Implement, maintain and enhance integrated GRC frameworks for FedRAMP and DoD authorizations, with a focus on continuous monitoring activities
Play a key role in the execution of ongoing significant change and annual assessment activities
Collaborate and communicate GRC requirements to a wide range of internal and external stakeholders
Own and maintain the Plan of Action and Milestone deliverable, keeping relevant stakeholders informed on risks to the system
Monitor relevant laws, regulations, and industry standards to understand impacts on authorized services and adjust processes or technical controls as needed
Requirements
5+ years of experience supporting FedRAMP and DoD compliance programs
U.S. citizenship is required; an active U.S. Secret or Top Secret security clearance is preferred
Experience with processes and tools required for automating continuous monitoring activities
Expertise in assessing SaaS, PaaS, and IaaS cloud offerings with a clear understanding of shared control responsibilities
Experience assessing containerized applications in Kubernetes and understanding security best practices for AI/ML technologies.