Federal Compliance Manager
Manages FedRAMP compliance for a cloud service provider by implementing security controls, supporting audits and remediation, maintaining SSP documentation, and coordinating authorization activities. Requires 5+ years of IT audit or compliance experience and hands-on FedRAMP ATO leadership.
About the job
Responsibilities
- Collaborate with legal, sales, product, enterprise, engineering, 3PAO, sponsoring agency, and FedRAMP PMO stakeholders.
- Document and implement FedRAMP cloud security control requirements.
- Analyze and support remediation of security control reviews, penetration testing, and vulnerability scan findings.
- Contribute to Plans of Action and Milestones (POA&M) reporting for authorizing agencies.
- Analyze information across teams to manage risks and resolve complex compliance issues.
- Support preparation for internal and external audits.
- Identify, escalate, and track technical and program risks through resolution.
- Develop automated capabilities for evidence collection, control validation, and process execution.
- Maintain technical documentation, including System Security Plans (SSPs), security controls, technical architecture, operational processes, and security protocols.
- Guide teams on FedRAMP and security framework implementation and communicate security and configuration requirements to cloud, application, and enterprise teams.
Requirements
- 5+ years of hands-on experience in IT auditing and/or compliance.
- Recent hands-on experience with the FedRAMP framework.
- Experience leading a Cloud Service Provider through a FedRAMP authorization to operate (ATO) process.
- SaaS audit and compliance experience.
- Experience with technologies hosted in cloud computing environments, such as AWS.
Nice to Have
- Understanding of application security, infrastructure and cloud security, incident response, security compliance, and security certifications.
- Hands-on experience with cloud computing technologies.
- Established connections in the FedRAMP industry and with government agencies.
- Familiarity with international regulatory compliance.
Compensation and Benefits
- Annual base salary: $153,000–$245,000 USD.
- Equity and benefits including health, dental, and vision coverage; retirement contributions; parental and family planning support; mental health and wellness benefits; paid time off; paid sick leave; holidays; and other applicable leave benefits.
- Additional benefits may include recharge days, cell phone and home internet reimbursements, lifestyle spending accounts, and an annual bonus plan for eligible non-sales roles.
Skills
FedRAMP, It Auditing, Security Compliance, Cloud Security, AWS, Saas Compliance, Penetration Testing, Vulnerability Scanning, Poa&M, System Security Plans, Security Controls, Technical Architecture, Incident Response, Audit Preparation, Risk Management
Similar jobs
Security Engineering jobsBuild automated detection, investigation, and incident-response systems for a cloud-native platform. The role requires strong software engineering, security incident investigation, cloud infrastructure, Kubernetes, Linux, networking, and SQL experience, with opportunities to apply LLMs to security operations.
The Application Security Engineer will embed security practices throughout the SaaS software development lifecycle, including threat modeling, automated testing, vulnerability remediation, and incident response. The role requires 5+ years of application or product security experience and expertise with DevSecOps workflows, web applications, and CI/CD automation.
The Cyber Threat Intel Analyst tracks, investigates, attributes, and reports on advanced threats targeting cloud, AI, and developer environments. The role requires at least three years of security or threat research experience and strong technical analysis and writing skills.
The GRC Analyst will operate and mature security and compliance programs across major privacy and security frameworks, supporting risk assessments, access reviews, third-party risk, control monitoring, and audits. The role requires 3–5 years of GRC or information security experience and strong cross-functional communication.
Security Scientist analyzing attacker and user behavior, building data-driven detections, and leading security investigations and design reviews. Requires strong security and anti-abuse knowledge, SQL fluency, scripting proficiency, and experience with distributed data systems and statistical methods.