Principal Security Compliance Analyst (Public Sector, Information Security)

Elastic

United States

Hybrid

USD 140,000 - 200,000

Full time

2 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Health coverage
Flexible location
Distributed workforce
Parental leave
Volunteer time
Donation match

Job summary

Elastic is seeking a Principal Security Compliance Analyst to lead the FedRAMP Moderate program and related continuous monitoring activities. You will manage the FedRAMP authorization lifecycle, maintain SSPs and evidence, and coordinate with 3PAOs, government partners, consultants, and internal teams to ensure ongoing compliance.

You will track findings, manage POA&Ms, and drive remediation while collaborating with Security, Engineering, IT, Product, and Legal teams.

Qualifications

  • 5+ years of experience managing or supporting a FedRAMP Moderate program.
  • Experience with SSPs, POA&M, control evidence, vulnerability management, and security assessments.
  • Ability to communicate effectively with auditors, government stakeholders, and leadership.
  • Strong understanding of FedRAMP, NIST SP 800-53, and continuous monitoring requirements.

Responsibilities

  • Manage the FedRAMP Moderate authorization and continuous monitoring program.
  • Maintain the System Security Plan, policies, procedures, evidence, inventories, diagrams, and other required documentation.
  • Coordinate assessments and reviews with 3PAO, federal agency partners, consultants, and internal teams.
  • Track security findings and POA&M items through remediation.
  • Work with Security, Engineering, IT, Product, and Legal teams to implement and maintain required controls.
  • Monitor program deadlines, risks, and compliance metrics and report progress to leadership.
  • Review system and product changes for potential FedRAMP impact.
  • Help control owners understand their responsibilities and prepare appropriate evidence.

Skills

FedRAMP
NIST SP 800-53
POA&M
SSP
Security assessments
Project management
Compliance monitoring
DoD IL4

Job description

  • Join our team as a Principal Security Compliance Analyst, where you’ll take the lead in managing our FedRAMP Moderate program. You’ll be part of a fantastic team that values a strong security culture, allowing you to contribute meaningfully to our mission while collaborating with like-minded professionals. Your expertise will help us maintain and enhance our compliance efforts in a supportive and engaging environment
  • Manage the FedRAMP Moderate authorization and continuous monitoring program
  • Maintain the System Security Plan, policies, procedures, evidence, inventories, diagrams, and other required documentation
  • Coordinate assessments and reviews with our 3PAO, federal agency partners, consultants, and internal teams
  • Track security findings and POA&M items through remediation
  • Work with Security, Engineering, IT, Product, and Legal teams to implement and maintain required controls
  • Monitor program deadlines, risks, and compliance metrics and report progress to leadership
  • Review system and product changes for potential FedRAMP impact
  • Help control owners understand their responsibilities and prepare appropriate evidence
Benefits
  • Toast to your health: Fully paid health coverage for you and your family, in many locations.
  • Craft your calendar: Flexible location and schedule for most roles.
  • Create space for you: Distributed by design workforce, plus generous number of vacation days each year.
  • Embrace parenthood: Minimum of 16 weeks of parental leave, plus generous family formation benefits.
  • Give back your time: 40 hours each year to use toward volunteering with organizations and causes you’re passionate about.
  • Amplify your impact: Double your charitable giving — we match donations up to $1500 USD (or local currency equivalent).

Ability to communicate effectively with technical teams, auditors, government stakeholders, and company leadershipStrong understanding of FedRAMP, NIST SP 800-53, and continuous monitoring requirementsEligible to work in Department of Defense (DoD) Impact Level 4 or above cloud service environments5+ years of experience managing or supporting a FedRAMP Moderate programExperience with SSPs, POA&Ms, control evidence, vulnerability management, and security assessmentsStrong project-management and organizational skills

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Principal Security Compliance Analyst - Public Sector - InfoSec
Principal Security Compliance Analyst - Public Sector - InfoSec

United States Digital Space LLC • United States

On-site
USD 110,000 - 160,000
Senior FedRAMP Security Compliance Lead
Senior FedRAMP Security Compliance Lead

United States Digital Space LLC • United States

On-site
USD 110,000 - 160,000
FedRAMP Moderate Compliance Lead
FedRAMP Moderate Compliance Lead

Elastic • United States

Hybrid
USD 140,000 - 200,000
Health coverage
Flexible location
Distributed workforce
+3
Senior FedRAMP & Compliance Lead - Public Sector
Senior FedRAMP & Compliance Lead - Public Sector

Elastic • United States

Hybrid
USD 160,000 - 253,000
Stock options
401k matching
Health coverage for you and family
+3
Public Sector FedRAMP Compliance Lead
Public Sector FedRAMP Compliance Lead

Referral Board • United States

On-site
USD 160,000 - 253,000
Stock program
401k matching
Flexible schedules
+1
Lead FedRAMP Compliance Analyst (Moderate)
Lead FedRAMP Compliance Analyst (Moderate)

Elastic • Mountain View (CA)

Hybrid
USD 160,000 - 253,000
Competitive pay
Health coverage
Flexible schedule
+4
Principal FedRAMP Moderate Compliance Analyst
Principal FedRAMP Moderate Compliance Analyst

Elasticsearch B.V. • Northern (KY)

Hybrid
USD 160,000 - 253,000
Health coverage
Flexible locations
Vacation days
+3
Cloud Security Architect
Cloud Security Architect

Pipe Recruit • Palo Alto (CA)

Hybrid
USD 207,000 - 344,000
Security Compliance Lead
Security Compliance Lead

Vulcan Technologies • Austin (TX)

On-site
USD 120,000 - 180,000
FedRAMP Cloud Security Project Manager
FedRAMP Cloud Security Project Manager

InfusionPoints, LLC • North Wilkesboro (NC)

On-site
USD 110,000 - 160,000