Senior FedRamp ISSO

Posted 3 Days Ago
Be an Early Applicant
Hiring Remotely in United States
Remote
128K-200K Annually
Senior level
Software
Cribl is the AI Platform for Telemetry.
The Role
Own the FedRAMP Moderate authorization and security compliance program, including SSP maintenance, POA&M management, continuous monitoring, 3PAO assessments, incident reporting, agency relationships, and change-impact reviews. Partner with engineering, DevOps, legal, and federal customers to maintain authorization and remediate findings. Improve compliance operations through automation, scripting, AI-assisted workflows, infrastructure-as-code, and compliance-as-code. Translate evolving NIST, FedRAMP, OMB, CISA, and AI governance requirements into actionable direction.
Summary Generated by Built In

Join the company that’s building the telemetry infrastructure for the AI era. At Cribl, we partner with IT and Security teams at many of the world’s biggest enterprises, including half of the Fortune 100, to bridge the gap between AI ambition and infrastructure reality. As the AI Platform for Telemetry, we give customers the choice, control, and flexibility to manage and analyze telemetry for both humans and agents, so they can build what’s next.

We’re one of the fastest‑growing private companies and a leading player in a massive, fast‑moving market. With a global workforce, we’re remote‑first and grounded in a simple idea: software is a people business. Cribl is the place where curious, collaborative people can do their best work, grow fast, and bring their full selves to the herd.

Why You’ll Love This Role

We’re looking for a FedRAMP ISSO to own and drive the security posture, compliance operations, and continuous monitoring program for our FedRAMP Moderate authorized cloud environment. This is the single-threaded leader of our federal authorization — You won’t just maintain compliance; you’ll define how we do it. That means building smarter, faster compliance operations — using AI and automation to streamline evidence collection, accelerate reporting, and reduce the manual grind that slows most FedRAMP programs down. You’ll work at the intersection of compliance rigor and real cloud security, partnering with engineering, product, legal, and our federal agency customers to keep our authorization healthy and our customers confident.


As An Active Member Of Our Team, You Will…

  • Own the FedRAMP program end-to-end: serve as the single accountable leader for our FedRAMP Moderate authorization, including the System Security Plan (SSP), continuous monitoring program, POA&M lifecycle, and agency relationships. You set the compliance strategy and drive execution.
  • Maintain and defend the System Security Plan: ensure the SSP accurately reflects system architecture, control implementations, operational changes, and any approved uses of automation or AI within the authorized boundary. When an auditor asks “why,” you have the answer.
  • Drive POA&M management from finding to closure: track open findings from 3PAO assessments, vulnerability scans, and internal reviews; coordinate remediation timelines with engineering; and build scalable tracking, trend analysis, and reporting workflows — including AI-assisted triage and prioritization where it accelerates outcomes.
  • Lead continuous monitoring: monthly and annual ConMon reporting, vulnerability scan review and triage, configuration management reviews, and incident reporting per FedRAMP requirements. Identify and implement opportunities to automate evidence collection and streamline reporting cycles.
  • Run annual 3PAO assessments from start to finish: prepare documentation packages, manage assessment logistics, facilitate evidence collection, and respond to auditor inquiries with clarity, confidence, and well-organized support materials.
  • Assess the security impact of system changes: evaluate new features, infrastructure updates, and emerging AI capabilities through the change management process — ensuring nothing ships that introduces unreviewed compliance, boundary, or control gaps.
  • Serve as the primary federal point of contact: build and maintain relationships with agency customers, Authorizing Officials (AOs), and the FedRAMP PMO, grounded in transparency, technical credibility, and clear communication on compliance posture and evolving technology use.
  • Collaborate with engineering and DevOps: partner on security control implementation, scan result review, and timely remediation. Identify opportunities to improve control validation and compliance operations through secure automation, infrastructure-as-code integration, and AI-assisted workflows.
  • Coordinate security incident response: work alongside the security operations team to ensure timely, accurate agency notification and defensible documentation per FedRAMP reporting requirements.
  • Monitor and translate evolving federal guidance: NIST publications, FedRAMP policy updates, OMB memos, CISA alerts, and emerging AI governance expectations (including NIST AI RMF) — into clear, actionable direction for the team.
  • We are a remote-first company and work happens across many time-zones – you may be required to occasionally perform duties outside your standard working hours


If You’ve Got It - We Want It

  • 5+ years of information security experience, with at least 3 years in a dedicated FedRAMP ISSO or ISSE role at a Cloud Service Provider — not just touching FedRAMP, but owning it.
  • Deep, working knowledge of NIST SP 800-53 Rev 5 and the FedRAMP Ecosystem baseline
  • Proven experience authoring and maintaining large-scale System Security Plans. You know your way around an SSP and can defend every line of it.
  • Hands-on POA&M management experience: opening, tracking, aging, escalating, and driving findings to documented closure
  • Direct experience running a continuous monitoring program end-to-end, including monthly ConMon reporting and coordination of annual 3PAO assessments.
  • Experience working directly with Third Party Assessment Organizations (3PAOs) through full assessment cycles, including evidence gathering and auditor facilitation.
  • Demonstrated ability to use automation, scripting, or AI tools to improve compliance operations — whether that’s automating evidence collection, building reporting pipelines, or using LLMs to accelerate documentation review. You don’t need to be an engineer, but you should be fluent enough to build or direct these workflows.
  • Familiarity with cloud environments and their security implications; AWS GovCloud experience strongly preferred, Azure Government or GCP also valued.
  • Strong written communication skills. The documents you produce will be scrutinized by federal auditors and agency security teams; your writing should hold up to that standard.
  • Active security certification: CISSP, Certified Authorization Professional (CAP/CGRC), or CISM.
  • Nice to haves
    • Experience with the FedRAMP High, IL4, or IL5 baseline; Moderate is the floor, not the ceiling.
    • Familiarity with OSCAL (Open Security Controls Assessment Language) and automated compliance tooling — we’re actively investing in this space.
    • Experience with compliance-as-code pipelines, infrastructure-as-code security scanning, or DevSecOps integration in a FedRAMP context.
    • Experience evaluating AI/ML capabilities within a FedRAMP-authorized boundary, including familiarity with the NIST AI Risk Management Framework.
    • Experience with GRC platforms
    • Knowledge of DISA STIGs and their applicability to cloud-hosted components.
    • An active federal security clearance, or eligibility to obtain one

#LI-KJ1
#LI-Remote

The salary for this role is dependent on geographic location and will be based on the individual candidate's job-related knowledge, skills, and experience.
In addition to base salary, for sales and some sales-adjacent roles, employees are eligible to earn incentive compensation (commission). For all other roles, employees are eligible to participate in the Cribl Corporate Bonus Program.
In addition to a competitive salary, Cribl also offers a generous benefits package which includes health, dental, vision, short-term disability, and life insurance, paid holidays and paid time off, a fertility treatment benefit, 401(k), and equity.

Base Salary Range
$128,000—$200,000 USD

Bring Your Whole Self

Diversity drives innovation, enables better decisions to support our customers, and inspires change for the better. We’re building a culture where differences are valued and welcomed, and we work together to bring out the best in each other. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or any other applicable legally protected characteristics in the location in which the candidate is applying.

Interested in joining the Cribl herd? Learn more about the smartest, funniest, most passionate goats you’ll ever meet at cribl.io/about-us. 

Skills Required

  • 5+ years of information security experience
  • At least 3 years in a dedicated FedRAMP ISSO or ISSE role at a Cloud Service Provider
  • Working knowledge of NIST SP 800-53 Revision 5 and the FedRAMP Ecosystem baseline
  • Experience authoring and maintaining large-scale System Security Plans
  • Hands-on POA&M management experience, including tracking, escalation, and closure of findings
  • Experience running continuous monitoring programs, including monthly ConMon reporting and annual 3PAO assessments
  • Experience working directly with Third Party Assessment Organizations through full assessment cycles
  • Experience using automation, scripting, or AI tools to improve compliance operations
  • Familiarity with cloud environments and their security implications
  • AWS GovCloud experience
  • Strong written communication skills
  • Active CISSP, Certified Authorization Professional, CGRC, or CISM certification
  • Experience with FedRAMP High, IL4, or IL5 baselines
  • Familiarity with OSCAL and automated compliance tooling
  • Experience with compliance-as-code, infrastructure-as-code security scanning, or DevSecOps integration in a FedRAMP context
  • Experience evaluating AI/ML capabilities within a FedRAMP-authorized boundary and familiarity with NIST AI RMF
  • Experience with GRC platforms
  • Knowledge of DISA STIGs and their applicability to cloud-hosted components
  • Active federal security clearance or eligibility to obtain one

Cribl Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Cribl and has not been reviewed or approved by Cribl.

  • Affordable Benefits — Medical and dental premiums are fully covered for individuals in the U.S., with low costs for dependents, and the plans are described as low‑cost overall. This positions healthcare expenses favorably for many employees.
  • Leave & Time Off Breadth — Unlimited PTO, paid holidays, and periodic company “refresh” or winter‑break days provide ample time away. Flexible schedules further support taking time when needed.
  • Wellbeing & Lifestyle Benefits — A monthly stipend for home office, phone, and internet, plus strong remote‑work setup support, underpin the remote‑first model. Additional perks like recharge days and equipment support bolster day‑to‑day wellbeing.

Cribl Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: San Francisco, CA
1,000 Employees
Year Founded: 2018

What We Do

Cribl, the AI Platform for Telemetry, empowers enterprises to manage and analyze telemetry for both humans and agents. Trusted by organizations worldwide, including half of the Fortune 100, Cribl bridges the gap between AI ambition and infrastructure reality. No lock-in. No data loss. No compromises. Cribl’s vendor-agnostic platform ensures data remains portable and interoperable. By cost-effectively handling increasing data volume and variety without delay, Cribl gives enterprises the choice, control, and flexibility to build what’s next.

Why Work With Us

We are building the company that will become the industry leader in IT and Security data. But, doing that doesn’t mean we’re always serious. We approach our work fearlessly, learn quickly, improve constantly, and celebrate our wins at every turn. And more importantly, we laugh a lot.

Gallery

Gallery

Similar Jobs

CrowdStrike Logo CrowdStrike

Technical Proposal Writer (Remote)

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
7 Locations
11000 Employees
86K-135K Annually
Remote or Hybrid
4 Locations
1100 Employees
185K-282K Annually
Remote or Hybrid
Boston, MA, USA
1100 Employees
264K-500K Annually

Hewlett Packard Enterprise Logo Hewlett Packard Enterprise

Solutions Architect

Artificial Intelligence • Cloud • Information Technology • Consulting
Remote
New Jersey, USA
85422 Employees
161K-378K Annually

Similar Companies Hiring

Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel Thumbnail
Aerospace • Hardware • Robotics • Software
Marina Del Rey, California
60 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account