
Security Engineer – FedRAMP
Posted Jun 25

Posted Jun 25
This is a fully remote position, open to applicants in United States.
• Conduct thorough architecture and technical design assessments on the complete stack for vendor solutions.
• Perform architecture evaluations of Cloud Service Providers (CSPs) authorization packages to ensure secure design, compliance with FedRAMP and agency standards, identify deficiencies, and advise the FedRAMP Government Lead on overall risk posture and adherence.
• Facilitate architecture interviews with CSPs to confirm that all essential control areas within the architecture are configured to fulfill program requirements.
• Create architecture briefing documents to update the Government FedRAMP program manager and CISO regarding CSP compliance with FedRAMP requirements, technical capabilities, and any issues identified during the review process.
• Conduct a thorough review and provide feedback on CSPs' FedRAMP documentation, which includes but is not limited to system security plans, policies and procedures, supplementary agency guidance documents, alternative implementation strategies, and risk acceptance documents.
• Collaborate with CSPs to resolve and address any documentation and technology discrepancies found during the assessment.
• Execute a detailed review of CSPs' assessments and package submissions post 3PAO audits, preparing a package briefing for the Government FedRAMP program manager and agency CISO. Artifacts include vendor security assessment plans, security assessment reports, vulnerability scans, penetration tests, and more.
• Work closely with the agency FedRAMP Lead and provide security engineering support.
• Assist with Continuous Monitoring activities, including reviewing annual package submissions, evaluating significant change proposals, and assessing risk acceptance documents.
• Interpret FedRAMP and other agency guidelines, offering vendors advice on expectations, technical requirements, and procedures.
• Remain updated on the latest FedRAMP guidance, industry best practices, emerging technologies, and Government cybersecurity directives, providing recommendations to the FedRAMP Government lead regarding potential impacts.
• Conduct security assessments of technologies for consideration within CSPs' authorization boundaries.
• Manage and oversee relationships for assigned systems that may be contractor-owned or contractor-operated, ensuring compliance with agency security and privacy regulations.
• Support stakeholders with IT security-related tasks to ensure project timelines are achieved.
• Guarantee that all systems are operated, maintained, and disposed of in accordance with documented security policies and procedures, including but not limited to Assessment & Authorization (A&A).
• Investigate assigned IT security systems to provide insights into IT security architectures and recommendations for those systems.
• A minimum of five (5) years of experience in the IT Security sector.
• A Bachelor’s degree in Computer Science, Information Systems, Mathematics, Engineering, or a related discipline, OR an additional three years of IT experience is required.
• Direct experience as a Security Engineer or System Architect analyzing FedRAMP Cloud Service Providers (CSP) architectures and control implementations (e.g., 3PAO, FedRAMP program at another federal agency, etc.).
• Four (4) years of practical technical experience as a System Architect or Security Engineer.
• Four (4) years of experience supporting FedRAMP in a role as an Engineer or Architect.
• Security+, CISSP, CISM, CISA, or equivalent security certification.
• Confidence and a comprehensive understanding necessary to lead discussions with potential vendors.
• Recent experience in reviewing third-party security assessment reports.
• In-depth knowledge and experience with NIST Policies, Governance, Security Planning and Architecture, FISMA Compliance, RMF, Incident Analysis, and General Security Best Practices.
• Excellent written and verbal communication skills to effectively support customers, internal stakeholders, peers, and public audiences.
• Ability to communicate, both written and verbally, with both technical and non-technical audiences.
• Strong communication skills to engage with senior managers, junior staff, and business unit (non-technical) customers.
• Valiant covers 99% of the Medical, Dental, and Vision Insurance for Full-time Employees.
• Valiant contributes 25% towards Health Coverage for Families and Dependents.
• 100% Paid Short-Term Disability and Life Insurance Policy for Full-time Employees.
• 100% Paid Certifications.
• 401K Matching up to 4%.
• Paid Time Off.
• Paid Federal Holidays.
• Valiant University – Online Education and Training Portal.
• Wellness & Fitness Program.
• FSA programs for Medical Costs, Dependent Care, Transit, and Parking.
• Referral Bonuses.
GuidePoint Security
Redpanda Data
CyberSheath
Akamai Technologies
Get handpicked remote jobs straight to your inbox weekly.