×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

Senior Security Engineer – GRC FedRAMP; Remote Eligible

Remote / Online - Candidates ideally in
Jacksonville, Duval County, Florida, 32290, USA
Listing for: Segment (Twilio)
Remote/Work from Home position
Listed on 2026-07-22
Job specializations:
  • IT/Tech
    Cybersecurity
Salary/Wage Range or Industry Benchmark: 145000 - 210000 USD Yearly USD 145000.00 210000.00 YEAR
Job Description & How to Apply Below
Position: Senior Security Engineer I – GRC FedRAMP (Remote Eligible)

For over 20 years, Smartsheet has empowered teams to manage work seamlessly and scale solutions smarter. Now, in our most ambitious chapter yet, we are uniting human teams with AI agents. By orchestrating the work agents do best, automating manual tasks and uncovering insights at scale, we create the space for people to focus on what truly matters: judgment, creativity, and big thinking.

That is magic at work, and it’s what we show up for every day.

FedRAMP and GovRAMP (formerly StateRAMP) are transforming how Smartsheet serves government and regulated customers. We need a FedRAMP and GovRAMP subject matter expert to lead these programs—someone with real hands‑on experience obtaining and maintaining ATO authorizations, navigating 3

PAO assessments, and managing continuous monitoring requirements. In this role, you'll own Smartsheet's FedRAMP and GovRAMP certifications, manage relationships with our 3

PAOs, drive annual assessment preparation, manage POA&M processes, and ensure we maintain authorizations at the highest level. You'll understand the nuances of federal compliance, speak fluently with government agencies and authorized assessors, and translate complex regulatory requirements into clear roadmaps for engineering and operations teams. You'll be the voice of federal compliance at Smartsheet and the trusted advisor to government customers on our security posture.

You Will:
  • Own FedRAMP and GovRAMP (formerly StateRAMP) certifications and roadmaps:
    Lead the overall strategy for obtaining and maintaining federal authorizations, including package management, compliance timelines, and authority coordination.
  • Manage 3

    PAO relationships and assessments:
    Work with accredited third-party assessment organizations to conduct initial assessments and annual re‑assessments. Coordinate scoping, evidence preparation, testing coordination, and results validation.
  • Lead continuous monitoring (Con Mon) execution:
    Oversee the delivery of monthly, annual, and event‑driven FedRAMP deliverables including vulnerability scans, penetration testing, system security plan updates, and compliance reporting.
  • Manage Plans of Action and Milestones (POA&M) processes:
    Own the identification, prioritization, tracking, and remediation of findings. Ensure timely closure of Critical (30 days), High (30 days), and Moderate (90 days) findings while coordinating with engineering and security teams.
  • Coordinate significant change requests and system modifications:
    Work with product and engineering to document, scope, assess, and obtain agency approval for system changes that impact security controls or compliance posture.
  • Engage with authorizing officials and federal agencies:
    Build and maintain relationships with government sponsors, CIOs, and agency decision‑makers. Provide regular status updates, respond to questions, and demonstrate authorization compliance.
  • Prepare comprehensive assessment packages:
    Lead the development of System Security Plans (SSP), Security Assessment Plans (SAP), risk exposure tables, and supporting documentation required for audits.
  • Drive compliance automation and efficiency:
    Identify opportunities to automate evidence collection, simplify reporting, and reduce manual effort while maintaining rigor and auditability.
You Have:
  • 5+ years of hands‑on experience with FedRAMP and/or GovRAMP (StateRAMP) programs, including direct involvement in obtaining and maintaining ATOs.
  • Proven experience working with accredited 3

    PAOs:
    You've coordinated initial assessments, managed annual re‑assessments, provided evidence packages, and worked through test results and findings.
  • A degree in Computer Science, Computer Engineering, Cybersecurity or a related field or equivalent practical experience.
  • Deep understanding of FedRAMP continuous monitoring requirements:
    Comprehensive knowledge of monthly deliverables, annual assessment cycles, POA&M management, vulnerability scan and penetration test requirements, and compliance reporting cadences.
  • Strong NIST 800‑53 control knowledge:
    Fluency with control baselines, supplemental overlays (ITAR, CJIS, HIPAA, etc.), impact level determination, and control selection for various system types.
  • Project…
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary