Lead FedRAMP Security Engineer

Commvault Systems, Inc.
United States
4 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
4 years minimum
Working hours
Regular working hours

Tech stack

Amazon Web Services Cloud Computing Cloud Computing Security Cyber Security Monitoring of Systems Runbook Security Information and Event Management Systems Integration Software Vulnerability Management Data Logging Cloud Platform System Data Ingestion
+3 more
Kubernetes Plan of Action and Milestones Vulnerability Analysis

Job description

Experteer Overview As Lead FedRAMP Security Engineer, you will own enterprise-wide FedRAMP security controls across cloud environments and security tooling. You translate FedRAMP and NIST 800-53 requirements into implemented, evidence-ready controls and runbooks. You’ll partner with Cloud Security, Engineering, Compliance, and government stakeholders to ensure consistent control coverage and continuous monitoring. This senior IC role offers meaningful program ownership and impact on secure, compliant cloud delivery. Compensation / Benefits * Lead enterprise-wide implementation and operation of FedRAMP security controls across cloud infrastructure, security tooling, logging, vulnerability management, and incident response processes * Own the health and coverage of FedRAMP technologies (EDR, vulnerability scanning, CSPM, container scanning, SIEM, alerting, and evidence workflows) * Design, maintain, and validate centralized log ingestion from cloud platforms, operating systems, apps, containers, and security tools into the SIEM * Drive vulnerability triage, remediation tracking, risk reduction reporting, and POA&M inputs with Engineering, Infrastructure, Compliance, and vulnerability management teams * Develop and maintain technical runbooks, SOPs, control implementation evidence, and operational procedures for FedRAMP security operations * Support FedRAMP Continuous Monitoring deliverables (vulnerability scans, POA&M updates, configuration reports, incident notifications, security metrics, control evidence) * Partner with product and infrastructure teams to understand architecture, deployment patterns, inherited controls, and shared responsibility * Serve as a senior technical point of contact for FedRAMP audits, 3PAO assessments, agency reviews, and government stakeholder discussions Tasks * 8+ years of experience in cloud security, security engineering, infrastructure security, security operations, or related roles * 4+ years of hands-on experience with FedRAMP-authorized or authorization-boundary cloud environments (prefer Moderate or High) * Strong knowledge of FedRAMP, NIST SP 800-53, Continuous Monitoring, POA&M management, control implementation, and audit evidence expectations * Hands-on experience with AWS GovCloud and commercial AWS; Kubernetes, EKS, Lambda, and cloud-native security controls preferred * Experience operating or integrating EDR, SIEM, vulnerability scanning, container scanning, CSPM, logging, alerting, and security monitoring technologies * Experience managing CrowdStrike (EDR, Cloud Security, NG-SIEM) in commercial or GovCloud environments * Ability to translate FedRAMP requirements into technical designs, control implementations, procedures, and evidence-ready artifacts * Experience coordinating incident response, vulnerability remediation, audit preparation, control validation, and cross-functional FedRAMP program activities * Strong communication skills for explaining controls, remediation, and audit findings to engineers, executives, auditors, and government stakeholders * Certifications such as CISSP, CCSP, AWS Security Specialty, CISM, CISA, Security+ or similar preferred * Senior technical operator capable of owning from design through audit validation and evidence production * Comfort with balancing hands-on security engineering with compliance, ConMon, and audit responsibilities * Ability to influence engineering, security, compliance, and external stakeholders without direct authority * Pragmatic, detail-oriented, with sound risk judgment and audit readiness * Accountable, organized, and able to drive complex issues to resolution in a regulated cloud environment Key requirements * Continuous professional development and product training * Clear career growth and advancement opportunities * Inclusive company culture * Comprehensive global benefits package

Requirements

ensure and security tools into the SIEM * Drive vulnerability triage, remediation tracking, risk reduction reporting, and POA&M inputs with Engineering, Infrastructure, Compliance, and vulnerability management teams * Develop and maintain technical runbooks, SOPs, control implementation evidence, and operational procedures for FedRAMP security operations * Support FedRAMP Continuous Monitoring deliverables (vulnerability scans, POA&M updates, configuration reports, incident notifications, security metrics, control evidence) * Partner with product and infrastructure teams to understand architecture, deployment patterns, inherited controls, and shared responsibility * Serve as a senior technical point of contact for FedRAMP audits, 3PAO assessments, agency reviews, and government stakeholder discussions Tasks * 8+ years of experience in cloud security, security engineering, infrastructure security, security operations, or related roles * 4+ years of hands-on experience with FedRAMP-authorized or authorization-boundary cloud environments (prefer Moderate or High) * Strong knowledge of FedRAMP, NIST SP 800-53, Continuous Monitoring, POA&M management, control implementation, and audit evidence expectations * Hands-on experience with AWS GovCloud and commercial AWS; Kubernetes, EKS, Lambda, and cloud-native security controls preferred * Experience operating or integrating EDR, SIEM, vulnerability scanning, container scanning, CSPM, logging, alerting, and security monitoring technologies * Experience managing CrowdStrike (EDR, Cloud Security, NG-SIEM) in commercial or GovCloud environments * Ability to translate FedRAMP requirements into technical designs, control implementations, procedures, and evidence-ready artifacts * Experience coordinating incident response, vulnerability remediation, audit preparation, control validation, and cross-functional FedRAMP program activities * Strong communication skills for explaining controls, remediation, and audit findings to engineers, aaaaaaaaa a auditors, and government stakeholders * Certifications such as CISSP, CCSP, AWS Security Specialty, CISM, CISA, Security+ or similar preferred * Senior technical operator capable of owning from design through audit validation and evidence production * Comfort with balancing hands-on security engineering with compliance, ConMon, and audit responsibilities * Ability to influence engineering, security, compliance, and external stakeholders without direct authority * Pragmatic, detail-oriented, with sound risk judgment and audit readiness * Accountable, organized, and able to drive complex issues to resolution in a regulated cloud environment Key requirements * Continuous professional development and product training * Clear career growth and advancement opportunities * Inclusive company culture * Comprehensive global benefits package

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on us.experteer.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:55 min

Executing secure deployments with verified compliance and data residency

Alex Laubscher Alex Laubscher · WWC 2025

1:10 min

Exposing sensitive information through partial search logs

Dennis Schulz Dennis Schulz +1 · WWC Europe 2026

2:28 min

Understanding Kubernetes architecture and core cluster components

Marc Nimmerrichter · WWC 2022

2:50 min

Introduction and the value of runbooks

Hila Fish · WWC 2023

6:51 min

Audience questions on cloud security and operational capacity

Steffen Heilmann · WWC 2021

1:56 min

Discovering incidents using logs, metrics, and traces

Nele Uhlemann · WWC 2023

Videos

See all

Related articles

See all