Senior Public Sector Compliance Manager

New
M
Menlo SecurityCybersecurity compliance
US - Distributed; Workplace: RemoteFull-TimeManager
Salary not disclosed
Apply NowOpens the employer's application page

Job Details

Experience
2–3 years of experience in information security compliance or risk management, preferably in a FedRAMP or FISMA-regulated environment.
Required Skills
Risk Management

Requirements

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field, or equivalent experience.
  • 2–3 years of experience in information security compliance or risk management; FedRAMP or FISMA-regulated experience is preferred.
  • Strong knowledge of NIST SP 800-53, FedRAMP Moderate/High baselines, and the FedRAMP authorization process.
  • Experience with security documentation such as SSP, POA&M, SAR, and SAP, and with governance tools.
  • Familiarity with vulnerability scanning tools such as Nessus or Qualys and interpreting security findings.
  • Strong analytical and problem-solving skills.
  • Ability to work independently and manage multiple priorities.
  • Ability to collaborate across teams and explain technical issues to non-technical stakeholders.
  • Experience with a 3PAO or federal agency is preferred.
  • FedRAMP or NIST security control implementation experience in AWS, Azure, or Google Cloud is preferred.
  • Security certifications such as CISSP, CISA, CAP, or CompTIA Security+ are preferred.

Responsibilities

  • Develop and govern a compliance roadmap to maintain CMMC certification and mitigate risks across internal and external systems.
  • Drive federal project initiatives and support systems and processes meeting DoD Impact Level 6 authorization requirements.
  • Support FedRAMP Moderate authorization and reauthorization, including developing, reviewing, and maintaining system security documentation.
  • Map and analyze security controls against FedRAMP Moderate/High baselines and NIST SP 800-53 controls.
  • Assist with implementing and monitoring security controls for FedRAMP-authorized systems.
  • Coordinate with engineering, operations, and DevSecOps to integrate security requirements into system design and operation.
  • Maintain continuous monitoring documentation and support periodic assessments, penetration tests, and vulnerability scans.
  • Coordinate with 3PAOs, government customers, and internal stakeholders on audits and assessments.
  • Track POA&M items to closure and manage FedRAMP platform administration, training, and recurring authorization requirements.
  • Provide compliance reporting, metrics, and risk analysis to management, and monitor changes to FedRAMP requirements and related guidance.
View Full Description & ApplyYou'll be redirected to the employer's site
View details
Apply Now