via Remote Rocketship
$85K - 120K a year
Lead FedRAMP and CMMC assessments, design cloud security aligned with NIST standards, manage compliance documentation, and mentor consultants.
Requires 5+ years experience in FedRAMP/CMMC compliance, deep knowledge of NIST frameworks, relevant certifications like CISM, and familiarity with GRC tools.
Job Description: • Lead FedRAMP Moderate and CMMC readiness assessments, including system boundary validation and control gap analysis • Design and implement cloud security architectures aligned to NIST 800-53 and NIST 800-171 requirements • Develop and own System Security Plans (SSPs), control narratives, and compliance documentation • Partner closely with client engineering, security, and compliance teams to remediate gaps and implement controls • Drive implementation of technical security measures such as encryption, IAM, logging, continuous monitoring, vulnerability management, and incident response • Advise clients on federal and DoD security mandates, including cryptographic requirements and vulnerability remediation timelines • Update and align security policies and procedures to support FedRAMP and CMMC compliance • Conduct preliminary control testing to validate effectiveness prior to formal assessments • Coordinate with Third-Party Assessment Organizations (3PAOs) and C3PAOs during independent assessments • Support assessment execution, evidence collection, remediation cycles, and authorization package submission • Mentor and review work from other consultants, raising the bar on technical quality and delivery • Conduct interviews with prospective team members, assessing candidate suitability while serving as a brand ambassador for the CSA practice and Riveron • Stay current on emerging risks and evolving control practices • Build and maintain strong industry relationships to support long-term business development Requirements: • Bachelor's and/or Master’s degree in Information Technology (IT), Computer Information Systems (CIS), Management Information Systems (MIS), or a related field • 5+ years of deep, demonstrable experience in FedRAMP and/or CMMC compliance efforts in real-world environments • Deep understanding of NIST 800-53 and NIST 800-171 control frameworks • Demonstrated knowledge of other compliance frameworks such as SOC 2, ISO 27001, HIPAA, PCI-DSS • Relevant certification preferred, such as CISA, CISM, CISSP or AWS Cloud Practitioner • Familiarity with GRC solutions, tools, and technologies. Benefits: • Full range of benefits including medical, dental, and vision insurance • 401(k) with company match • PTO
This job posting was last updated on 7/27/2026