Principal Security Compliance Analyst - Public Sector - InfoSec
United States · Remote · Full-time
- Posted 4w ago
- From Elastic’s careers page
- Location
- United States
- Work mode
- Remote
- Type
- Full-time
- Level
- Senior
- Experience
- 5+ years
- Department
- Other
Opens the listing on jobs.elastic.co
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.
About the role
What Is The Role :
Join our team as a Principal Security Compliance Analyst, where you'll take the lead in managing our FedRAMP Moderate program. You'll be part of a fantastic team that values a strong security culture, allowing you to contribute meaningfully to our mission while collaborating with like-minded professionals. Your expertise will help us maintain and enhance our compliance efforts in a supportive and engaging environment.
What You Will Be Doing :
- Manage the FedRAMP Moderate authorization and continuous monitoring program.
- Maintain the System Security Plan, policies, procedures, evidence, inventories, diagrams, and other required documentation.
- Coordinate assessments and reviews with our 3PAO, federal agency partners, consultants, and internal teams.
- Track security findings and POA&M items through remediation.
- Work with Security, Engineering, IT, Product, and Legal teams to implement and maintain required controls.
- Monitor program deadlines, risks, and compliance metrics and report progress to leadership.
- Review system and product changes for potential FedRAMP impact.
- Help control owners understand their responsibilities and prepare appropriate evidence.
What You Bring :
- 5+ years of experience managing or supporting a FedRAMP Moderate program.
- Strong understanding of FedRAMP, NIST SP 800-53, and continuous monitoring requirements.
- Experience with SSPs, POA&Ms, control evidence, vulnerability management, and security assessments.
- Strong project-management and organizational skills.
- Ability to communicate effectively with technical teams, auditors, government stakeholders, and company leadership.
- Eligible to work in Department of Defense (DoD) Impact Level 4 or above cloud service environments.
Skills they ask for
Pick one to see other roles that ask for it.
About Elastic
Search, observability and securityElastic develops search, observability and security products, including Elasticsearch and tools for analyzing application and security data.
See all 131 roles at ElasticMore roles at Elastic
See all 131- Principal Software Engineer I - CI/CD - Platform Engineering ProductivityUnited States · PrincipalSoftware Development · PrincipalUnited States3h
- Revenue ManagerUnited StatesFinance and AccountingUnited States8h
- Public Sector Account ExecutiveDelhiSalesDelhi, India1d
- Pub Sec Account Executive IIIDelhi · SeniorSales · SeniorDelhi, India1d
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.