure project timelines are adhered to.
• Ensure all systems are operated, maintained, and disposed of in accordance with documented security policies and procedures, including but not limited to Assessment & Authorization (A&A).
• Investigate assigned IT security systems to provide insights into IT security architectures and recommendations for those systems.
• A minimum of five (5) years of experience in the IT Security sector.
• A Bachelor’s degree in Computer Science, Information Systems, Mathematics, Engineering, or a related discipline, OR an additional three years of IT experience is required.
• At least four (4) years of hands-on technical experience as a System Architect or Security Engineer.
• Four (4) years of experience supporting FedRAMP Security+, CISSP, CISM, CISA, or an equivalent security certification.
• Direct experience as a Security Engineer or System Architect analyzing FedRAMP Cloud Service Providers (CSP) architectures and control implementations (e.g., 3PAO, FedRAMP program in another federal agency, etc.).
• Confidence and a comprehensive understanding to lead discussions with potential vendors.
• Current experience in reviewing third-party security assessment reports.
• Extensive knowledge and experience with NIST Policies, Governance, Security Planning and Architecture, FISMA Compliance, RMF, Incident Analysis, and General Security Best Practices.
• Strong written and verbal communication skills to support customers, internal stakeholders, peers, and public audiences.
• Ability to communicate effectively, both in writing and orally, to technical and non-technical stakeholders.
• Excellent communication skills to interact with senior management, junior staff, and business unit (non-technical) customers.
• Valiant covers 99% of the Medical, Dental, and Vision premiums for Full-time Employees.
• Valiant contributes 25% towards Health Coverage for Families and Dependents.
• 100% Paid Short-Term Disability and Life Insurance Policy for Full-time Employees.
• 100% Paid Certifications.
• 401K Matching up to 4%.
• Paid Time Off.
• Paid Federal Holidays.
• Access to Valiant University – an Online Education and Training Portal.
• Wellness & Fitness Program.
• FSA programs available for Medical Costs, Dependent Care, Transit, and Parking.
• Referral Bonuses.
3M Consultancy
Jones Lang LaSalle Americas, Inc.
Get handpicked remote jobs straight to your inbox weekly.