This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Security Engineer (FedRAMP Engineer) based in United States.
This role offers the opportunity to provide hands-on security engineering expertise within a fast-paced federal cybersecurity environment. You will assess cloud service provider architectures and security controls against FedRAMP, NIST, FISMA, RMF, and agency requirements. The position combines technical architecture review, compliance analysis, risk assessment, and stakeholder engagement. You will work closely with government program leaders, CISOs, vendors, and technical teams to identify gaps and strengthen security postures. Your recommendations will directly support authorization decisions and continuous monitoring activities. The role is fully remote and suited to an experienced security professional comfortable operating across technical and non-technical audiences.
Accountabilities
-
Perform detailed technical and architecture reviews across the full technology stack of cloud service provider solutions, evaluating secure design, resilience, and compliance.
-
Review FedRAMP authorization packages, including system security plans, policies, procedures, assessment plans, security assessment reports, vulnerability scans, penetration tests, and related documentation.
-
Lead architecture interviews and discussions with cloud service providers to evaluate security controls, technical implementations, and compliance with program and agency requirements.
-
Identify documentation, architectural, and technology gaps; work with vendors to reconcile findings and provide guidance on remediation and compliance expectations.
-
Develop architecture briefings and technical reports for government FedRAMP program leadership and CISO stakeholders, communicating compliance status, technical capabilities, risks, and areas of concern.
-
Support continuous monitoring activities, including annual package reviews, significant change proposals, risk acceptance documentation, and ongoing security assessments.
-
Partner with government FedRAMP leads and stakeholders to provide security engineering support and help ensure project and authorization milestones are achieved.
-
Interpret FedRAMP, NIST, FISMA, RMF, and agency cybersecurity requirements and translate them into actionable technical guidance for vendors and stakeholders.
-
Evaluate emerging technologies, updated cybersecurity directives, FedRAMP guidance, and industry practices, providing recommendations on their potential impact.
-
Conduct security reviews of technologies considered for use within cloud service provider authorization boundaries.
-
Oversee relationships for assigned contractor-owned or contractor-operated systems and help ensure compliance with applicable security and privacy requirements.
-
Research security architectures and systems to provide technical insights, recommendations, and solutions aligned with documented security policies and procedures.
Requirements
-
At least 5 years of professional experience in IT security, including substantial experience in security engineering or architecture.
-
Direct experience analyzing FedRAMP cloud service provider architectures and security control implementations, such as experience with a 3PAO, the federal FedRAMP program, or another federal agency.
-
At least 4 years of hands-on experience as a Security Engineer or System Architect and at least 4 years supporting FedRAMP as an engineer or architect.
-
Bachelor’s degree in Computer Science, Information Systems, Mathematics, Engineering, or a related discipline, or an additional 3 years of relevant IT experience in lieu of the degree.
-
Security certification such as Security+, CISSP, CISM, CISA, or an equivalent credential.
-
Strong knowledge of NIST policies and governance, security planning and architecture, FISMA compliance, Risk Management Framework (RMF), incident analysis, and general security best practices.
-
Current experience reviewing third-party security assessment reports and related security documentation.
-
Ability to confidently lead meetings and technical discussions with vendors, government stakeholders, senior managers, technical teams, and non-technical audiences.
-
Excellent written and verbal communication skills, with the ability to translate complex security concepts into clear recommendations.
-
Strong analytical, problem-solving, and advisory capabilities, with sound judgment when evaluating security risks and compliance gaps.
-
Ability to work independently while collaborating effectively across multidisciplinary teams in a fast-paced environment.
-
Strong understanding of secure, compliant, and resilient cloud architectures and the ability to assess technical solutions against established requirements.
Benefits
-
Fully remote work within the United States.
-
Base salary range of $140,000–$155,000, depending on factors such as experience, skills, education, location, achievements, and other relevant considerations.
-
Employer-paid medical, dental, and vision coverage at 99% for full-time employees.
-
Employer contribution toward health coverage for families and dependents.
-
Company-paid short-term disability and life insurance.
-
401(k) matching of up to 4%.
-
Paid certifications and access to an online education and training portal.
-
Paid time off and paid federal holidays.
-
Wellness and fitness program.
-
Flexible Spending Account programs covering medical costs, dependent care, transit, and parking.
-
Employee referral bonuses.
-
Remote-first environment with core business-hour collaboration and a focus on trust, accountability, and professional development.
-
Reasonable workplace accommodations are available for qualified individuals with disabilities.