Senior Security Engineer I – GRC FedRAMP

🕒 il y a 20 jours

🇺🇸 États-Unis – Télétravail

💵 $145 000 - $210 000 / an

⏰ Temps Plein

🟠 Senior

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🦅 Parrain de Visa H1B

info

🗣️🇺🇸🇬🇧 Anglais requis

Postuler Maintenant
Trouver des Emplois à Distance Similaires

📊 Vérifiez votre score de CV pour ce poste

Améliorez vos chances d'obtenir un entretien en vérifiant votre score de CV avant de postuler.

Logo of Smartsheet

Smartsheet

1001 - 5000 employés

Fondée en 2005

💼 Conseil

🏥 Santé

📣 Marketing

Consulting • Healthcare • Marketing

Smartsheet est une plateforme conçue pour gérer les projets, automatiser les flux de travail et créer des solutions à grande échelle. Elle offre une large gamme de fonctionnalités comprenant l'automatisation, la collaboration en équipe, les tableaux de bord et le reporting, ainsi que des intégrations, permettant aux entreprises de rationaliser leurs opérations. La plateforme répond à divers cas d'utilisation tels que la gestion de projets, la gestion de portefeuilles IT, la gestion marketing, et bien plus encore, s'adressant à diverses industries, y compris le gouvernement, la finance et la santé. Smartsheet accorde également une grande importance à la sécurité et à la protection des données, garantissant la confidentialité des données des utilisateurs. De plus, elle propose des services professionnels tels que le conseil, la formation et le support à la mise en œuvre pour maximiser les capacités de la plateforme.

Description

• Own FedRAMP and GovRAMP (formerly StateRAMP) certifications and roadmaps: Lead the overall strategy for obtaining and maintaining federal authorizations, including package management, compliance timelines, and authority coordination. • Manage 3PAO relationships and assessments: Work with accredited third-party assessment organizations to conduct initial assessments and annual re-assessments. Coordinate scoping, evidence preparation, testing coordination, and results validation. • Lead continuous monitoring (ConMon) execution: Oversee the delivery of monthly, annual, and event-driven FedRAMP deliverables including vulnerability scans, penetration testing, system security plan updates, and compliance reporting. • Manage Plans of Action and Milestones (POA&M) processes: Own the identification, prioritization, tracking, and remediation of findings. Ensure timely closure of Critical (30 days), High (30 days), and Moderate (90 days) findings while coordinating with engineering and security teams. • Coordinate significant change requests and system modifications: Work with product and engineering to document, scope, assess, and obtain agency approval for system changes that impact security controls or compliance posture. • Engage with authorizing officials and federal agencies: Build and maintain relationships with government sponsors, CIOs, and agency decision-makers. Provide regular status updates, respond to questions, and demonstrate authorization compliance. • Prepare comprehensive assessment packages: Lead the development of System Security Plans (SSP), Security Assessment Plans (SAP), risk exposure tables, and supporting documentation required for audits. • Drive compliance automation and efficiency: Identify opportunities to automate evidence collection, simplify reporting, and reduce manual effort while maintaining rigor and auditability.

🎯 Exigences

• 5+ years of hands-on experience with FedRAMP and/or GovRAMP (StateRAMP) programs, including direct involvement in obtaining and maintaining ATOs. • Proven experience working with accredited 3PAOs: You've coordinated initial assessments, managed annual re-assessments, provided evidence packages, and worked through test results and findings. • A degree in Computer Science, Computer Engineering, Cybersecurity or a related field or equivalent practical experience. • Deep understanding of FedRAMP continuous monitoring requirements: Comprehensive knowledge of monthly deliverables, annual assessment cycles, POA&M management, vulnerability scan and penetration test requirements, and compliance reporting cadences. • Strong NIST 800-53 control knowledge: Fluency with control baselines, supplemental overlays (ITAR, CJIS, HIPAA, etc.), impact level determination, and control selection for various system types. • Project management and stakeholder coordination skills: Experience managing complex, multi-month compliance programs with multiple dependencies, stakeholders, and tight deadlines. • Technical foundation in cloud security and compliance: Working knowledge of AWS/GCP/Azure, cloud security controls, identity and access management, encryption, logging, and incident response—sufficient to understand system architecture and control implementations. • Excellent documentation and communication skills: Ability to write clear System Security Plans, coordinate across multiple stakeholders, and translate technical and compliance concepts for government audiences. • Understanding of federal procurement and contracting: Familiarity with how government agencies acquire and authorize cloud services, and the role of compliance in federal GTM. • US Person Status: Must be a U.S. Citizen, U.S. National to meet federal compliance requirements.

🏖️ Avantages

• Employer subsidized medical/vision and dental coverage for full-time employees • 401k Match to help you save for your future (50% of your contribution up to the first 6% of your eligible pay) • Monthly stipend to support your work and productivity • Flexible Time Away Program, plus Sick Time Off • US employees are automatically covered under Smartsheet-sponsored life insurance, short-term, and long-term disability plans • US employees receive 12 paid holidays per year • Up to 24 weeks of Parental Leave • Personal paid Volunteer Day to support our community • Opportunities for professional growth and development including access to Udemy online courses • Company Funded Perks, including a counseling membership, local retail discounts, and your own personal Smartsheet account • Teleworking options from any registered location in the U.S. (role specific)

Postuler Maintenant

Emplois Similaires

🕒 il y a 20 jours

Cherokee Federal

5001 - 10000

🏥 Santé

📦 Logistique

🏭 Fabrication

Security Electronics Technician III at Cherokee Federal Solutions installing and maintaining electronic security systems including video surveillance and access control. Responsible for technical assistance, documentation, and customer support.

🇺🇸 États-Unis – Télétravail

💵 $33 - $35 / heure

⏰ Temps Plein

🟡 Intermédiaire

🟠 Senior

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🗣️🇺🇸🇬🇧 Anglais requis

🕒 il y a 21 jours

Coterie

11 - 50

👥 B2C

🛍️ eCommerce

🛒 Commerce de détail

Security Engineer managing identity and access operations for a remote team at Coterie. Focused on enhancing security posture through compliance and operations support.

🇺🇸 États-Unis – Télétravail

💵 $90 000 - $110 000 / an

⏰ Temps Plein

🟡 Intermédiaire

🟠 Senior

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🦅 Parrain de Visa H1B

info

🗣️🇺🇸🇬🇧 Anglais requis

🕒 il y a 21 jours

The Home Depot

10 000+ employés

🏗️ Construction

📦 Logistique

🛒 Commerce de détail

Cybersecurity Manager leading proactive threat hunting programs at The Home Depot. Focusing on team development and advanced detection capabilities in cybersecurity.

🇺🇸 États-Unis – Télétravail

💵 $170 000 - $240 000 / an

💰 Debt Financing en 2007-07

⏰ Temps Plein

🟠 Senior

🔴 Expert

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🗣️🇺🇸🇬🇧 Anglais requis

Cyber Security

🕒 il y a 21 jours

SpecterOps

51 - 200

🔒 Cybersecurity

🏢 Entreprise

📚 Éducation

Security Advocate promoting SpecterOps tools and educating on attack path management. Engaging with cybersecurity professionals through content and community events.

🇺🇸 États-Unis – Télétravail

💵 $160 000 - $185 000 / an

⏰ Temps Plein

🟠 Senior

🔴 Expert

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🗣️🇺🇸🇬🇧 Anglais requis

Cyber Security

🕒 il y a 21 jours

Defy Security

51 - 200

💼 Conseil

🔐 Sécurité

🏢 Entreprise

Enterprise Account Executive driving strategic growth in cybersecurity solutions across large enterprise clients. Partnering with C-level leaders to transform cyber risk management and enhance security decisions.

🇺🇸 États-Unis – Télétravail

💵 $110 000 - $130 000 / an

⏰ Temps Plein

🟠 Senior

🔴 Expert

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🗣️🇺🇸🇬🇧 Anglais requis

Cyber Security