
Senior Security Engineer I – GRC FedRAMP
Posted Jul 17

Posted Jul 17
This is a fully remote position, open to applicants in United States.
• Take charge of FedRAMP and GovRAMP (formerly StateRAMP) certifications and roadmaps: Direct the overarching strategy for securing and sustaining federal authorizations, which includes package management, compliance schedules, and coordination with authorities.
• Oversee relationships and assessments with 3PAOs: Collaborate with accredited third-party assessment organizations to carry out initial assessments and yearly re-assessments. Manage scoping, evidence preparation, testing coordination, and validation of results.
• Direct the execution of continuous monitoring (ConMon): Supervise the delivery of monthly, annual, and event-driven FedRAMP deliverables such as vulnerability scans, penetration tests, system security plan updates, and compliance reports.
• Manage the Plans of Action and Milestones (POA&M) processes: Be responsible for identifying, prioritizing, tracking, and addressing findings. Ensure timely closure of Critical (30 days), High (30 days), and Moderate (90 days) findings while coordinating with engineering and security teams.
• Coordinate major change requests and system modifications: Collaborate with product and engineering teams to document, scope, assess, and secure agency approval for system changes that affect security controls or compliance status.
• Engage with authorizing officials and federal agencies: Establish and maintain relationships with government sponsors, CIOs, and agency decision-makers. Provide regular updates, address inquiries, and demonstrate compliance with authorizations.
• Prepare thorough assessment packages: Lead the creation of System Security Plans (SSP), Security Assessment Plans (SAP), risk exposure tables, and the necessary documentation for audits.
• Promote compliance automation and efficiency: Identify opportunities to automate evidence collection, streamline reporting, and minimize manual efforts while ensuring rigor and auditability.
• A minimum of 5 years of practical experience with FedRAMP and/or GovRAMP (StateRAMP) programs, including direct involvement in securing and maintaining ATOs.
• Demonstrated experience working with accredited 3PAOs: You have coordinated initial assessments, handled annual re-assessments, supplied evidence packages, and navigated test results and findings.
• A degree in Computer Science, Computer Engineering, Cybersecurity, or a related field, or equivalent practical experience.
• In-depth understanding of FedRAMP continuous monitoring requirements: Comprehensive knowledge of monthly deliverables, annual assessment cycles, POA&M management, vulnerability scanning, and penetration testing needs, as well as compliance reporting schedules.
• Strong knowledge of NIST 800-53 controls: Proficiency with control baselines, supplemental overlays (ITAR, CJIS, HIPAA, etc.), impact level determination, and control selection for various system types.
• Skills in project management and stakeholder coordination: Experience in managing complex, multi-month compliance initiatives with numerous dependencies, stakeholders, and tight timelines.
• Technical expertise in cloud security and compliance: Practical knowledge of AWS/GCP/Azure, cloud security controls, identity and access management, encryption, logging, and incident response—sufficient to understand system architecture and control implementations.
• Exceptional documentation and communication abilities: Capability to write clear System Security Plans, coordinate among multiple stakeholders, and convey technical and compliance concepts to government audiences.
• Understanding of federal procurement and contracting: Familiarity with how government agencies acquire and authorize cloud services, along with the role of compliance in federal go-to-market strategies.
• US Person Status: Must be a U.S. Citizen or U.S. National to fulfill federal compliance requirements.
• Employer-subsidized medical, vision, and dental coverage for full-time employees.
• 401k Match to assist you in saving for your future (50% of your contribution up to the first 6% of your eligible pay).
• Monthly stipend to enhance your work and productivity.
• Flexible Time Away Program, in addition to Sick Time Off.
• US employees are automatically enrolled in Smartsheet-sponsored life insurance, short-term, and long-term disability plans.
• US employees enjoy 12 paid holidays each year.
• Up to 24 weeks of Parental Leave.
• A personal paid Volunteer Day to support our community.
• Opportunities for professional growth and development, including access to Udemy online courses.
• Company-funded perks, which include a counseling membership, local retail discounts, and your own personal Smartsheet account.
• Teleworking options available from any registered location in the U.S. (specific to the role).
GuidePoint Security
Redpanda Data
CyberSheath
Akamai Technologies
Get handpicked remote jobs straight to your inbox weekly.