
Principal, Public Sector SecOps, GRC
Posted Jul 29

Posted Jul 29
This is a fully remote position, open to applicants in United States.
• Act as the primary leader in security and compliance for all public sector projects.
• Direct the design, execution, and management of a cohesive security framework that complies with NIST 800-53 Rev. 5 controls, FedRAMP High authorizations, GovRAMP, CMMC, and evolving SLED requirements.
• Ensure prompt threat mitigation, efficient audit processes, and secure delivery of cloud services to government entities.
• Prepare and submit Monthly Continuous Monitoring (ConMon) reports, which include vulnerability assessments, POA&M trackers, and asset inventories.
• Supervise threat hunting and vulnerability remediation efforts to guarantee compliance with rigorous federal timelines.
• Elevate unresolved vulnerabilities and initiate the creation of a Plan of Action and Milestones (POA&M) within 7 days of identifying an issue.
• Organize and oversee Annual 3PAO Security Assessments, which encompass penetration testing and red team activities.
• Maintain a compliant, secure repository for storing, accessing, and provisioning security packages and artifacts.
• Oversee third-party entities performing public sector security tasks and provide project management support for these initiatives.
• Serve as the System Steward for the VA-F package in eMASS.
• Ensure accurate documentation for marketplace listings is submitted and maintained.
• Manage actionable incident response testing biannually.
• Handle background checks and reinvestigations for personnel who require system access.
• Keep current diagrams of the SaaS platform architecture and submit Security Change Requests (SCRs).
• Contribute to non-FedRAMP commercial compliance frameworks.
• Offer security and compliance advice to IT, engineering, and development teams.
• Identify, assess, and implement GRC and SecOps tools.
• Assist in addressing customer security assessments.
• Mentor junior personnel or members of cross-functional teams.
• Support the development of business continuity plans, disaster recovery documentation, and live operational exercises.
• Bachelor's degree in computer science, information technology, or cybersecurity.
• Active Certified Information Systems Security Professional (CISSP) and Project Management Professional (PMP) certification.
• Must undergo a Public Trust Background Investigation with a favorable suitability determination.
• Over 8 years of experience in information security governance, risk, and compliance, with a minimum of 5 years dedicated to supporting FedRAMP High, FISMA, NIST SP 800-53 Rev. 5, or RMF.
• At least 5 years in the ISSM or ISSO role, managing the security package for federal government high-impact systems.
• A minimum of 5 years of experience in managing or assisting security assessments with Third Party Assessment Organizations (3PAOs).
• Over 3 years of hands-on experience with GRC platforms (e.g., RSA Archer, ServiceNow GRC, OneTrust) and vulnerability management platforms (e.g., Tenable, Qualys, Rapid7).
• At least 2 years of direct experience mapping controls and leading assessments for GovRAMP, CMMC (Level 2+), and StateRAMP/SLED requirements.
• Over 2 years of experience with identity and access management systems (e.g., Okta, Azure AD) for governance over access control.
• Proven experience working in cloud environments such as AWS GovCloud or Azure Government, including cloud-native security controls.
• Proficient in AWS CLI, PowerShell, and scripting automated compliance tasks in both Windows and Linux systems tools, Nessus Pro, Burp Suite, Splunk, AWS IAM, Jira, FortiGate firewalls, eMASS, Box.com for Gov, and Okta for Gov Identity Provider.
• Strong analytical skills to evaluate complex security risks, interpret compliance requirements, and assess technical vulnerabilities.
• Capable of building and enhancing repeatable, auditable processes for security governance, risk management, and compliance activities.
• Excellent communication skills to effectively engage with both technical and non-technical stakeholders, including auditors, developers, and executive leadership.
• Ability to implement continuous monitoring and assessment programs to detect and address security threats in real-time, maintaining a proactive SecOps approach.
• Annual performance bonus
• Employee Stock Purchase Plan (ESPP)
• Enhanced time off packages
Spektrum Group
FICO
SafelyYou
Get handpicked remote jobs straight to your inbox weekly.