
Security Engineer – FedRAMP Engineer
Posted 3 days ago

Posted 3 days ago
This is a fully remote position, open to applicants in United States.
• Deliver technical guidance on the implementation of security controls and establish information security procedures for systems and applications.
• Offer programmatic, analytical, technical, and advisory assistance to clients and the supported Cloud Service Providers.
• Conduct pre-assessment tasks, including an in-depth analysis of technology stacks that feature vendor solutions.
• Design secure, compliant, and resilient architectures and solutions.
• Evaluate vendor systems for technical adherence to NIST, FedRAMP, and agency standards.
• Execute comprehensive architecture and technical design reviews across the entire stack for vendor solutions.
• Examine CSP authorization packages, confirm secure design and compliance with FedRAMP and agency standards, identify deficiencies, and provide guidance on risk posture and compliance.
• Facilitate architecture discussions with CSPs to ensure critical control areas fulfill program requirements.
• Create architecture briefing documents for the Government FedRAMP program manager and CISO.
• Review and provide feedback on CSP FedRAMP documentation, including system security plans, policies, procedures, agency guidance, alternative implementations, and risk acceptance documents.
• Collaborate with CSPs to resolve documentation and technology discrepancies.
• Analyze CSP assessments and package submissions following 3PAO audits and prepare package briefings.
• Review vendor security assessment plans, security assessment reports, vulnerability scans, and penetration test results.
• Provide security engineering support alongside the agency FedRAMP Lead.
• Assist with Continuous Monitoring activities, including annual package submissions, significant change proposals, and risk acceptance documents.
• Interpret FedRAMP and agency requirements and advise vendors on expectations, technical specifications, and procedures.
• Monitor updated FedRAMP guidelines, industry best practices, emerging technologies, and Government cybersecurity mandates.
• Suggest implications of updates to the FedRAMP Government lead.
• Conduct security evaluations of technologies intended for use within CSP authorization boundaries.
• Manage relationships for assigned contractor-owned or contractor-operated systems and ensure adherence to agency security and privacy standards.
• Assist stakeholders with IT security tasks to achieve project deadlines.
• Ensure systems are operated, maintained, and decommissioned in line with documented security policies and procedures, including Assessment & Authorization.
• Investigate assigned IT security systems and offer architecture and security recommendations.
• A minimum of five (5) years of experience in the IT Security domain.
• Bachelor’s degree in Computer Science, Information Systems, Mathematics, Engineering, or a related field, OR an additional three years of IT experience.
• Proven experience as a Security Engineer or System Architect analyzing FedRAMP Cloud Service Providers (CSP) architectures and control implementations.
• At least four (4) years of hands-on technical experience as a System Architect or Security Engineer.
• Four (4) years of experience supporting FedRAMP in an engineering or architectural capacity.
• Possession of Security+, CISSP, CISM, CISA, or an equivalent security certification.
• Confidence and thorough understanding to lead discussions with potential vendors.
• Current experience in evaluating third-party security assessment reports.
• Extensive knowledge and experience with NIST Policies, Governance, Security Planning and Architecture, FISMA Compliance, RMF, Incident Analysis, and General Security Best Practices.
• Strong written and verbal communication skills for engaging with customers, internal stakeholders, peers, and public audiences.
• Ability to effectively communicate, both in writing and verbally, with both technical and non-technical stakeholders.
• Excellent communication skills to engage with senior management, junior staff, and business unit (non-technical) customers.
• A quiet and distraction-free workspace with reliable internet connectivity.
• Full attention and availability during working hours.
• Schedule must align with coworkers’ and clients’ core business hours.
• Disclosure of current or future outside employment commitments and written approval for outside employment or professional activities.
• No outside business solicitation or activities during the core business hours of Valiant Solutions and its clients.
• 99% coverage for Medical, Dental, and Vision for Full-time Employees.
• 25% contribution towards Health Coverage for Families and Dependents.
• 100% Paid Short-Term Disability and Life Insurance Policy for Full-time Employees.
• 100% coverage for Certifications.
• 401K Matching up to 4%.
• Paid Time Off.
• Paid Federal Holidays.
• Access to Valiant University – an Online Education and Training Portal.
• Wellness & Fitness Program.
• FSA programs for Medical Costs, Dependent Care, Transit, and Parking.
• Referral Bonuses.
• Work-life balance.
• Opportunities for career development.
• Remote work options.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.