
Product Security Analyst III
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in United States.
• Oversee the FedRAMP Continuous Monitoring (ConMon) processes and guarantee effective monthly reviews with ExtraHop and agency stakeholders; manage asset inventory, vulnerability scan results, and the Plan of Action & Milestones (POA&M) documentation.
• Administer vulnerability detection and response pipelines, which encompass tools, reporting, and tracking.
• Direct the vulnerability management lifecycle: including triage, reporting, coordination with system owners, and tracking remediation efforts.
• Create and deliver vulnerability findings and responses to both internal and external stakeholders, including customers.
• Partner with the Director of Product Security to address customer and pre-sales security inquiries.
• Aid in fulfilling compliance requirements for various standards (e.g., CSA STAR, ISO 27001, DoDIN APL, NIAP, FIPS, CMMC, IL4), supporting gap assessments and facilitating audits, including the coordination of evidence collection and submission.
• Formulate a product security compliance roadmap and coordinate essential activities across the organization to meet milestones.
• Collaborate with Product Security team members to develop and enhance standards, policies, procedures, documentation, and training.
• Utilize security information & event management (SIEM) tools and other systems to conduct security investigations.
• Execute and/or lead security incident response activities.
• Engage in an on-call rotation with occasional after-hours paging to assess prioritized security detections.
• A minimum of 5 years of experience in cybersecurity, concentrating on compliance frameworks such as FedRAMP, SOC 2, or similar.
• At least 2 years of hands-on experience specifically managing compliance programs, security assessments, or cloud security initiatives.
• Bachelor's degree in a relevant field such as Cybersecurity, Computer Science, Information Systems, Engineering, or another technical discipline.
• Direct experience with the FedRAMP compliance framework, including security control requirements, documentation, and assessment methodologies.
• Technical expertise in web application security and cloud security, including best practices and controls for cloud-based environments.
• Proficient in security tools, including vulnerability scanners, ticketing systems (e.g., Jira), compliance reporting platforms, and SIEM tools.
• Outstanding analytical skills to effectively address and resolve security and compliance challenges.
• Demonstrated ability to convey complex security concepts to both technical and non-technical audiences.
• All R&D employees are required to attend 2 mandatory in-person events annually. These events typically take place in our offices in downtown Seattle and last 4-5 days each.
• Must be a U.S. citizen or national, a U.S. permanent resident (current Green Card holder), or lawfully admitted into the U.S. as a refugee or granted asylum.
• Health, Dental, and Vision Benefits.
• Flexible PTO, Sick Time Prorated Based on Date of Hire, and All Federal Holidays (US Only), plus 3 Days of Paid Volunteer Time.
• Non-Commissioned Positions may qualify to participate in the Annual Discretionary Bonus Plan.
• FSA and Dependent Care Accounts, along with EAP, where applicable.
• Educational Reimbursement.
• 401k with Employer Match or Pension, where applicable.
• Pet Insurance (US Only).
• Parental Leave (US Only).
• Hybrid and Remote Work Model.
Solo Network
Agile Defense
EMCOR Group, Inc.
CoE | Centro de Excelência Votorantim
Get handpicked remote jobs straight to your inbox weekly.