
Government Compliance Technical Specialist
Posted Sep 11

Posted Sep 11
This is a fully remote position, open to applicants in United States, +1 more country.
β’ Lead the technical compliance build activities for FedRAMP 20x readiness, which includes interpreting Key Security Indicators (KSIs), defining evidence strategies, and coordinating machine-readable compliance outputs.
β’ Oversee the daily management and execution of FedRAMP Moderate/Class C continuous monitoring, managing deliverables, POA&M tracking, and deviation requests.
β’ Create and maintain System Security Plans (SSPs), Security Decision Records (SDRs), and other compliance documentation in formats suitable for both human and machine readability.
β’ Manage the tracking of findings and remediation across various government compliance programs.
β’ Collaborate with engineering, security, and cloud operations teams to gather evidence, validate control implementation, and address compliance gaps.
β’ Provide support for GovRAMP, TX-RAMP, IRAP, and other governmental or public-sector compliance programs.
β’ Cultivate relationships with Third Party Assessment Organizations (3PAOs) and agency stakeholders.
β’ Monitor and report on the health of government programs.
β’ Stay updated on FedRAMP policy changes and adapt the compliance roadmap accordingly.
β’ Automate the processes for evidence collection pipelines and indicator health tracking.
β’ Assist in managing government compliance workstreams alongside product, security, and engineering teams.
β’ At least 3 years of experience in FedRAMP program management and technical compliance.
β’ 4β7 years of experience in information security, compliance, or Governance, Risk, and Compliance (GRC).
β’ Proven ability to manage a FedRAMP Moderate program, which includes SSP authorship, Continuous Monitoring (ConMon) execution, POA&M management, and coordination with assessors.
β’ In-depth knowledge of NIST SP 800-53 controls and their practical application in cloud environments.
β’ Strong understanding of FedRAMP 20x concepts, such as Key Security Indicators (KSIs), machine-readable evidence frameworks, and continuous assessment models.
β’ Ability to interpret and define KSIs in relation to BeyondTrust's compliance posture.
β’ Capable of coordinating across engineering, infrastructure, legal, and operations teams to gather evidence and ensure remediation is completed.
β’ Experience in building or supporting automated compliance evidence pipelines.
β’ Familiarity with GRC tools for managing findings, collecting evidence, and tracking programs.
β’ Competence in managing multiple concurrent workstreams, identifying blockers, and maintaining consistent delivery schedules.
β’ Excellent written and verbal communication skills to convey technical compliance information to diverse audiences.
β’ A culture that promotes flexibility, trust, and continuous learning.
β’ Supportive employee environment with an emphasis on inclusivity.
β’ Initiatives focused on diversity and inclusion.
RTX
EnergyHub
Johnson & Johnson
Johnson & Johnson
Get handpicked remote jobs straight to your inbox weekly.