
Senior GRC Engineer – GOV, FedRAMP 20x
Posted Aug 14

Posted Aug 14
This is a fully remote position, open to applicants in United States.
• Lead advisory engagements focused on federal certification for FedRAMP 20x, Assessment & Authorization, and the lifecycles of federal compliance.
• Act as an executive-level trusted consultant, translating intricate federal requirements into understandable business language.
• Oversee, mentor, coach, and manage compliance professionals while ensuring quality standards and accountability in delivery.
• Create and update Security Decision Records, Security Configuration Guides, and compliance artifacts in OSCAL/JSON/YAML formats.
• Integrate CSPM and GRC platforms within agency pipelines following the FedRAMP Collaborative Continuous Monitoring model.
• Perform federal gap assessments, readiness evaluations, and control mapping in accordance with FedRAMP 20x Class A, B, and C requirements.
• Coordinate 3PAO assessments, C3PAO audits, and evaluations by independent assessors.
• Oversee CR26, Significant Change Notifications, and manage the timeline for the Rev5-to-20x transition.
• Take on active portfolio ownership within the first 15 days of employment.
• Represent clients during executive calls while maintaining client engagement, satisfaction, and account retention.
• A minimum of 5 years of direct experience in federal compliance implementation, including NIST SP 800-53, FedRAMP, or Risk Management Framework standards.
• At least 3 years of experience leading multi-project client engagements, fostering executive trust, and managing account retention.
• Strong knowledge of FedRAMP 20x Program Certifications and Rev5 Agency Certifications.
• Practical experience with AWS, Azure, and GCP, particularly with AWS GovCloud or Azure Government regions.
• Proficient in Python, OPA/Rego, infrastructure as code, and policy-as-code tools.
• Hands-on experience working with or for a 3PAO, contributing to security assessment teams, or conducting formal evidence adjudication.
• Current certifications such as CISSP, CISM, CGRC, or Certified Authorization Professional.
• Active cloud certifications like AWS Solutions Architect Associate, Azure Security Engineer, or GCP Associate Cloud Engineer.
• Documented experience managing FedRAMP certification processes and real-time Collaborative Continuous Monitoring workflows.
• Practical experience in authoring or validating machine-readable SSPs, POA&Ms, or KSI evidence using OSCAL, JSON, or YAML schemas.
• Exceptional written and verbal communication skills in English.
• Reliable high-speed internet connection and a professional home office environment.
• Availability for a standard work schedule from 8:00 AM to 5:00 PM US Eastern Time, with some flexibility.
• Willingness and ability to travel locally for occasional onsite meetings, team events, or business activities.
• Participation in live video interviews with the camera on and identity verification during the recruitment and onboarding process is required.
• Employment is contingent upon identity verification and background screening where allowed by law.
• Must have authorization to work in the U.S. without current or future visa sponsorship.
• Opportunities for career development through mentorship and training programs.
• Reimbursement for approved training and certification courses related to the role.
• Competitive base salary.
• Regular performance evaluations tied to merit-based assessments.
• Bonus potential.
• Opportunities for career advancement.
• Flexibility for remote work.
• Adaptable working hours to meet business needs and support global collaboration.
Pfizer
YipitData
Sezzle
Get handpicked remote jobs straight to your inbox weekly.