
Senior Consultant – FedRAMP 20X Advisory
Posted Aug 28

Posted Aug 28
This is a fully remote position, open to applicants in United States.
• Lead initiatives assessing client firms against regulatory and industry standards, requirements, and security best practices.
• Provide gap analyses and comprehensive program recommendations for regulatory or compliance milestones.
• Prepare clients for FedRAMP 20x Vulnerability Detection & Response (VDR).
• Offer guidance on FIPS 140-2/140-3 encryption.
• Create and maintain FedRAMP authorization boundary diagrams.
• Enhance management-plane tooling, including SIEM and vulnerability management solutions.
• Generate Security Decision Records (SDRs) and Certification Package Overviews (CPOs).
• Design and implement client solutions aligned with FedRAMP 20x Key Security Indicators.
• Develop automated, code-based validation methods utilizing scripts, APIs, and Infrastructure-as-Code.
• Monitor FedRAMP 20x releases and Change Requests, translating guidance into actionable client recommendations.
• Utilize AI/ML tools to catalog Key Security Indicators and assist in navigating evolving requirements.
• Counsel cloud service providers on creating machine-readable compliance visibility.
• Foster positive collaborative relationships with clients and stakeholders.
• Guide clients on compliance activities and desired outcomes.
• Lead the preparation and review of documentation and artifacts, conduct procedure evaluations, and facilitate client interviews.
• Ensure timely delivery of quality products and services within allocated hours.
• Engage in continuous professional development and pursue industry-specific certifications.
• Escalate client and project issues to management as necessary.
• Mentor team members to enhance their skills.
• Maintain communication with clients throughout the entire engagement process.
• Bachelor's Degree or equivalent practical experience.
• Over 6 years of professional services experience.
• More than 4 years of FedRAMP experience or background in cloud security engineering.
• Solid understanding of FedRAMP 20x Key Security Indicators (KSIs).
• Proficient in utilizing AI tools to decipher and organize regulatory requirements.
• An active GitHub or portfolio showcasing coding/cloud automation projects.
• Competence in the Microsoft 365 product suite.
• Capability to work independently with minimal supervision.
• Quick to evaluate new and innovative technologies and concepts.
• Strong relationship-building skills with team members and clients.
• Comfortable working in a fast-paced team environment.
• Strong technical proficiency in cloud security.
• Experience with Infrastructure-as-Code (Terraform) and scripting/automation.
• Aspiring to achieve AWS Solutions Architect or Security Specialty, or equivalent certifications in Azure/GCP.
• Familiarity with testing in cloud environments, including prior 3PAO experience.
• Experience in writing scripts or creating integrations for continuous compliance monitoring/validation.
• Keen interest in advancing cloud engineering skills in AWS, Azure, or GCP.
• Must be legally authorized to work in the United States without sponsorship.
• Willingness to travel to client sites as needed.
• Medical insurance.
• Dental insurance.
• Vision insurance.
• 401K plan with a 4% match.
• Company-paid short-term disability.
• Company-paid long-term disability.
• Company-paid AD&D and life insurance.
• Flexible time off.
• Annual bonuses.
• Training stipends.
• Certification reimbursements.
• Access to over 30,000 free online training courses.
• Personal cell phone allowance.
• Stipend for new hires and annual home office expenses.
• Spot awards.
• Eleven paid holidays.
Mercor
Mercor
Solvenio GmbH
Get handpicked remote jobs straight to your inbox weekly.