Senior FedRamp ISSO @Cribl
All Others
Salary usd 128,000 - 2..
Remote Location
๐Ÿ‡บ๐Ÿ‡ธ USA Only
Employment Type full-time
Posted 2d ago

[Hiring] Senior FedRamp ISSO @Cribl

2d ago - Cribl is hiring a remote Senior FedRamp ISSO. ๐Ÿ’ธ Salary: usd 128,000 - 200,000 per year ๐Ÿ“Location: USA

Role Description

Weโ€™re looking for a FedRAMP ISSO to own and drive the security posture, compliance operations, and continuous monitoring program for our FedRAMP Moderate authorized cloud environment. This is the single-threaded leader of our federal authorization โ€” You wonโ€™t just maintain compliance; youโ€™ll define how we do it. That means building smarter, faster compliance operations โ€” using AI and automation to streamline evidence collection, accelerate reporting, and reduce the manual grind that slows most FedRAMP programs down. Youโ€™ll work at the intersection of compliance rigor and real cloud security, partnering with engineering, product, legal, and our federal agency customers to keep our authorization healthy and our customers confident.

As An Active Member Of Our Team, You Willโ€ฆ

  • Own the FedRAMP program end-to-end:
    • Serve as the single accountable leader for our FedRAMP Moderate authorization, including the System Security Plan (SSP), continuous monitoring program, POA&M lifecycle, and agency relationships.
    • Set the compliance strategy and drive execution.
  • Maintain and defend the System Security Plan:
    • Ensure the SSP accurately reflects system architecture, control implementations, operational changes, and any approved uses of automation or AI within the authorized boundary.
    • Provide clear answers to auditor inquiries.
  • Drive POA&M management from finding to closure:
    • Track open findings from 3PAO assessments, vulnerability scans, and internal reviews.
    • Coordinate remediation timelines with engineering.
    • Build scalable tracking, trend analysis, and reporting workflows โ€” including AI-assisted triage and prioritization.
  • Lead continuous monitoring:
    • Conduct monthly and annual ConMon reporting, vulnerability scan review and triage, configuration management reviews, and incident reporting per FedRAMP requirements.
    • Identify and implement opportunities to automate evidence collection and streamline reporting cycles.
  • Run annual 3PAO assessments from start to finish:
    • Prepare documentation packages, manage assessment logistics, facilitate evidence collection, and respond to auditor inquiries.
  • Assess the security impact of system changes:
    • Evaluate new features, infrastructure updates, and emerging AI capabilities through the change management process.
  • Serve as the primary federal point of contact:
    • Build and maintain relationships with agency customers, Authorizing Officials (AOs), and the FedRAMP PMO.
  • Collaborate with engineering and DevOps:
    • Partner on security control implementation, scan result review, and timely remediation.
    • Identify opportunities to improve control validation and compliance operations.
  • Coordinate security incident response:
    • Work alongside the security operations team to ensure timely, accurate agency notification and defensible documentation.
  • Monitor and translate evolving federal guidance:
    • Translate NIST publications, FedRAMP policy updates, OMB memos, CISA alerts, and emerging AI governance expectations into clear, actionable direction for the team.

We are a remote-first company and work happens across many time-zones โ€“ you may be required to occasionally perform duties outside your standard working hours.

Qualifications

  • 5+ years of information security experience, with at least 3 years in a dedicated FedRAMP ISSO or ISSE role at a Cloud Service Provider.
  • Deep, working knowledge of NIST SP 800-53 Rev 5 and the FedRAMP Ecosystem baseline.
  • Proven experience authoring and maintaining large-scale System Security Plans.
  • Hands-on POA&M management experience.
  • Direct experience running a continuous monitoring program end-to-end.
  • Experience working directly with Third Party Assessment Organizations (3PAOs).
  • Demonstrated ability to use automation, scripting, or AI tools to improve compliance operations.
  • Familiarity with cloud environments and their security implications; AWS GovCloud experience strongly preferred.
  • Strong written communication skills.
  • Active security certification: CISSP, Certified Authorization Professional (CAP/CGRC), or CISM.

Requirements

  • Experience with the FedRAMP High, IL4, or IL5 baseline; Moderate is the floor, not the ceiling.
  • Familiarity with OSCAL (Open Security Controls Assessment Language) and automated compliance tooling.
  • Experience with compliance-as-code pipelines, infrastructure-as-code security scanning, or DevSecOps integration in a FedRAMP context.
  • Experience evaluating AI/ML capabilities within a FedRAMP-authorized boundary.
  • Experience with GRC platforms.
  • Knowledge of DISA STIGs and their applicability to cloud-hosted components.
  • An active federal security clearance, or eligibility to obtain one.

Benefits

  • Health, dental, and vision insurance.
  • Short-term disability and life insurance.
  • Paid holidays and paid time off.
  • Fertility treatment benefit.
  • 401(k) plan.
  • Equity opportunities.

Company Description

Diversity drives innovation, enables better decisions to support our customers, and inspires change for the better. Weโ€™re building a culture where differences are valued and welcomed, and we work together to bring out the best in each other.

Before You Apply
๏ธ
๐Ÿ‡บ๐Ÿ‡ธ Be aware of the location restriction for this remote position: USA Only
โ€ผ Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Senior FedRamp ISSO @Cribl
All Others
Salary usd 128,000 - 2..
Remote Location
๐Ÿ‡บ๐Ÿ‡ธ USA Only
Employment Type full-time
Posted 2d ago
Apply for this position
Did not apply โœ“
Applied โœ“
Sent Follow-Up โœ“
Interview Scheduled โœ“
Interview Completed โœ“
Offer Accepted โœ“
Offer Declined โœ“
Application Denied โœ“
Unlock 120,000+ Remote Jobs
๏ธ
๐Ÿ‡บ๐Ÿ‡ธ Be aware of the location restriction for this remote position: USA Only
โ€ผ Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply โœ“
Applied โœ“
Sent Follow-Up โœ“
Interview Scheduled โœ“
Interview Completed โœ“
Offer Accepted โœ“
Offer Declined โœ“
Application Denied โœ“
Unlock 120,000+ Remote Jobs
ร—
Apply to the best remote jobs
before everyone else

Access 120,000+ vetted remote jobs and get daily alerts.

4.9 โ˜…โ˜…โ˜…โ˜…โ˜… from 500+ reviews

โšก 124,307+ remote jobs, refreshed hourly

๐Ÿ”” Real-time alerts: Apply first

๐Ÿ›ก๏ธ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later