Source Job

$117,500–$166,250/yr
US

  • Lead FedRAMP Moderate and CMMC readiness assessments, including system boundary validation and control gap analysis.
  • Design and implement cloud security architectures aligned to NIST 800-53 and NIST 800-171 requirements.
  • Develop and own System Security Plans (SSPs), control narratives, and compliance documentation.

FedRAMP CMMC NIST 800-53 Cloud Security GRC

20 jobs similar to Cyber Security - Manager (FedRAMP)

Jobs ranked by similarity.

US 24w maternity 24w paternity

  • Own FedRAMP and GovRAMP certifications and roadmaps, including package management and compliance timelines.
  • Manage 3PAO relationships and assessments, coordinating scoping, evidence, and results validation.
  • Lead continuous monitoring, POA&M processes, and drive compliance automation and efficiency.

Smartsheet empowers teams to manage work seamlessly and scale solutions smarter, now uniting human teams with AI agents. It is an equal opportunity employer committed to fostering an inclusive environment with the best employees.

US Unlimited PTO

  • Manage and implement complex controls frameworks for large systems consisting of Cloud infrastructure and SaaS services.
  • Design and develop automation solutions for evidence collection across Cloud infrastructure, endpoints, and SaaS services.
  • Conduct risk assessments across business units and processes, identifying risk findings and recommending remediation strategies.

Virtru is a data protection platform that enables secure sharing without sacrificing security or privacy. Backed by top venture capital firms, the company helps Fortune 500 companies and government agencies achieve true data security with freedom to share.

India Unlimited PTO

  • Lead delivery of FedRAMP, CMMC, HITRUST, and NIST compliance engagements where federal authorization is on the line.
  • Build reusable IP like control-mapping libraries, SSP templates, and evidence-collection playbooks for complex frameworks.
  • Own pricing, margin, and utilization for specialized federal engagements, plus leverage AI to standardize deliverables.

Sprinto is an Autonomous Trust Platform that centralizes trust requirements across security frameworks, vendors, and customers. Backed by top-tier investors like Accel, Elevation, and Blume Ventures, we've raised $31.8M and are trusted by over 3,000 organizations across 75 countries, with a remote culture built on ownership and progress over perfection.

$190,000–$210,000/yr
Global

  • Own Filevine's FedRAMP 20x strategy and execution, including evidence automation, continuous monitoring, and certification readiness.
  • Drive the security compliance and trust program across FedRAMP, SOC 2, ISO, HIPAA, and PCI-DSS, converting obligations into engineering work.
  • Lead cross-functional alignment and executive reporting to ensure compliance, privacy, and security priorities are shipped on time.

Filevine is a Legal AI company delivering Legal Operating Intelligence for the future of legal work. Fueled by a team of exceptional collaborators and innovators, Filevine’s rapid growth has earned AI awards and recognition from Deloitte and Inc. as one of the most innovative and fastest-growing technology companies in the country.

Global

  • Own RMF authorizations across Department of War components and FedRAMP High, alongside CMMC 2.0 and SOC 2 compliance for corporate systems.
  • Maintain authorization and audit evidence, including SSPs, SARs, POA&Ms, STIGs, and control mappings.
  • Partner with Engineering, Product, and Security to embed compliance requirements into system design and CI/CD workflows.

Onebrief builds collaboration and AI-powered workflow software for military planning and operational coordination. Founded in 2019, valued at over $2 billion, they are a distributed team of builders from military, operational, and technology backgrounds.

US

  • Lead end-to-end service delivery operations for cybersecurity and cloud security professional services engagements.
  • Own the delivery lifecycle for FedRAMP advisory, implementation, continuous monitoring, and related security programs.
  • Develop operational strategies and governance models ensuring compliance with NIST 800-53, FedRAMP, and DoD frameworks.

This company specializes in cybersecurity and cloud service delivery for federal agencies, managing mission-critical environments with strict compliance requirements. They are a mid-sized organization focused on scalable operations and measurable outcomes.

US

  • Identify products or programs through the FedRAMP (Joint Authorization Board or Agency) authorization process.
  • Collaborate with the Program Manager Public Sector Compliance to define strategic roadmaps and support full product lifecycle.
  • Provide product architectural guidance for Vultr's public sector cloud product roadmap.

Vultr makes high-performance cloud infrastructure easy to use, affordable, and locally accessible for enterprises and AI innovators worldwide. We are the world's largest privately-held cloud infrastructure company, trusted by hundreds of thousands of active customers across 185 countries.

$126,180–$154,220/yr
US

  • Lead the end-to-end authorization process for FedRAMP High, while driving alignment with CMMC and MARS-E.
  • Manage ongoing FedRAMP continuous monitoring, including monthly deliverables and vulnerability management.
  • Collaborate with engineering, security, and operations teams to develop a 'comply once, satisfy many' strategy.

Amwell provides a technology-enabled care platform for healthcare organizations, offering services across the care continuum. With a team passionate about transforming care delivery, they have served large healthcare organizations for nearly two decades.

US

  • Maintain Risk Management Framework artifacts for DevSecOps pipeline inheritance of NIST SP 800-53 controls.
  • Complete and validate STIG/SRG checklists quarterly and provide monthly application STIG status reports.
  • Evaluate program risks, document mitigation strategies, and recommend courses of action to ensure continuous ATO compliance.

DecisionPoint is a company providing cloud services and DevSecOps solutions, supporting ARTRANS AWS environments. It is a regular full-time employer fostering a culture of security and compliance, with an active Secret clearance required for this role.

US 26w PTO

  • Serve as a trusted compliance advisor for DoD contractors, guiding them through NIST SP 800-171, CMMC 2.0, and DFARS requirements from gap analysis to audit readiness.
  • Conduct recurring strategy meetings, review implementation progress, translate complex regulations into practical recommendations, and collaborate with client leadership.
  • Prepare professional assessment reports, maintain compliance documentation, deliver training, and support clients through ongoing compliance management and SPRS submissions.

On Call Computer Solutions is a nationwide leader in cybersecurity, compliance, and managed IT services for Department of Defense contractors. Since 2003, they have helped organizations meet DFARS, NIST SP 800-171, and CMMC requirements with an award-winning team.

$112,000–$179,000/yr
US

  • Lead and execute RMF compliance activities in accordance with DoD and NIST requirements, supporting system accreditation and ATO efforts.
  • Conduct STIG and SRG assessments across Windows, Linux, database, cloud, and application environments using tools such as SCC and STIG Viewer.
  • Analyze vulnerability scan results, develop and maintain POA&Ms, and track remediation activities to closure.

Peraton is a next-generation national security company that drives missions of consequence across land, sea, space, air, and cyberspace. As a leading mission capability integrator and enterprise IT provider, we deliver trusted solutions to protect our nation and allies, supporting essential government agencies and every branch of the U.S. armed forces.

US

  • Serves as a cybersecurity SME for Assessment and Authorization (A&A) of information systems, applying NIST 800-53 security controls and the Risk Management Framework (RMF) process.
  • Possesses five years of relevant RMF, NIST, and A&A experience, including assessing security controls for large, complex organizations like DLA.
  • Briefs senior management on authorization progress and understands cybersecurity in emerging technology areas such as Cloud and Industrial Control Systems.

Horizon Industries Limited is a dynamic IT and Management Consulting firm based in the Washington, DC area, providing full-cycle IT consulting and management support to both private and public sectors. Founded in 1996, the company prides itself on a diverse, employee- and family-centric culture with a focus on professional growth.

$105,000–$130,000/yr
US

  • Consult onsite and remotely with customers to collect and analyze data related to policies, infrastructure, and compliance requirements.
  • Perform gap analyses of current environments and recommend remediation steps.
  • Assist with sales and marketing activities as a subject matter expert and prepare industry presentations.

CampusGuard provides information security and privacy consulting and compliance services for campus-based organizations. It is a full-service firm leveraging industry standards to deliver world-class security and compliance services.

$111,427–$200,000/yr
US

  • Lead Risk Management Framework activities for a federal AI platform deployment in AWS GovCloud.
  • Own authorization artifacts and coordinate with ISSOs and Authorizing Officials for ATO.
  • Partner with platform engineers on cloud and container security, vulnerability management, and hardening.

LMI is a digital solutions provider dedicated to accelerating government impact with innovation and speed, bringing commercial-grade platforms and mission-ready AI to federal agencies. Headquartered in Tysons, Virginia, it serves the defense, space, healthcare, and energy sectors, with a culture more startup than traditional government contractor.

US

  • Lead ISSO activities to ensure confidentiality, integrity, availability, and compliance of enterprise applications and information systems.
  • Manage RMF processes including ATO packages, continuous monitoring, risk assessments, and accreditation documentation within eMASS.
  • Implement and maintain compliance with DISA STIGs, NIST 800-53 controls, and federal cybersecurity requirements.

Jobgether is a platform that uses AI-powered matching to connect candidates with job opportunities. The company facilitates the hiring process by sharing top-fitting candidate shortlists with partner companies, focusing on efficiency and objectivity.

$170,000–$218,000/yr
US

  • Design, deploy, and operate secure cloud infrastructure across AWS and AWS GovCloud to support regulated deployments.
  • Drive platform reliability, release operations, and incident response for production and customer-facing systems.
  • Translate compliance obligations into practical engineering work, including access controls, monitoring, and documentation.

Arch Systems empowers discrete manufacturing facilities with deep data insights for optimal efficiency and proactive decision-making. As a remote-first company with a passionate, multidisciplinary team, they foster innovation and collaboration among employees.

United States Unlimited PTO

  • Partner with the CISO to drive security strategy, roadmap, and execution across application security, GRC, and operations.
  • Support compliance initiatives including PCI, SOC 2, ISO 27001, DORA, and FedRAMP readiness.
  • Serve as a trusted security leader in customer-facing settings, translating technical risks into business language.

Sardine is the leading agentic risk platform for fighting financial crime, integrating data across risk teams to stop fraud and automate AML operations. With over 6 billion profiled devices and 800 million consumers, we maintain a remote-first culture that values performance over hours worked.

$77,800–$85,341/yr
US

  • Design and implement enterprise security controls aligned with NIST SP 800-53 and Zero Trust Architecture principles.
  • Conduct continuous security monitoring, incident response, and vulnerability management across cloud, network, and endpoint environments.
  • Develop and maintain cybersecurity SOPs, security baselines, and asset inventories to support audit readiness.

DMI is a leading provider of digital services and technology solutions, headquartered in Tysons Corner, VA, supporting public sector agencies and commercial enterprises globally. Recognized as a Top Workplace, the company delivers secure, efficient, and cost-effective solutions through a culture guided by five core values.

$80,000–$92,500/yr
US

  • Support cybersecurity efforts across multiple projects within the VA Health portfolio, including ATO remediation, system scans, and artifact development.
  • Communicate and provide consultative support on system security certification & accreditation, coordinating with internal and external project stakeholders.
  • Identify and mitigate risks, support team of cyber professionals, and build artifacts in accordance with NIST and VA guidelines.

LTS provides IT program management and cybersecurity support for the Department of Veterans Affairs Health Portfolio. The company values innovation, growth, collaboration, and quality, offering comprehensive benefits and a career path that rewards ambition and performance.

India

  • Lead security discovery workshops and translate high-level architectural requirements into actionable security roadmaps.
  • Design end-to-end cloud security frameworks and document controls for SOC 2 and HITRUST compliance.
  • Establish governance and security processes for AI and manage vulnerability remediation with development teams.

Ollion is a global technology partner that helps organizations solve their toughest business challenges in AI, data, and cloud. They are a remote-first, globally distributed team focused on making a world of difference through innovation and collaboration.