> Markdown version of [/jobs/ext/2867915-principal-security-compliance-analyst-public-sector-infosec](https://www.wearedevelopers.com/jobs/ext/2867915-principal-security-compliance-analyst-public-sector-infosec). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Security Compliance Analyst - Public Sector - InfoSec - **Company:** Elastic - **Location:** Mountain View, CA, United States - **Experience:** Expert - **Salary:** $159,800.0 - $252,800.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, Cloud Services, Software Vulnerability Management, Information Security Management System, Plan of Action and Milestones - **Published:** September 12, 2026 - **Apply:** https://diversityjobs.com/main/sendform/8/8/28176/1/18285059?backUrl=%2Fcareer%2F18285059%2FPrincipal-Security-Compliance-Analyst-Public-Sector-Infosec-California-Mountain-View ## About the Role * 5+ years of experience managing or supporting a FedRAMP Moderate program. * Strong understanding of FedRAMP, NIST SP 800-53, and continuous monitoring requirements. * Experience with SSPs, POA&Ms, control evidence, vulnerability management, and security assessments. * Strong project-management and organizational skills. * Ability to communicate effectively with technical teams, auditors, government stakeholders, and company leadership. * Eligible to work in Department of Defense (DoD) Impact Level 4 or above cloud service environments. ## Description Join our team as a Principal Security Compliance Analyst, where you'll take the lead in managing our FedRAMP Moderate program. You'll be part of a fantastic team that values a strong security culture, allowing you to contribute meaningfully to our mission while collaborating with like-minded professionals. Your expertise will help us maintain and enhance our compliance efforts in a supportive and engaging environment. What You Will Be Doing: * Manage the FedRAMP Moderate authorization and continuous monitoring program. * Maintain the System Security Plan, policies, procedures, evidence, inventories, diagrams, and other required documentation. * Coordinate assessments and reviews with our 3PAO, federal agency partners, consultants, and internal teams. * Track security findings and POA&M items through remediation. * Work with Security, Engineering, IT, Product, and Legal teams to implement and maintain required controls. * Monitor program deadlines, risks, and compliance metrics and report progress to leadership. * Review system and product changes for potential FedRAMP impact. * Help control owners understand their responsibilities and prepare appropriate evidence. ## Related Videos - [Beyond the Numbers: Engineering Recruiting Excellence Through Quality, Data, and Team Empowerment](https://www.wearedevelopers.com/videos/1491-beyond-the-numbers-engineering-recruiting-excellence-through-quality-data-and-team-empowerment) - [Leverage Cloud Computing Benefits with Serverless Multi-Cloud ML ](https://www.wearedevelopers.com/videos/78-leverage-cloud-computing-benefits-with-serverless-multi-cloud-ml) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [ZEISS & Microsoft - Building the Next Generation Medical Ecosystem in the Cloud](https://www.wearedevelopers.com/videos/424-zeiss-microsoft-building-the-next-generation-medical-ecosystem-in-the-cloud) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)