
Senior Security Engineer I - GRC FedRAMP
Job description
Senior Security Engineer I - GRC FedRAMP at Smartsheet.
About the role
Smartsheet is on the lookout for a security engineer to spearhead its federal compliance efforts. This position plays a vital role in securing necessary government authorizations while ensuring compliance with rigorous federal standards. As the main liaison for all activities related to FedRAMP and GovRAMP, you will be instrumental in guiding the organization through the complexities of federal security requirements.
Key facts
What you'll do
- Develop and implement strategies for acquiring and maintaining FedRAMP and GovRAMP certifications, including managing essential documentation and liaising with relevant authorizing bodies.
- Supervise relationships with Third-Party Assessment Organizations (3PAOs), overseeing both initial and recurring assessment processes, submission of evidence, and review of assessment findings.
- Lead the continuous monitoring initiative, ensuring that all necessary compliance artifacts are delivered on time, whether they are monthly, annual, or event-driven.
- Oversee the complete lifecycle of Plans of Action and Milestones (POA&M), from the identification and prioritization of security findings to tracking and remediation efforts.
- Collaborate with engineering and product teams to evaluate and document system modifications that may affect security controls and compliance status, ensuring that all necessary approvals are obtained.
- Build and maintain strong relationships with government sponsors and agency representatives, providing them with regular updates on compliance progress.
- Prepare detailed assessment packages, which include System Security Plans (SSPs) and Security Assessment Plans (SAPs), ensuring all documentation meets federal standards.
- Identify and implement automation opportunities within compliance processes and reporting to improve efficiency and enhance auditability.
Requirements
- At least 5 years of direct experience with FedRAMP and/or GovRAMP (StateRAMP) programs, including practical involvement in securing and maintaining Authority to Operate (ATO) approvals.
- Proven experience working with accredited 3PAOs, including the coordination of assessments, documentation provision, and management of findings.
- A degree in Computer Science, Computer Engineering, Cybersecurity, or a related discipline, or equivalent professional experience.
- Comprehensive knowledge of FedRAMP continuous monitoring requirements, including monthly deliverables, annual assessment cycles, POA&M management, and vulnerability/penetration testing protocols.
- Strong grasp of NIST 800-53 controls, including baselines, supplemental overlays, impact level determination, and control selection processes.
- Demonstrated project management and stakeholder coordination skills, capable of overseeing complex compliance programs with numerous dependencies and deadlines.
- A foundational understanding of cloud security principles and compliance in environments like AWS, GCP, or Azure, including aspects such as identity and access management, encryption, and logging.
- Exceptional written and verbal communication skills, with the ability to create clear documentation and explain technical and compliance-related concepts to a variety of audiences.
- Familiarity with federal government procurement processes and the methods through which cloud services are acquired and authorized.
- Must be a U.S. Citizen or U.S. National.
Nice to have
- Professional certifications such as CISSP, CISM, CISA, CRISC, or specific credentials related to FedRAMP.
- Experience with systems across various impact levels (IL2, IL4, IL6) and their corresponding requirements.
- Previous involvement in government contracting, DoD CMMC, or other federal compliance frameworks.
- Experience with SaaS FedRAMP authorizations, especially for multi-tenant systems, and an understanding of different ATO pathways.
Skills & tools
- FedRAMP
- GovRAMP
- NIST 800-53
- Cloud Security (AWS, GCP, Azure)
- POA&M Management
- Continuous Monitoring
- 3PAO Assessments
- System Security Plans (SSPs)
Practical notes
The anticipated base salary range for this position is between $145,000 and $210,000 USD annually, complemented by a competitive incentive opportunity. Actual compensation will be influenced by factors such as professional experience, educational background, skills, and the candidate's location.
Benefits include employer-subsidized medical, vision, and dental insurance, 401k matching, a monthly work stipend, flexible time off, life insurance, short-term and long-term disability coverage, paid holidays, parental leave, and opportunities for professional development.
This role provides the flexibility of teleworking from any registered location within the United States.