Lead FedRAMP Security Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+3 more
Job description
Experteer Overview As Lead FedRAMP Security Engineer, you will own enterprise-wide FedRAMP security controls across cloud environments and security tooling. You translate FedRAMP and NIST 800-53 requirements into implemented, evidence-ready controls and runbooks. You’ll partner with Cloud Security, Engineering, Compliance, and government stakeholders to ensure consistent control coverage and continuous monitoring. This senior IC role offers meaningful program ownership and impact on secure, compliant cloud delivery. Compensation / Benefits * Lead enterprise-wide implementation and operation of FedRAMP security controls across cloud infrastructure, security tooling, logging, vulnerability management, and incident response processes * Own the health and coverage of FedRAMP technologies (EDR, vulnerability scanning, CSPM, container scanning, SIEM, alerting, and evidence workflows) * Design, maintain, and validate centralized log ingestion from cloud platforms, operating systems, apps, containers, and security tools into the SIEM * Drive vulnerability triage, remediation tracking, risk reduction reporting, and POA&M inputs with Engineering, Infrastructure, Compliance, and vulnerability management teams * Develop and maintain technical runbooks, SOPs, control implementation evidence, and operational procedures for FedRAMP security operations * Support FedRAMP Continuous Monitoring deliverables (vulnerability scans, POA&M updates, configuration reports, incident notifications, security metrics, control evidence) * Partner with product and infrastructure teams to understand architecture, deployment patterns, inherited controls, and shared responsibility * Serve as a senior technical point of contact for FedRAMP audits, 3PAO assessments, agency reviews, and government stakeholder discussions Tasks * 8+ years of experience in cloud security, security engineering, infrastructure security, security operations, or related roles * 4+ years of hands-on experience with FedRAMP-authorized or authorization-boundary cloud environments (prefer Moderate or High) * Strong knowledge of FedRAMP, NIST SP 800-53, Continuous Monitoring, POA&M management, control implementation, and audit evidence expectations * Hands-on experience with AWS GovCloud and commercial AWS; Kubernetes, EKS, Lambda, and cloud-native security controls preferred * Experience operating or integrating EDR, SIEM, vulnerability scanning, container scanning, CSPM, logging, alerting, and security monitoring technologies * Experience managing CrowdStrike (EDR, Cloud Security, NG-SIEM) in commercial or GovCloud environments * Ability to translate FedRAMP requirements into technical designs, control implementations, procedures, and evidence-ready artifacts * Experience coordinating incident response, vulnerability remediation, audit preparation, control validation, and cross-functional FedRAMP program activities * Strong communication skills for explaining controls, remediation, and audit findings to engineers, executives, auditors, and government stakeholders * Certifications such as CISSP, CCSP, AWS Security Specialty, CISM, CISA, Security+ or similar preferred * Senior technical operator capable of owning from design through audit validation and evidence production * Comfort with balancing hands-on security engineering with compliance, ConMon, and audit responsibilities * Ability to influence engineering, security, compliance, and external stakeholders without direct authority * Pragmatic, detail-oriented, with sound risk judgment and audit readiness * Accountable, organized, and able to drive complex issues to resolution in a regulated cloud environment Key requirements * Continuous professional development and product training * Clear career growth and advancement opportunities * Inclusive company culture * Comprehensive global benefits package
Requirements
ensure and security tools into the SIEM * Drive vulnerability triage, remediation tracking, risk reduction reporting, and POA&M inputs with Engineering, Infrastructure, Compliance, and vulnerability management teams * Develop and maintain technical runbooks, SOPs, control implementation evidence, and operational procedures for FedRAMP security operations * Support FedRAMP Continuous Monitoring deliverables (vulnerability scans, POA&M updates, configuration reports, incident notifications, security metrics, control evidence) * Partner with product and infrastructure teams to understand architecture, deployment patterns, inherited controls, and shared responsibility * Serve as a senior technical point of contact for FedRAMP audits, 3PAO assessments, agency reviews, and government stakeholder discussions Tasks * 8+ years of experience in cloud security, security engineering, infrastructure security, security operations, or related roles * 4+ years of hands-on experience with FedRAMP-authorized or authorization-boundary cloud environments (prefer Moderate or High) * Strong knowledge of FedRAMP, NIST SP 800-53, Continuous Monitoring, POA&M management, control implementation, and audit evidence expectations * Hands-on experience with AWS GovCloud and commercial AWS; Kubernetes, EKS, Lambda, and cloud-native security controls preferred * Experience operating or integrating EDR, SIEM, vulnerability scanning, container scanning, CSPM, logging, alerting, and security monitoring technologies * Experience managing CrowdStrike (EDR, Cloud Security, NG-SIEM) in commercial or GovCloud environments * Ability to translate FedRAMP requirements into technical designs, control implementations, procedures, and evidence-ready artifacts * Experience coordinating incident response, vulnerability remediation, audit preparation, control validation, and cross-functional FedRAMP program activities * Strong communication skills for explaining controls, remediation, and audit findings to engineers, aaaaaaaaa a auditors, and government stakeholders * Certifications such as CISSP, CCSP, AWS Security Specialty, CISM, CISA, Security+ or similar preferred * Senior technical operator capable of owning from design through audit validation and evidence production * Comfort with balancing hands-on security engineering with compliance, ConMon, and audit responsibilities * Ability to influence engineering, security, compliance, and external stakeholders without direct authority * Pragmatic, detail-oriented, with sound risk judgment and audit readiness * Accountable, organized, and able to drive complex issues to resolution in a regulated cloud environment Key requirements * Continuous professional development and product training * Clear career growth and advancement opportunities * Inclusive company culture * Comprehensive global benefits package
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on us.experteer.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
What Are The Top Skills Required For Azure Developers?
Walking Into The Era of Supply Chain Risks
Building Security Champions
Fully Remote Software Engineer Jobs