Senior FedRamp ISSO

Cribl

United States

Remote

USD 150,000 - 190,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Cribl is seeking a FedRAMP ISSO to own and drive the security posture, compliance operations, and continuous monitoring for our FedRAMP Moderate cloud environment. You will be the single accountable leader, shaping the compliance strategy and leveraging automation to streamline evidence collection and reporting.

You’ll partner with engineering, product, legal, and agency customers to maintain authorization health, defend SSPs, manage POA&M from finding to closure, and run ConMon and annual 3PAO

Qualifications

  • 5+ years of information security experience, with at least 3 years in a dedicated FedRAMP ISSO or ISSE role at a Cloud Service Provider.
  • Deep knowledge of NIST SP 800-53 Rev 5 and the FedRAMP Ecosystem baseline.
  • Proven experience authoring and maintaining large-scale System Security Plans (SSP).
  • Hands-on POA&M management: opening, tracking, aging, escalating, and driving findings to closure.
  • Direct experience running a continuous monitoring program end-to-end, including monthly ConMon reporting and coordination of annual 3PAO assessments.
  • Experience working with Third Party Assessment Organizations (3PAOs) through full assessment cycles, including evidence gathering and auditor facilitation.
  • Demonstrated ability to use automation, scripting, or AI tools to improve compliance operations.
  • Familiarity with cloud environments and their security implications; AWS GovCloud experience strongly preferred, Azure Government or GCP also valued.
  • Strong written communication skills for federal auditors and agency security teams.
  • Active security certification: CISSP, Certified Authorization Professional (CAP/CGRC), or CISM.

Responsibilities

  • Own FedRAMP program end-to-end: serve as the single accountable leader for our FedRAMP Moderate authorization, including the SSP, continuous monitoring program, POA&M lifecycle, and agency relationships.
  • Maintain the System Security Plan: ensure SSP reflects system architecture, control implementations, operational changes, and any approved uses of automation or AI.
  • Drive POA&M management from finding to closure: track findings, coordinate remediation timelines, and build scalable workflows with AI-assisted triage.
  • Lead continuous monitoring: monthly and annual ConMon reporting, vulnerability triage, configuration reviews, and incident reporting per FedRAMP.
  • Run annual 3PAO assessments from start to finish: prepare documentation, manage logistics, and respond to auditor inquiries.
  • Assess the security impact of system changes: evaluate new features and AI capabilities through change management.
  • Serve as the primary federal point of contact: build relationships with agency customers, AOs, and the FedRAMP PMO.
  • Collaborate with engineering and DevOps: improve control validation and automation, including IaC integrations and AI workflows.
  • Coordinate security incident response: ensure timely, accurate agency notification and defensible documentation.
  • Monitor evolving federal guidance: translate NIST/FedRAMP/OMB/CISA guidance into actionable directions for the team.
  • Remote-first operations with multi-timezone collaboration.

Skills

FedRAMP ISSO experience
NIST SP 800-53 Rev 5
SSP authoring
POA&M management
Continuous Monitoring
3PAO coordination
Automation / AI in compliance
Cloud security
Strong written communication
Security certifications (CISSP/CAP/CIS

Job description

Why You’ll Love This Role

We’re looking for a FedRAMP ISSO to own and drive the security posture, compliance operations, and continuous monitoring program for our FedRAMP Moderate authorized cloud environment. This is the single-threaded leader of our federal authorization — You won’t just maintain compliance; you’ll define how we do it. That means building smarter, faster compliance operations — using AI and automation to streamline evidence collection, accelerate reporting, and reduce the manual grind that slows most FedRAMP programs down. You’ll work at the intersection of compliance rigor and real cloud security, partnering with engineering, product, legal, and our federal agency customers to keep our authorization healthy and our customers confident.

As An Active Member Of Our Team, You Will…
  • Own the FedRAMP program end-to-end: serve as the single accountable leader for our FedRAMP Moderate authorization, including the System Security Plan (SSP), continuous monitoring program, POA&M lifecycle, and agency relationships. You set the compliance strategy and drive execution.

  • Maintain and defend the System Security Plan: ensure the SSP accurately reflects system architecture, control implementations, operational changes, and any approved uses of automation or AI within the authorized boundary. When an auditor asks “why,” you have the answer.

  • Drive POA&M management from finding to closure: track open findings from 3PAO assessments, vulnerability scans, and internal reviews; coordinate remediation timelines with engineering; and build scalable tracking, trend analysis, and reporting workflows — including AI-assisted triage and prioritization where it accelerates outcomes.

  • Lead continuous monitoring: monthly and annual ConMon reporting, vulnerability scan review and triage, configuration management reviews, and incident reporting per FedRAMP requirements. Identify and implement opportunities to automate evidence collection and streamline reporting cycles.

  • Run annual 3PAO assessments from start to finish: prepare documentation packages, manage assessment logistics, facilitate evidence collection, and respond to auditor inquiries with clarity, confidence, and well-organized support materials.

  • Assess the security impact of system changes: evaluate new features, infrastructure updates, and emerging AI capabilities through the change management process — ensuring nothing ships that introduces unreviewed compliance, boundary, or control gaps.

  • Serve as the primary federal point of contact: build and maintain relationships with agency customers, Authorizing Officials (AOs), and the FedRAMP PMO, grounded in transparency, technical credibility, and clear communication on compliance posture and evolving technology use.

  • Collaborate with engineering and DevOps: partner on security control implementation, scan result review, and timely remediation. Identify opportunities to improve control validation and compliance operations through secure automation, infrastructure-as-code integration, and AI-assisted workflows.

  • Coordinate security incident response: work alongside the security operations team to ensure timely, accurate agency notification and defensible documentation per FedRAMP reporting requirements.

  • Monitor and translate evolving federal guidance: NIST publications, FedRAMP policy updates, OMB memos, CISA alerts, and emerging AI governance expectations (including NIST AI RMF) — into clear, actionable direction for the team.

  • We are a remote-first company and work happens across many time-zones – you may be required to occasionally perform duties outside your standard working hours

If You’ve Got It - We Want It
  • 5+ years of information security experience, with at least 3 years in a dedicated FedRAMP ISSO or ISSE role at a Cloud Service Provider — not just touching FedRAMP, but owning it.

  • Deep, working knowledge of NIST SP 800-53 Rev 5 and the FedRAMP Ecosystem baseline

  • Proven experience authoring and maintaining large-scale System Security Plans. You know your way around an SSP and can defend every line of it.

  • Hands-on POA&M management experience: opening, tracking, aging, escalating, and driving findings to documented closure

  • Direct experience running a continuous monitoring program end-to-end, including monthly ConMon reporting and coordination of annual 3PAO assessments.

  • Experience working directly with Third Party Assessment Organizations (3PAOs) through full assessment cycles, including evidence gathering and auditor facilitation.

  • Demonstrated ability to use automation, scripting, or AI tools to improve compliance operations — whether that’s automating evidence collection, building reporting pipelines, or using LLMs to accelerate documentation review. You don’t need to be an engineer, but you should be fluent enough to build or direct these workflows.

  • Familiarity with cloud environments and their security implications; AWS GovCloud experience strongly preferred, Azure Government or GCP also valued.

  • Strong written communication skills. The documents you produce will be scrutinized by federal auditors and agency security teams; your writing should hold up to that standard.

  • Active security certification: CISSP, Certified Authorization Professional (CAP/CGRC), or CISM.

  • Nice to haves

#LI-KJ1
#LI-Remote

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Public Sector Compliance Manager
Senior Public Sector Compliance Manager

Jobgether SRL • United States

Remote
USD 110,000 - 170,000
Remote work within United States
Exposure to federal security programs
Cross-functional collaboration
Principal Security Compliance Analyst (Public Sector, Information Security)
Principal Security Compliance Analyst (Public Sector, Information Security)

Elastic • United States

Hybrid
USD 140,000 - 200,000
Health coverage
Flexible location
Distributed workforce
+3
Principal Security Compliance Analyst - Public Sector - InfoSec
Principal Security Compliance Analyst - Public Sector - InfoSec

United States Digital Space LLC • United States

On-site
USD 110,000 - 160,000
Cybersecurity - Lead ISSO
Cybersecurity - Lead ISSO

Securepro Inc • Arlington (VA)

On-site
USD 120,000 - 190,000
401(k)
401(k) matching
Dental insurance
+1
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

Talentify • Colorado

Hybrid
USD 115,000 - 231,000
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

Talentify • Delaware

Hybrid
USD 115,000 - 192,000
FedRAMP Compliance Program Manager
FedRAMP Compliance Program Manager

preciselyusjobs • United States

Remote
USD 140,000 - 190,000
100% remote
Sr. Information Security Technical Lead
Sr. Information Security Technical Lead

Trend Micro • United States

Remote
USD 150,000 - 190,000
Information System Security Officer
Information System Security Officer

Inadev • Reston (VA)

On-site
USD 110,000 - 170,000
Information System Security Officer
Information System Security Officer

Inadev-Corporatio • Reston (VA)

On-site
USD 110,000 - 140,000