Lead FedRAMP Security Engineer

3 weeks, 2 days ago
Full-time
Lead
DevOps and Infrastructure
Commvault - English - United States

Commvault - English - United States

Commvault is a leading provider of data protection and information management solutions, helping companies worldwide activate their data to drive more value and business insight. With a focus on data management, Commvault offers a comprehensive portfol...

IT Services
1K-5K
Founded 1996

Description

  • Lead enterprise-wide implementation and ongoing operation of FedRAMP security controls across cloud infrastructure and security processes.
  • Own the technical health and coverage of security tools including EDR, vulnerability scanning, CSPM, container scanning, SIEM ingestion, alerting, and related workflows.
  • Design, maintain, and validate centralized log ingestion from cloud platforms, systems, applications, containers, and security tools into the SIEM.
  • Drive vulnerability triage, remediation tracking, risk reduction reporting, and POA&M inputs with engineering and compliance teams.
  • Develop and maintain technical runbooks, SOPs, implementation evidence, and operational procedures for FedRAMP security operations.
  • Support FedRAMP continuous monitoring deliverables including scan results, POA&M updates, configuration reports, incident notifications, metrics, and control evidence.
  • Partner with product and infrastructure teams to understand architecture, deployment patterns, authorization boundaries, inherited controls, and shared responsibilities.
  • Serve as a senior technical point of contact for FedRAMP audits, 3PAO assessments, agency reviews, and government stakeholder discussions.

Requirements

  • 8+ years of experience in cloud security, security engineering, infrastructure security, security operations, or related technical security roles.
  • 4+ years of hands-on experience supporting or operating FedRAMP-authorized or authorization-boundary cloud environments, preferably Moderate or High.
  • Strong working knowledge of FedRAMP, NIST SP 800-53, continuous monitoring, POA&M management, control implementation, and audit evidence expectations.
  • Hands-on experience with AWS GovCloud and commercial AWS environments.
  • Experience with Kubernetes, containers, EKS, Lambda, and cloud-native security controls strongly preferred.
  • Experience operating or integrating EDR, SIEM, vulnerability scanning, container scanning, CSPM, logging, alerting, and security monitoring technologies.
  • Experience managing and operating CrowdStrike, including EDR, Cloud Security, and NG-SIEM modules, in commercial or GovCloud instances.
  • Ability to translate FedRAMP requirements into technical designs, control implementations, operational procedures, and evidence-ready artifacts.
  • Experience coordinating incident response, vulnerability remediation, audit preparation, control validation, and cross-functional FedRAMP program activities.
  • Strong communication skills for explaining technical control posture, remediation plans, and audit findings to engineers, executives, auditors, 3PAOs, and government stakeholders.
  • Relevant certifications such as CISSP, CCSP, AWS Security Specialty, CISM, CISA, Security+, or similar are preferred.
  • Ability to balance hands-on security engineering with structured compliance, continuous monitoring, and audit responsibilities.
  • Ability to influence engineering, security, compliance, and external stakeholders without direct authority.
  • Pragmatic, detail-oriented, organized, and able to drive complex issues to resolution in a regulated cloud environment.

Benefits

  • Base salary range of $93,500 to $182,850 USD.
  • Continuous professional development and product training.
  • Clear career growth and advancement opportunities.
  • Inclusive company culture.
  • Comprehensive global benefits package.
  • Remote work option indicated by #LI-Remote.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Quantum Computing / Cryptography Engineer

MKS2 Technologies 51-250 Internet Software & Services

MKS2 Technologies is seeking a remote Quantum Computing / Cryptography Engineer to support a federal program by advancing cryptographic modernization, quantum readiness, and post-quantum security migration planning.

C++ Cybersecurity Encryption Java Python
17 hours, 24 minutes ago

Cybersecurity Research Assistant

Axle Informatics 51-250 Pharmaceuticals

Axle is seeking a remote Cybersecurity Research Assistant in the United States to support rare disease research at NIH by implementing and monitoring security controls across Kubernetes, Linux, database, and high-performance computing environments.

Ansible Bash Cybersecurity DNS Elasticsearch Git Grafana Kubernetes Linux LLM Prometheus Python RHEL Secrets Management TCP/IP Terraform TLS Ubuntu
17 hours, 39 minutes ago

Cyber Security Engineer (R-00206)

True Zero Technologies 11-50 Internet Software & Services

True Zero Technologies is seeking Cybersecurity Engineers to support enterprise Zero Trust implementation by integrating security capabilities, validating controls, and producing technical evidence for authorization activities.

Cybersecurity Network Security
18 hours, 9 minutes ago

Zero Trust Engineer (R-00205)

True Zero Technologies 11-50 Internet Software & Services

True Zero Technologies is seeking Zero Trust Engineers to implement enterprise Zero Trust use cases across prioritized Department of Veterans Affairs information systems and guide them through planning, validation, testing, and operational transition.

Azure Cybersecurity
1 day, 17 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers