FedRAMP’s 2026 modernization replaces narrative compliance documentation with measurable security outcomes, validated through automation and evidenced continuously. Coalfire delivers FedRAMP environments against standardized reference architecture, and this role owns those architectures and the capabilities that deliver them. This is the top of our engineering individual-contributor track: a design-authority role with no direct reports, whose influence comes from technical judgment and expertise. The standards you set are what dozens of engineers build against, at every client, every day. You’ll take on the most strategic and technical implementations our clients require and support the Cloud Services organization on continuous delivery improvements through client engagements. If you’re driven by a desire to innovate, excel at operational excellence, and thrive in a collaborative environment, come be part of a team committed to making the world a safer place.
What You'll Do
· Own the technical integrity of Coalfire’s FedRAMP reference architectures and capabilities across AWS, Azure, and GCP, and across certification levels.
· Set the engineering standards delivery teams build against—architecture patterns, security baselines, automation frameworks, and evidence-collection approaches.
· Review and approve custom architecture decisions when client requirements fall outside the standard; promote recurring customizations into the reference architecture so the standard improves every quarter.
· Serve as a technical escalation point for delivery teams on architecture and security design questions to improve client outcomes.
· Keep reference architectures current with evolving FedRAMP requirements, including machine-readable compliance packaging (OSCAL or JSON) and continuous-monitoring mandates.
· Mentor engagement architects and senior engineers; raise the technical bar across the delivery organization.
· Partner with the sales organization on solution shape for the most strategic pursuits.
· Represent Coalfire’s technical point of view in the FedRAMP community—working groups, public comment, and industry forums.
WORK ENVIRONMENT/TRAVEL REQUIRED:
Travel: Approximately 10–15%
U.S. citizenship is required, as this position supports federal compliance programs.
What You'll Bring
· BS or above in a related Information Technology field or equivalent combination of education and experience
· 10+ years in cloud security engineering and architecture, including principal- or staff-level scope
· Hands-on FedRAMP authorization experience—building, operating, or assessing FedRAMP environments
· Demonstrated design-authority experience: owning standards, running architecture review, and documenting decisions in a form other engineers build from
· Deep expertise in infrastructure-as-code (Terraform or equivalent), CI/CD, policy-as-code, and compliance automation
· Architecture depth on at least two of the three major cloud platforms (AWS, Azure, GCP)
· Fluency in NIST 800-53 and the FedRAMP control framework, as well as CMMC and DoD compliance standards
· Excellent communication, organizational, and problem-solving skills
· Effective documentation skills, including technical diagrams and written descriptions
· Ability to work independently and as part of a team with a professional attitude and demeanor
· Critical thinking, and the ability to balance security requirements with mission needs
REQUIRED CERTIFICATIONS:
· Professional/Expert-level certification in at least one major cloud platform (AWS, Azure, or GCP)
Bonus Points
· Familiarity with FedRAMP 20x, Key Security Indicators (KSIs), and machine-readable evidence (OSCAL, JSON)
· Experience designing productized or repeatable delivery models for professional services
· Published writing, conference talks, or open-source work in cloud security or compliance automation
· CISSP, CISM, or CISA certifications
· Familiarity with configuration baseline standards such as CIS Benchmarks & DISA STIG
Skills Required
- BS or above in IT or equivalent experience
- 10+ years in cloud security engineering and architecture
- Hands-on FedRAMP authorization experience (building, operating, or assessing FedRAMP environments)
- Design-authority experience owning standards and running architecture reviews
- Deep expertise in infrastructure-as-code (Terraform or equivalent), CI/CD, policy-as-code, and compliance automation
- Architecture depth on at least two of: AWS, Azure, GCP
- Fluency in NIST 800-53 and the FedRAMP control framework; familiarity with CMMC and DoD standards
- Professional/Expert-level certification in at least one major cloud platform (AWS, Azure, or GCP)
- U.S. citizenship (position supports federal compliance programs)
- Approximately 10-15% travel
- Excellent communication, documentation, and problem-solving skills
- Ability to work independently and in a team; professional demeanor
- Familiarity with FedRAMP 20x, Key Security Indicators (KSIs), and machine-readable evidence (OSCAL, JSON)
- Experience designing productized or repeatable delivery models for professional services
- Published writing, conference talks, or open-source work in cloud security or compliance automation
- CISSP, CISM, or CISA certifications
- Familiarity with configuration baseline standards such as CIS Benchmarks & DISA STIG
Coalfire Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Coalfire and has not been reviewed or approved by Coalfire.
-
Leave & Time Off Breadth — Flexible paid time off and paid parental leave are prominently offered, with remote/WFH support enabling time away when workload allows.
-
Healthcare Strength — Comprehensive medical, dental, vision, wellness resources, and an EAP are part of the core package. Carrier coverage and plan options are regularly highlighted across employer materials.
-
Retirement Support — A company‑matched 401(k) is included alongside other financial and development perks. This retirement benefit is consistently featured across benefits overviews.
Coalfire Insights
What We Do
Coalfire is the cybersecurity advisor that helps private and public sector organizations avert threats, close gaps, and effectively manage risk. By providing independent and tailored advice, assessments, technical testing, and cyber engineering services, we help clients develop scalable programs that improve their security posture, achieve their business objectives, and fuel their continued success. Coalfire has been a cybersecurity thought leader for more than 20 years and has offices throughout the United States and Europe.









