> Markdown version of [/jobs/ext/3030311-federal-security-consultant](https://www.wearedevelopers.com/jobs/ext/3030311-federal-security-consultant). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Federal Security Consultant - **Company:** Genesis Consulting Group - **Location:** Washington, DC, United States (Remote available) - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** SAP Cloud, Software as a Service, Cloud Computing, Cloud Engineering, Cyber Security, Data Security, Internet Security, Information Systems Security Architecture Professional, Cloud Services, SAP Concur, SAP (Applications), Software Vulnerability Management, Netsuite Erp, HybridCloud, Information Technology, Mulesoft - **Published:** September 22, 2026 - **Apply:** https://www.careerbuilder.com/job-details/federal-security-consultant-washington-dc--4e6afc93-b22e-45c8-9f34-3b7c0901400e ## About the Role * Minimum 5 years of experience in federal cybersecurity, including at least 3 years in FedRAMP, FISMA, or related authorization frameworks. * Deep familiarity with NIST SP 800-53, 800-171, and 800-37 RMF. * Solid understanding of security architecture for cloud SaaS solutions (preferably SAP Concur, Mulesoft, or similar platforms). * Experience with vulnerability management, incident response, and security operations. * Strong written and verbal communication skills for interfacing with Federal stakeholders. Preferred Qualifications: * CISSP, CISM, or FedRAMP 3PAO experience. * Experience supporting GSA, DHS, or other civilian agencies in large-scale digital modernization projects. * Prior involvement in cloud migration or ERP cloud security initiatives., * Bachelor's Degree in Information Security, Computer Science, or related field. Master's Degree preferred. Required Certifications: * CISSP or CISM Certifications Preferred. Other: * Must be US Citizen with ability to obtain Public Trust Clearance. * Must be willing to travel to Washington, DC on occasion. Skills: Bridge Building, CISM - Certified Information Security Manager, CISSP - Certified Information Systems Security Professional, Cloud Architecture, Cloud Computing, Communication Skills, Computer Science, Computer Security, Documentation, ERP (Enterprise Resource Planning), Enterprise Architecture, Enterprise Protection, External Audit, FISMA - Federal Information Security Management Act, Homeland Security, Hybrid Cloud, Incident Response, Information/Data Security (InfoSec), Internal Audit, Internet Security, Presentation/Verbal Skills, Project/Program Management, Risk Analysis, Risk Management, Risk Management Framework (RMF), SAP, Security Architecture, Security Consulting, Software as a Service (SaaS), Systems Maintenance, Technical Leadership, U.S. National Institute of Standards and Technology (NIST), United States Citizen, Validation Documentation, Vendor/Supplier Evaluation, Willing to Travel, Writing Skills ## Description The Federal Security Consultant will serve as a key member of the Go.gov transformation team, ensuring that SAP Concur and related cloud solutions achieve and sustain FedRAMP Authorization to Operate (ATO). This role bridges enterprise security architecture, compliance engineering, and federal risk management frameworks in a complex, multi-agency program., Duties will include but may not be limited to: * Lead the planning and execution of FedRAMP ATO activities for SAP Concur and aligned SaaS platforms used in the Go.gov modernization program. * Develop, review, and maintain system security documentation including SSPs, POA&Ms, and related artifacts per NIST SP 800-53 and 800-37 guidelines. * Interface with GSA IT Security, agency ISSOs, and SAP Cloud Compliance teams to align controls, evidence, and risk assessments. * Conduct continuous monitoring and controls assessment to sustain authorization. * Define and communicate security architecture strategies compatible with multi-tenant and hybrid cloud environments. * Evaluate vendor security postures and integration security impacts for connected applications. * Support internal and external audits, coordinating responses and remediation activities across functional teams. * Advise project managers and technical leads on secure configuration baselines and policy compliance., * Secure, compliant SAP Concur implementation aligned with GSA's Go.gov transformation milestones. * Comprehensive ATO documentation and control validation evidence. * A sustainable framework for ongoing monitoring and risk management across participating agencies. ## Related Videos - [Remote Driving on Plant Grounds with State-of-the-Art Cloud Technologies](https://www.wearedevelopers.com/videos/251-remote-driving-on-plant-grounds-with-state-of-the-art-cloud-technologies) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Why make use of an integration platform in today's software developments and infrastructure?](https://www.wearedevelopers.com/videos/758-why-make-use-of-an-integration-platform-in-today-s-software-developments-and-infrastructure) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Beyond GPT: Building Unified GenAI Platforms for the Enterprise of Tomorrow](https://www.wearedevelopers.com/videos/1525-beyond-gpt-building-unified-genai-platforms-for-the-enterprise-of-tomorrow) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Best Coding Boot Camps in Germany](https://www.wearedevelopers.com/magazine/237-best-coding-boot-camps-in-germany) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)