Senior FedRamp ISSO
Listed on 2026-10-07
-
IT/Tech
Cybersecurity
B2B SAAS data observability software.
Join the company that’s building the telemetry infrastructure for the AI era. At Cribl, we partner with IT and Security teams at many of the world’s biggest enterprises, including half of the Fortune 100, to bridge the gap between AI ambition and infrastructure reality. As the AI Platform for Telemetry, we give customers the choice, control, and flexibility to manage and analyze telemetry for both humans and agents, so they can build what’s next.
We’re one of the fastest‑growing private companies and a leading player in a massive, fast‑moving market. With a global workforce, we’re remote‑first and grounded in a simple idea: software is a people business. Cribl is the place where curious, collaborative people can do their best work, grow fast, and bring their full selves to the herd.
We’re looking for a FedRAMP ISSO to own and drive the security posture, compliance operations, and continuous monitoring program for our FedRAMP Moderate authorized cloud environment. This is the single‑threaded leader of our federal authorization
- You won’t just maintain compliance; you’ll define how we do it. That means building smarter, faster compliance operations - using AI and automation to streamline evidence collection, accelerate reporting, and reduce the manual grind that slows most FedRAMP programs down. You’ll work at the intersection of compliance rigor and real cloud security, partnering with engineering, product, legal, and our federal agency customers to keep our authorization healthy and our customers confident.
An Active Member Of Our Team, You Will
- Own the FedRAMP program end-to-end: serve as the single accountable leader for our FedRAMP Moderate authorization, including the System Security Plan (SSP), continuous monitoring program, POA&M lifecycle, and agency relationships. You set the compliance strategy and drive execution.
- Maintain and defend the System Security Plan: ensure the SSP accurately reflects system architecture, control implementations, operational changes, and any approved uses of automation or AI within the authorized boundary. When an auditor asks "why," you have the answer.
- Drive POA&M management from finding to closure: track open findings from 3
PAO assessments, vulnerability scans, and internal reviews; coordinate remediation timelines with engineering; and build scalable tracking, trend analysis, and reporting workflows - including AI‑assisted triage and prioritization where it accelerates outcomes. - Lead continuous monitoring: monthly and annual Con Mon reporting, vulnerability scan review and triage, configuration management reviews, and incident reporting per FedRAMP requirements.
- Identify and implement opportunities to automate evidence collection and streamline reporting cycles.
- Run annual 3
PAO assessments from start to finish: prepare documentation packages, manage assessment logistics, facilitate evidence collection, and respond to auditor inquiries with clarity, confidence, and well‑organized support materials. - Assess the security impact of system changes: evaluate new features, infrastructure updates, and emerging AI capabilities through the change management process - ensuring nothing ships that introduces unreviewed compliance, boundary, or control gaps.
- Serve as the primary federal point of contact: build and maintain relationships with agency customers, Authorizing Officials (AOs), and the FedRAMP PMO, grounded in transparency, technical credibility, and clear communication on compliance posture and evolving technology use.
- Collaborate with engineering and Dev Ops: partner on security control implementation, scan result review, and timely remediation.
- Identify opportunities to improve control…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).