Cyber Security - Manager
Job description
About the role
This role is centered on providing expert guidance to clients as they navigate demanding federal compliance programs, with a primary focus on FedRAMP and CMMC initiatives. You will serve as a trusted technical advisor, helping organizations design, implement, and validate secure cloud infrastructures that meet rigorous government standards. A core part of this position involves leading complex assessments and translating intricate regulatory requirements into actionable plans for clients. You will work directly with client stakeholders to close security control gaps and ensure alignment with federal mandates. The role requires a deep understanding of cloud security architectures and the ability to manage the full lifecycle of compliance engagements. You will leverage your expertise to foster client trust and support the successful adoption of security frameworks. This position represents a key opportunity to influence how organizations approach security and compliance in regulated environments.
Key facts
What you'll do
- Oversee comprehensive evaluations for FedRAMP Moderate and CMMC compliance, including precise definition of system boundaries and thorough identification of control gaps.
- Design and implement robust cloud security frameworks that strictly adhere to NIST 800-53 and NIST 800-171 requirements.
- Author, update, and maintain critical compliance documentation such as System Security Plans, control narratives, and detailed control descriptions.
- Partner closely with client technical and security personnel to resolve deficiencies and deploy effective security controls across the infrastructure.
- Direct the implementation and configuration of essential security technologies, including encryption mechanisms, identity and access management solutions, logging platforms, continuous monitoring tools, and incident response capabilities.
- Educate clients on specific federal and Department of Defense security requirements, covering areas such as cryptographic standards and realistic remediation timelines.
- Customize and refine security policies and operational procedures to ensure strict adherence to FedRAMP and CMMC mandates.
- Execute preliminary control testing to verify effectiveness and readiness ahead of formal assessment cycles.
- Coordinate interactions and deliverables with Third-Party Assessment Organizations (3PAOs) and C3PAOs during independent audit reviews.
- Provide active support throughout the assessment lifecycle, including evidence collection, remediation tracking, and compilation of authorization submission packages.
- Review and mentor the work of fellow consultants to uphold consistent delivery standards and high-quality outputs.
- Engage in recruitment interviews for cyber security positions, serving as a representative of the Cyber Security Advisory practice.
- Continuously research and integrate knowledge of emerging risks and evolving security control methodologies.
- Develop and maintain a strong professional network within the industry to facilitate new business opportunities and client growth.
Requirements
- Hold a Bachelor's or Master's degree in Information Technology, Computer Information Systems, Management Information Systems, or a closely related technical field.
- Bring at least 5 years of demonstrable experience conducting FedRAMP and/or CMMC compliance activities in real-world client settings.
- Show advanced proficiency with NIST 800-53 security controls and NIST 800-171 requirements, including implementation and assessment practices.
- Illustrate familiarity with a broad set of compliance frameworks, including but not limited to SOC 2, ISO 27001, HIPAA, and PCI-DSS.
- Exhibit hands-on experience using Governance, Risk, and Compliance (GRC) platforms, tools, and associated technologies.
- Demonstrate the ability to operate effectively in a client-facing role, communicating complex technical concepts to diverse audiences.
- Possess strong analytical and problem-solving skills, with attention to detail in managing large volumes of compliance evidence.
- Be prepared to travel within the United States as necessary to support client engagements and team collaboration activities.
Nice to have
- Obtain industry-recognized certifications such as CISA, CISM, CISSP, or AWS Cloud Practitioner to further validate expertise and credibility.
Practical notes
- This is a fully remote, full-time position open to candidates across the United States.
- Standard full-time working hours apply, with expectations for availability during core business hours.
- Employees who meet eligibility criteria are entitled to a comprehensive benefits package, including medical, dental, and vision insurance.
- Participation in the 401(k) retirement plan is available, with company matching contributions included.
- Paid time off is provided to support work-life balance and personal commitments.
- The organization utilizes artificial intelligence tools at various stages of the hiring workflow, such as screening and assessment processes. These technologies support the recruitment team in evaluating applications but do not replace human decision-making. Final selection decisions are always made by people.