Skip to main content
Commvault

Lead FedRAMP Security Engineer

RemoteUnited States only
Published
Role
Security
Experience
Lead
Company size
Enterprise
$93.5k–$182.9k/yr
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

Lead-level security engineer with 8+ years in cloud/security engineering and 4+ years hands-on with FedRAMP-authorized or authorization-boundary cloud environments. Must know FedRAMP, NIST 800-53, ConMon, POA&M, AWS GovCloud/commercial AWS, and security tooling like EDR, SIEM, vulnerability scanning, CSPM, and logging. US-based remote role.

Core skills

FedRAMPAWS GovCloudSIEM

Required skills

NIST SP 800-53Continuous MonitoringPOA&MAWSEDRvulnerability scanningcontainer scanningCSPMloggingalertingsecurity monitoringCrowdStrike

Optional skills

KubernetescontainersEKSLambdacloud-native security controls

What you'll do

  • Lead enterprise-wide implementation and ongoing operation of FedRAMP security controls across cloud infrastructure, security tooling, logging, vulnerability management, and incident response processes.
  • Own the technical health and control coverage of FedRAMP security technologies, including EDR, vulnerability scanning, CSPM, container scanning, SIEM ingestion, alerting, and evidence-producing security workflows.
  • Design, maintain, and validate centralized log ingestion from cloud platforms, operating systems, applications, containers, and security tools into the SIEM.
  • Drive vulnerability triage, remediation tracking, risk reduction reporting, and POA&M inputs with Engineering, Infrastructure, Compliance, and enterprise vulnerability management teams.
  • Develop and maintain technical runbooks, SOPs, control implementation evidence, and operational procedures for FedRAMP security operations.
  • Support FedRAMP Continuous Monitoring deliverables, including vulnerability scan results, POA&M updates, configuration reports, incident notifications, security metrics, and control evidence.
  • Partner with product and infrastructure teams to understand architecture, deployment patterns, authorization boundaries, inherited controls, and shared responsibility assumptions.
  • Serve as a senior technical point of contact for FedRAMP audits, 3PAO assessments, agency reviews, and government stakeholder discussions.

What they require

  • 8+ years of experience in cloud security, security engineering, infrastructure security, security operations, or related technical security roles.
  • 4+ years of hands-on experience supporting or operating FedRAMP-authorized or authorization-boundary cloud environments, preferably Moderate or High.
  • Strong working knowledge of FedRAMP, NIST SP 800-53, Continuous Monitoring, POA&M management, control implementation, and audit evidence expectations.
  • Hands-on experience with AWS GovCloud and commercial AWS environments.
  • Preferred: Experience with Kubernetes, containers, EKS, Lambda, and cloud-native security controls.
  • Experience operating or integrating EDR, SIEM, vulnerability scanning, container scanning, CSPM, logging, alerting, and security monitoring technologies.
  • Experience managing and operating CrowdStrike in either commercial or GovCloud instances including EDR, Cloud Security, and NG-SIEM modules.
  • Ability to translate FedRAMP requirements into technical designs, control implementations, operational procedures, and evidence-ready artifacts.
  • Experience coordinating incident response, vulnerability remediation, audit preparation, control validation, and cross-functional FedRAMP program activities.
  • Strong communication skills, with the ability to explain technical control posture, remediation plans, and audit findings to engineering teams, executives, auditors, 3PAOs, and government stakeholders.
  • Preferred: Relevant certifications such as CISSP, CCSP, AWS Security Specialty, CISM, CISA, Security+, or similar.
  • Senior technical operator who can own FedRAMP security control implementation from design through evidence and audit validation.
  • Comfortable balancing hands-on security engineering with structured compliance, ConMon, and audit responsibilities.
  • Able to influence engineering, security, compliance, and external stakeholders without direct authority.
  • Pragmatic and detail-oriented, with strong judgment on risk, remediation priority, and audit readiness.
  • Accountable, organized, and able to drive complex issues to resolution in a regulated cloud environment.

Benefits

  • Continuous professional development and product training
  • Clear career growth and advancement opportunities
  • Inclusive company culture
  • Comprehensive global benefits package

data management and information management software company

CybersecurityEnterprisecommvault.com

Details

Apply routeGreenhouse
$93.5k–$182.9k/yr