> Markdown version of [/jobs/ext/2549807-lead-fedramp-security-engineer](https://www.wearedevelopers.com/jobs/ext/2549807-lead-fedramp-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead FedRAMP Security Engineer - **Company:** Commvault Systems, Inc. - **Location:** United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Cloud Computing, Cloud Computing Security, Cyber Security, Monitoring of Systems, Runbook, Security Information and Event Management, Systems Integration, Software Vulnerability Management, Data Logging, Cloud Platform System, Data Ingestion, Kubernetes, Plan of Action and Milestones, Vulnerability Analysis - **Published:** August 6, 2026 - **Apply:** https://us.experteer.com/career/view-jobs/lead-fedramp-security-engineer-usa-58856154 ## About the Role ensure and security tools into the SIEM * Drive vulnerability triage, remediation tracking, risk reduction reporting, and POA&M inputs with Engineering, Infrastructure, Compliance, and vulnerability management teams * Develop and maintain technical runbooks, SOPs, control implementation evidence, and operational procedures for FedRAMP security operations * Support FedRAMP Continuous Monitoring deliverables (vulnerability scans, POA&M updates, configuration reports, incident notifications, security metrics, control evidence) * Partner with product and infrastructure teams to understand architecture, deployment patterns, inherited controls, and shared responsibility * Serve as a senior technical point of contact for FedRAMP audits, 3PAO assessments, agency reviews, and government stakeholder discussions Tasks * 8+ years of experience in cloud security, security engineering, infrastructure security, security operations, or related roles * 4+ years of hands-on experience with FedRAMP-authorized or authorization-boundary cloud environments (prefer Moderate or High) * Strong knowledge of FedRAMP, NIST SP 800-53, Continuous Monitoring, POA&M management, control implementation, and audit evidence expectations * Hands-on experience with AWS GovCloud and commercial AWS; Kubernetes, EKS, Lambda, and cloud-native security controls preferred * Experience operating or integrating EDR, SIEM, vulnerability scanning, container scanning, CSPM, logging, alerting, and security monitoring technologies * Experience managing CrowdStrike (EDR, Cloud Security, NG-SIEM) in commercial or GovCloud environments * Ability to translate FedRAMP requirements into technical designs, control implementations, procedures, and evidence-ready artifacts * Experience coordinating incident response, vulnerability remediation, audit preparation, control validation, and cross-functional FedRAMP program activities * Strong communication skills for explaining controls, remediation, and audit findings to engineers, aaaaaaaaa a auditors, and government stakeholders * Certifications such as CISSP, CCSP, AWS Security Specialty, CISM, CISA, Security+ or similar preferred * Senior technical operator capable of owning from design through audit validation and evidence production * Comfort with balancing hands-on security engineering with compliance, ConMon, and audit responsibilities * Ability to influence engineering, security, compliance, and external stakeholders without direct authority * Pragmatic, detail-oriented, with sound risk judgment and audit readiness * Accountable, organized, and able to drive complex issues to resolution in a regulated cloud environment Key requirements * Continuous professional development and product training * Clear career growth and advancement opportunities * Inclusive company culture * Comprehensive global benefits package ## Description Experteer Overview As Lead FedRAMP Security Engineer, you will own enterprise-wide FedRAMP security controls across cloud environments and security tooling. You translate FedRAMP and NIST 800-53 requirements into implemented, evidence-ready controls and runbooks. You'll partner with Cloud Security, Engineering, Compliance, and government stakeholders to ensure consistent control coverage and continuous monitoring. This senior IC role offers meaningful program ownership and impact on secure, compliant cloud delivery. Compensation / Benefits * Lead enterprise-wide implementation and operation of FedRAMP security controls across cloud infrastructure, security tooling, logging, vulnerability management, and incident response processes * Own the health and coverage of FedRAMP technologies (EDR, vulnerability scanning, CSPM, container scanning, SIEM, alerting, and evidence workflows) * Design, maintain, and validate centralized log ingestion from cloud platforms, operating systems, apps, containers, and security tools into the SIEM * Drive vulnerability triage, remediation tracking, risk reduction reporting, and POA&M inputs with Engineering, Infrastructure, Compliance, and vulnerability management teams * Develop and maintain technical runbooks, SOPs, control implementation evidence, and operational procedures for FedRAMP security operations * Support FedRAMP Continuous Monitoring deliverables (vulnerability scans, POA&M updates, configuration reports, incident notifications, security metrics, control evidence) * Partner with product and infrastructure teams to understand architecture, deployment patterns, inherited controls, and shared responsibility * Serve as a senior technical point of contact for FedRAMP audits, 3PAO assessments, agency reviews, and government stakeholder discussions Tasks * 8+ years of experience in cloud security, security engineering, infrastructure security, security operations, or related roles * 4+ years of hands-on experience with FedRAMP-authorized or authorization-boundary cloud environments (prefer Moderate or High) * Strong knowledge of FedRAMP, NIST SP 800-53, Continuous Monitoring, POA&M management, control implementation, and audit evidence expectations * Hands-on experience with AWS GovCloud and commercial AWS; Kubernetes, EKS, Lambda, and cloud-native security controls preferred * Experience operating or integrating EDR, SIEM, vulnerability scanning, container scanning, CSPM, logging, alerting, and security monitoring technologies * Experience managing CrowdStrike (EDR, Cloud Security, NG-SIEM) in commercial or GovCloud environments * Ability to translate FedRAMP requirements into technical designs, control implementations, procedures, and evidence-ready artifacts * Experience coordinating incident response, vulnerability remediation, audit preparation, control validation, and cross-functional FedRAMP program activities * Strong communication skills for explaining controls, remediation, and audit findings to engineers, executives, auditors, and government stakeholders * Certifications such as CISSP, CCSP, AWS Security Specialty, CISM, CISA, Security+ or similar preferred * Senior technical operator capable of owning from design through audit validation and evidence production * Comfort with balancing hands-on security engineering with compliance, ConMon, and audit responsibilities * Ability to influence engineering, security, compliance, and external stakeholders without direct authority * Pragmatic, detail-oriented, with sound risk judgment and audit readiness * Accountable, organized, and able to drive complex issues to resolution in a regulated cloud environment Key requirements * Continuous professional development and product training * Clear career growth and advancement opportunities * Inclusive company culture * Comprehensive global benefits package ## Related Videos - [Technical Documentation - How Can I Write Them Better and Why Should I Care?](https://www.wearedevelopers.com/videos/681-technical-documentation-how-can-i-write-them-better-and-why-should-i-care) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [SRE Methods In an Agency Environment](https://www.wearedevelopers.com/videos/348-sre-methods-in-an-agency-environment) - [Bridging AI and Nomad: a Go-based MCP Server for Cluster Control](https://www.wearedevelopers.com/videos/2063-bridging-ai-and-nomad-a-go-based-mcp-server-for-cluster-control) - [Build Delightful Mobile Experiences with Kotlin, Realm, and Atlas Device Sync](https://www.wearedevelopers.com/videos/694-build-delightful-mobile-experiences-with-kotlin-realm-and-atlas-device-sync) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Building Security Champions](https://www.wearedevelopers.com/magazine/87-building-security-champions) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs)