Enable job alerts via email!

Software Engineering FedRAMP Security & Compliance Engineer Professional Austin, US

Avature

Austin (TX)

Hybrid

USD 117,000 - 202,000

Full time

27 days ago

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

An established industry player is seeking a FedRAMP Security & Compliance Engineer to join their dynamic team in Austin, Texas. This role focuses on ensuring compliance with critical security standards, including FedRAMP and NIST, while collaborating with skilled engineers globally. The ideal candidate will possess extensive experience in security and compliance, demonstrating strong communication and technical documentation skills. You will play a vital role in monitoring security controls, conducting audits, and preparing compliance reports, all while contributing to a culture of innovation and excellence. This is an exciting opportunity to make a significant impact in a rapidly evolving environment.

Benefits

Healthcare benefits
401(k)
Employee Stock Purchase Plan
Generous paid time off
Training and educational resources
Diverse employee resource groups

Qualifications

  • 5+ years experience in security and compliance is essential.
  • Familiarity with FedRAMP and NIST Security controls is required.
  • Excellent communication skills and ability to work with IT management.

Responsibilities

  • Ensure compliance with FedRAMP and other regulations for MaaS360.
  • Conduct audits and continuous monitoring of security controls.
  • Prepare reports on compliance activities for management.

Skills

Security and compliance
Vulnerability management
Technical documentation
Audit coordination
Communication skills

Education

Associate's Degree/College Diploma

Tools

Tenable
Nessus/Security Center
OWSAP
Twistlock

Job description

A career in IBM Software means you’ll be part of a team that transforms our customer’s challenges into solutions.

Seeking new possibilities and always staying curious, we are a team dedicated to creating the world’s leading AI-powered, cloud-native software solutions for our customers. Our renowned legacy creates endless global opportunities for our IBMers, so the door is always open for those who want to grow their career.

IBM’s product and technology landscape includes Research, Software, and Infrastructure. Entering this domain positions you at the heart of IBM, where growth and innovation thrive.

Your role and responsibilities

The ideal candidate for this role will become an active member of a globally distributed team responsible for ensuring MaaS360, IBM’s Unified Endpoint Management offering, is running smoothly and providing customers the quality of service they’ve come to expect. This role is focused on working with multiple technology and offering teams to ensure the MaaS360 is deployed, supported to achieve both corporate and regulatory compliance requirements with specific focus on FedRAMP, FBA/ FFIEC, SOC 2, and NIST 800-53. The candidate will be working in an exciting and rapidly expanding environment driving high standards while collaborating with a group of skilled engineers and developers from around the world. The successful applicant will be performing work in FedRAMP environments, and therefore, must be a U.S. Person (although US Citizen is preferred).

  • Demonstrate familiarity with current FedRAMP and NIST Security controls and technologies, including vulnerability management capabilities.
  • Ability to develop and lead FedRAMP documentation.
  • Lead recurring ConMon meetings; including review and submission of required artifacts, aid annual 3PAO security assessment, and generate or facilitate deviation requests as needed.
  • Conduct continuous monitoring activities to assess the effectiveness of security controls and identify potential vulnerabilities or non-compliance issues.
  • Lead internal and external audits, for example, FedRAMP, SOC2, and Internal corporate audits.
  • Develop dashboarding and metric reporting to ensure the FedRAMP Continuous Monitoring program is meeting compliance obligations.
  • Flexible, self-motivated, and able to work independently in a fast-paced environment.
  • Excellent communication skills and the proven ability to work effectively with all levels of IT and business management.
  • Skill in preparing and making written and oral presentations of complex technical nature.
  • Understand enterprise operating environments, including security posture, application environment, and associated security controls.
  • Understand/document information system specifications and security controls, including logical and physical diagrams, connectivity, communication, and data flow diagrams, both internal and external to the system.
  • Gather information, architecture diagrams and implementation of the security controls by interfacing with security engineering, operations and build teams and use inputs to develop compliance documentation.
  • Assist with the FedRAMP or FISMA authorization to include, but not limited to, prep of security engineering, build, and ops teams through training & mock interviews, update implementation language in security documentation and develop processes as required in support of FedRAMP PMO/ Agency / CISO requests.
  • Track and oversee the vulnerability remediation efforts in order to advise leadership as required on status blockers, and escalation when needed.
  • Prepare and present regular reports on the status of FedRAMP compliance activities to management and relevant partners.
  • Drive compliance efforts including audit coordination, reporting, risk management and continuous compliance reporting.
  • Coordinate security audits performed by both internal and external parties.
  • Engage offering teams and other business units to drive compliance efforts.
  • Help design and work within security architecture of continuous compliance with both operations and management teams.
  • Partner cross-functionally across the organization to support the implementation of technical, management, and operational controls, with a focus on controls required to deliver and operate regulated environments.
Required education

None

Preferred education

Associate's Degree/College Diploma

Required technical and professional expertise
  • 5+ years experience in security and compliance.
  • Experience working with external and internal auditors to appropriately convey compliance posture.
  • Working with multiple compliance standards to meet each regulation’s required parameters.
  • Ability to build standard templates that are compliant to regulatory standards.
  • Technical experience running vulnerability scanning solutions such as Tenable, Nessus/Security Center, OWSAP, Twistlock.
  • Familiarity with vulnerability management concepts, such as CVE and CVSS.
Preferred technical and professional experience
  • Experience in filing deviation requests for vulnerabilities on behalf of product teams.
  • One or more related professional certifications (e.g. CISSP, CRISC, CISM).
  • Knowledge and experience in large, hybrid FedRAMP or highly regulated programs.
  • Excellent communication and technical documentation skills.
  • Experience working in a compliance role in a SaaS organization.
  • Degree in Computer Science or related discipline or equivalent work experience.
  • Understanding of current cloud technologies and web-services concepts.
  • Understanding agile software development life cycle, continuous integration, continuous delivery.
ABOUT BUSINESS UNIT

IBM Software infuses core business operations with intelligence—from machine learning to generative AI—to help make organizations more responsive, productive, and resilient. IBM Software helps clients put AI into action now to create real value with trust, speed, and confidence across digital labor, IT automation, application modernization, security, and sustainability.

YOUR LIFE @ IBM

In a world where technology never stands still, we understand that dedication to our clients' success, innovation that matters, and trust and personal responsibility in all our relationships, lives in what we do as IBMers as we strive to be the catalyst that makes the world work better.

ABOUT IBM

IBM’s greatest invention is the IBMer. We believe that through the application of intelligence, reason and science, we can improve business, society and the human condition, bringing the power of an open hybrid cloud and AI strategy to life for our clients and partners around the world.

OTHER RELEVANT JOB DETAILS

IBM offers a competitive and comprehensive benefits program. Eligible employees may have access to:

  • Healthcare benefits including medical & prescription drug coverage, dental, vision, and mental health & well being.
  • Financial programs such as 401(k), the IBM Employee Stock Purchase Plan, financial counseling, life insurance, short & long- term disability coverage, and opportunities for performance-based salary incentive programs.
  • Generous paid time off including 12 holidays, minimum 56 hours sick time, 120 hours vacation, 12 weeks parental bonding leave in accordance with IBM Policy, and other Paid Care Leave programs.
  • Training and educational resources on our personalized, AI-driven learning platform where IBMers can grow skills and obtain industry-recognized certifications to achieve their career goals.
  • Diverse and inclusive employee resource groups, giving & volunteer opportunities, and discounts on retail products, services & experiences.

We consider qualified applicants with criminal histories, consistent with applicable law.

This position was posted on the date cited in the key job details section and is anticipated to remain posted for 21 days from this date or less if not needed to fill the role.

IBM will not be providing visa sponsorship for this position now or in the future. Therefore, in order to be considered for this position, you must have the ability to work without a need for current or future visa sponsorship.

Job Title: FedRAMP Security & Compliance Engineer

Date posted: 15-Apr-2025

Job ID: 29004

City / Township / Village: Austin

State / Province: Texas

Country: United States

Work arrangement: Hybrid

Area of work: Software Engineering

Employment type: Regular

Contract type: Regular

Projected Minimum Salary per year: 117,000.00

Projected Maximum Salary per year: 202,000.00

Position type: Professional

Some travel may be required based on business demand.

Company: (0147) International Business Machines Corporation

Shift: General (daytime)

Is this role a commissionable/sales incentive based position?

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Technical Product Manager, Public Trust Certificates

HID Global Corporation

Town of Texas

Remote

USD 135,000 - 145,000

13 days ago

Staff Golang Software Engineer

SailPoint Technologies Holdings, Inc.

Austin

Remote

USD 129,000 - 185,000

12 days ago

Engineer III - Data Reliability Engineer (Remote)

CrowdStrike Holdings, Inc.

Austin

Remote

USD 110,000 - 180,000

13 days ago

Sr. Data Reliability Engineer (Remote)

CrowdStrike

Kansas City

Remote

USD 110,000 - 180,000

10 days ago

Federal/SLED Customer Success Manager Austin, Texas, United States; Remote

ThousandEyes

Austin

Remote

USD 100,000 - 120,000

22 days ago

Senior Microsoft Dynamics 365 (D365) Developer Remote - USA

Sylogist, Ltd.

Remote

USD 90,000 - 150,000

Yesterday
Be an early applicant

Software Engineer, Observability

Ivanti

Remote

USD 80,000 - 120,000

2 days ago
Be an early applicant

Senior Software Engineer, Observability

Ivanti

Remote

USD 100,000 - 130,000

2 days ago
Be an early applicant

Penetration Tester

Locke & Mccloud

Georgia

Remote

USD 90,000 - 120,000

3 days ago
Be an early applicant