RESEARCH TRIANGLE PARK, NC, 27709, USA
1 day ago
FedRAMP Compliance Monitoring Leader
**Introduction** IBM and the Federal Center of Excellence is looking for a Senior Technical resouce, FedRAMP ConMon, with extensive experience of assessing risk and running continuous monitoring activities within the FedRAMP space. The primary objective of this role is to drive and manage the monthly Plan of Action and Milestones (POA&M) process as part of continuous monitoring for FedRAMP attestations, while achieving best in class automation. **Your role and responsibilities** * Manage and monitor compliance-related tasks, such as vulnerability scanning, security testing, and security incident management. * Develop and maintain FedRAMP compliance documentation and reports, including System Security Plans (SSPs), Security Assessment Reports (SARs), and Continuous Monitoring Plans (CMPs). * Collaborating with customers FedRAMP ISSOs and other ConMon leaders to develop and maintain a continuous monitoring program for all the company’s system. * Develop and update the Plan of Action and Milestones by including findings identified during both the initial assessment and monthly following the ATO. * Provide first level SIA and SCR technical review and document Significant Change Requests (SCR) and Operational Requirements * Collaborate with the FedRAMP ISSO to ensure that the system is operating effectively despite changes in the threat landscape and any upgrades or improvements to the system. * Coordinate and verify FedRAMP evidence and artifacts per Continuous Monitoring requirements for FedRAMP customers. * Partner with engineering and operations teams to ensure alignment to compliance requirements for FedRAMP. * Effectively communicate with management on decisions that impact federal programs and teams. * Executing the monthly Plan of Actions and Milestones (POA&M) report and coordinating related activities with various stakeholders within the security and business teams. * Provide metrics to executive leadership team and compliance team on a weekly basis. * Leading monthly government customer calls and walking them through the state of remediation * Experience in Software as a Service organization is a plus. * Ability to make high quality decisions with limited information. * The ability to drive collaboration and influence multiple technical and functional teams. * Demonstrated ability to function as a strong business to technology, helping to bridge the business view and requirements to technologists building solutions. * Experience in requirements development, program management, and/or process improvement efforts in a technical company, preferably a SaaS provider. * Experience working with governance, risk, and compliance systems and performing risk assessment activities is highly preferred. **Required technical and professional expertise** * 5 + years of experience in creating and driving POA&M for FedRAMP * Highly proficient with NIST Risk Management Framework (FIPS 199/200, NIST 800 18/30/37/39/53 publications * 3 + years of experience in implementing security controls following NIST 800-53 * FAIR, CRISC, CISSP, SANS GSEC or equivalent certifications * 7 years of related experience or Masters + 5 years of related or demonstrated experience in FedRAMP requirements and SA&A * 3+ years of experience in building productive relationships with both technical and non-technical teams. * 3+ years of proven history in identifying dependencies between complex projects and resolving potential impact. * Must have architectural, engineering and coding experience **Preferred technical and professional experience** * 8+ years of experience in Security Risk/Vulnerability Management * 5+ years of experience with FedRAMP audit/POA&M * Knowledge of public cloud platforms and related security topics . IBM is committed to creating a diverse environment and is proud to be an equal-opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender, gender identity or expression, sexual orientation, national origin, caste, genetics, pregnancy, disability, neurodivergence, age, veteran status, or other characteristics. IBM is also committed to compliance with all fair employment practices regarding citizenship and immigration status.
Confirmar seu email: Enviar Email