Remotery

Senior Security Engineer I – GRC FedRAMP

Posted Jul 17

This is a fully remote position, open to applicants in United States.

📋 Description

• Take charge of FedRAMP and GovRAMP (formerly StateRAMP) certifications and roadmaps: Direct the overarching strategy for securing and sustaining federal authorizations, which includes package management, compliance schedules, and coordination with authorities.

• Oversee relationships and assessments with 3PAOs: Collaborate with accredited third-party assessment organizations to carry out initial assessments and yearly re-assessments. Manage scoping, evidence preparation, testing coordination, and validation of results.

• Direct the execution of continuous monitoring (ConMon): Supervise the delivery of monthly, annual, and event-driven FedRAMP deliverables such as vulnerability scans, penetration tests, system security plan updates, and compliance reports.

• Manage the Plans of Action and Milestones (POA&M) processes: Be responsible for identifying, prioritizing, tracking, and addressing findings. Ensure timely closure of Critical (30 days), High (30 days), and Moderate (90 days) findings while coordinating with engineering and security teams.

• Coordinate major change requests and system modifications: Collaborate with product and engineering teams to document, scope, assess, and secure agency approval for system changes that affect security controls or compliance status.

• Engage with authorizing officials and federal agencies: Establish and maintain relationships with government sponsors, CIOs, and agency decision-makers. Provide regular updates, address inquiries, and demonstrate compliance with authorizations.

• Prepare thorough assessment packages: Lead the creation of System Security Plans (SSP), Security Assessment Plans (SAP), risk exposure tables, and the necessary documentation for audits.

• Promote compliance automation and efficiency: Identify opportunities to automate evidence collection, streamline reporting, and minimize manual efforts while ensuring rigor and auditability.


⛳️ Requirements

• A minimum of 5 years of practical experience with FedRAMP and/or GovRAMP (StateRAMP) programs, including direct involvement in securing and maintaining ATOs.

• Demonstrated experience working with accredited 3PAOs: You have coordinated initial assessments, handled annual re-assessments, supplied evidence packages, and navigated test results and findings.

• A degree in Computer Science, Computer Engineering, Cybersecurity, or a related field, or equivalent practical experience.

• In-depth understanding of FedRAMP continuous monitoring requirements: Comprehensive knowledge of monthly deliverables, annual assessment cycles, POA&M management, vulnerability scanning, and penetration testing needs, as well as compliance reporting schedules.

• Strong knowledge of NIST 800-53 controls: Proficiency with control baselines, supplemental overlays (ITAR, CJIS, HIPAA, etc.), impact level determination, and control selection for various system types.

• Skills in project management and stakeholder coordination: Experience in managing complex, multi-month compliance initiatives with numerous dependencies, stakeholders, and tight timelines.

• Technical expertise in cloud security and compliance: Practical knowledge of AWS/GCP/Azure, cloud security controls, identity and access management, encryption, logging, and incident response—sufficient to understand system architecture and control implementations.

• Exceptional documentation and communication abilities: Capability to write clear System Security Plans, coordinate among multiple stakeholders, and convey technical and compliance concepts to government audiences.

• Understanding of federal procurement and contracting: Familiarity with how government agencies acquire and authorize cloud services, along with the role of compliance in federal go-to-market strategies.

• US Person Status: Must be a U.S. Citizen or U.S. National to fulfill federal compliance requirements.


🏝️ Benefits

• Employer-subsidized medical, vision, and dental coverage for full-time employees.

• 401k Match to assist you in saving for your future (50% of your contribution up to the first 6% of your eligible pay).

• Monthly stipend to enhance your work and productivity.

• Flexible Time Away Program, in addition to Sick Time Off.

• US employees are automatically enrolled in Smartsheet-sponsored life insurance, short-term, and long-term disability plans.

• US employees enjoy 12 paid holidays each year.

• Up to 24 weeks of Parental Leave.

• A personal paid Volunteer Day to support our community.

• Opportunities for professional growth and development, including access to Udemy online courses.

• Company-funded perks, which include a counseling membership, local retail discounts, and your own personal Smartsheet account.

• Teleworking options available from any registered location in the U.S. (specific to the role).

People also viewed

GuidePoint Security2 days ago

Senior Security Entra Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Redpanda Data2 days ago

Staff Security Engineer

US flagUnited States, +1 more stateFull-timeCybersecurity / Security Engineer$210k – $247k/year
ApplyView job
CyberSheath2 days ago

Cloud Security Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$85k – $100k/year
ApplyView job
Akamai Technologies2 days ago

Senior Security Sales Specialist

US flagCalifornia OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
CloudLinux2 days ago

AI Pipeline Engineer – Security Automation Platform

PL flagPoland, +4 more statesFull-timeCybersecurity / Security Engineer
ApplyView job
Oxfam America2 days ago

Manager, Cybersecurity and Infrastructure

US flagMassachusetts OnlyFull-timeCybersecurity / Security Engineer$105k – $115k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers