Senior FedRamp ISSO
Cribl · Remote - United States
About this role
## Senior FedRAMP ISSO ### About the Role Cribl is seeking a **FedRAMP ISSO** to own and drive the security posture, compliance operations, and continuous monitoring program for our **FedRAMP Moderate** authorized cloud environment. This is the **single-threaded leader** of our federal authorization—you’ll define how we run compliance, not just maintain it. You’ll work at the intersection of **compliance rigor** and **real cloud security**, partnering with engineering, product, legal, and federal agency customers to keep our authorization healthy and our customers confident. ### What You’ll Do - **Own the FedRAMP program end-to-end** as the single accountable leader for FedRAMP Moderate authorization, including the **SSP**, **continuous monitoring**, **POA&M lifecycle**, and **agency relationships**. - **Maintain and defend the System Security Plan (SSP)** to ensure it accurately reflects system architecture, control implementations, operational changes, and approved automation/AI usage within the authorized boundary. - **Drive POA&M management from finding to closure**: track findings from 3PAO assessments, vulnerability scans, and internal reviews; coordinate remediation timelines; build scalable tracking, trend analysis, and reporting workflows (including AI-assisted triage where it helps). - **Lead continuous monitoring** including monthly and annual ConMon reporting, vulnerability scan review/triage, configuration management reviews, and incident reporting per FedRAMP requirements. Identify opportunities to automate evidence collection and streamline reporting. - **Run annual 3PAO assessments** end-to-end: prepare documentation packages, manage assessment logistics, facilitate evidence collection, and respond to auditor inquiries. - **Assess security impact of system changes** through change management to ensure nothing ships with unreviewed compliance, boundary, or control gaps. - **Serve as the primary federal point of contact** for agency customers, Authorizing Officials (AOs), and the FedRAMP PMO—grounded in transparency, technical credibility, and clear communication. - **Collaborate with engineering and DevOps** on security control implementation, scan result review, and timely remediation; improve control validation and compliance operations via secure automation, infrastructure-as-code integration, and AI-assisted workflows. - **Coordinate security incident response** with the security operations team to ensure timely, accurate agency notification and defensible documentation per FedRAMP reporting requirements. - **Monitor and translate evolving federal guidance** (NIST publications, FedRAMP policy updates, OMB memos, CISA alerts, and AI governance expectations such as **NIST AI RMF**) into actionable direction. - **Occasional work outside standard hours** due to remote-first, multi-time-zone operations. ### What You Bring - **5+ years** information security experience, including **3+ years** in a dedicated **FedRAMP ISSO/ISSE** role at a **Cloud Service Provider** (owning FedRAMP, not just touching it). - Deep working knowledge of **NIST SP 800-53 Rev 5** and the **FedRAMP** ecosystem baseline. - Proven experience authoring and maintaining large-scale **System Security Plans** and defending every line. - Hands-on **POA&M management**: opening, tracking, aging, escalating, and driving findings to documented closure. - Direct experience running **continuous monitoring** end-to-end, including monthly ConMon reporting and
Listing freshness
CronJobs last confirmed this listing 2h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.