Security GRC Lead

Jobtailor

Washington (District of Columbia)

On-site

USD 150,000 - 190,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor seeks a senior security/compliance professional to own FedRAMP programs end to end, coordinating with 3PAOs, sponsoring agencies, and PMO. You will drive continuous monitoring and annual audits while guiding cross-functional teams on cloud product onboarding within the FedRAMP boundary.

You will translate regulatory requirements into actionable guidance for engineering, product, and sales, reporting metrics for informed decision-making.

Qualifications

  • 5+ years of FedRAMP program and project management experience.
  • Hands-on with government cloud environments such as AWS GovCloud, Azure Government, or Google Cloud.
  • Knowledge of SOC 2, ISO 27001, PCI DSS, HIPAA, and CMMC.

Responsibilities

  • Own FedRAMP and related authorization programs end to end, including relationships with 3PAO, sponsoring agencies, and PMO, and maintenance of SSP/POA&M.
  • Lead Continuous Monitoring efforts and annual external audits with cross-functional partners.
  • Collaborate with engineering, product, sales, and legal to onboard new cloud products into the compliance boundary and document findings.

Skills

FedRAMP experience
Program management
GovCloud/Azure Gov/Google Cloud
Security compliance
Clear communication

Tools

AWS
Azure Government
Google Cloud

Job description

Responsibilities
  • Own and manage FedRAMP and related authorization programs end to end, including relationships with our Third-Party Assessment Organization (3PAO), sponsoring agencies, and the FedRAMP Program Management Office (PMO), as well as maintenance of the System Security Plan (SSP) and Plan of Action and Milestones (POA&M).
  • Drive Continuous Monitoring efforts and lead annual external audits, including planning, scheduling, preliminary analysis, and providing audit training and support to cross‑functional partners.
  • Collaborate with engineering, product, sales, and legal teams to safely onboard new cloud products into the compliance boundary, identify opportunities to reduce risk, and document and address findings in accordance with FedRAMP regulatory standards.
  • Provide subject‑matter expertise on all public sector requirements to internal stakeholders and customers, and contribute to reporting and metrics that provide meaningful context for informed decision‑making.
Requirements
  • 5+ years of FedRAMP industry experience, including program and project management at a software company.
  • Hands‑on experience with government cloud environments such as AWS GovCloud, Azure Government, or Google Cloud (covering Software as a Service (SaaS), Infrastructure as a Service (IaaS), and Platform as a Service (PaaS) models).
  • Strong working knowledge of corporate security management, governance frameworks, and compliance standards including SOC 2, ISO 27001, PCI DSS, HIPAA, and CMMC.
  • Clear communication skills with the ability to work directly with engineering, product, DevSecOps, and executive stakeholders and translate compliance requirements into actionable guidance.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Governance Manager
Security Governance Manager

Jobtailor • Washington

On-site
USD 120,000 - 155,000
Senior FedRAMP Assessor
Senior FedRAMP Assessor

Jobtailor • California (MO)

On-site
USD 80,000 - 120,000
GRC Officer
GRC Officer

penlink • Lincoln (NE)

Hybrid
USD 110,000 - 150,000
Lead Governance and Compliance Analyst
Lead Governance and Compliance Analyst

Jobtailor • Washington

On-site
USD 140,000 - 190,000
GRC Program Manager (FedRAMP & Compliance)
GRC Program Manager (FedRAMP & Compliance)

Port.io • Boston (MA)

On-site
USD 120,000 - 150,000
Federal GRC & Compliance Lead (FedRAMP Focus)
Federal GRC & Compliance Lead (FedRAMP Focus)

penlink • Lincoln (NE)

Hybrid
USD 110,000 - 150,000
Lead Federal Auditor
Lead Federal Auditor

Jobtailor • California (MO)

On-site
USD 120,000 - 180,000
Senior GRC Analyst
Senior GRC Analyst

Workato • Palo Alto (CA)

On-site
USD 150,000 - 190,000
Lead Security Compliance Advisor (GRC)
Lead Security Compliance Advisor (GRC)

Frey Consulting Group • Columbus (OH)

Remote
USD 100,000 - 150,000
East Coast US GRC Specialist (US Citizen)
East Coast US GRC Specialist (US Citizen)

Oligo Cyber Security Ltd. • United States

On-site
USD 110,000 - 160,000