The Role
The Government Compliance Technical Specialist is a full-time individual contributor on BeyondTrust's Trust & Assurance team, reporting to the Director of Trust & Assurance. This role owns day-to-day technical execution of BeyondTrust's government compliance programs, including FedRAMP Moderate, TX-RAMP, IRAP, and other emerging public-sector frameworks. Responsibilities include continuous monitoring, writing and maintaining compliance documentation, POA&M management, and building automation to support compliance modernization, including FedRAMP 20x. The ability to interpret, define, and design automation for Key Security Indicators (KSIs) is required.
The ideal candidate has run a FedRAMP program end-to-end and can operate with a high degree of autonomy in a fast-paced cybersecurity product environment. They bring technical depth in NIST 800-53 controls, understand cloud compliance boundaries, and can demonstrate technical automation. This role will also support the program management of government compliance workstreams alongside product, security, and engineering teams.
What You'll Do
- Lead technical compliance build activities for FedRAMP 20x readiness, including interpreting Key Security Indicators (KSIs), defining evidence strategies, and coordinating machine-readable compliance outputs.
- Own day-to-day management and execution of FedRAMP Moderate/Class C continuous monitoring, including deliverables, POA&M tracking, and deviation requests.
- Author and maintain System Security Plans (SSPs), Security Decision Records (SDRs), and other compliance documentation in human and machine readable formats.
- Manage findings and remediation tracking across all government compliance programs.
- Coordinate directly with engineering, security, and cloud operations teams to gather evidence, validate control implementation, and close compliance gaps.
- Support GovRAMP, TX-RAMP, IRAP, and other government or public-sector compliance programs.
- Manage day-to-day relationships with Third Party Assessment Organizations (3PAOs) and agency stakeholders.
- Track and report government program health.
- Monitor FedRAMP policy changes, framework evolution, and translate changes into compliance roadmap.
- Automate evidence collection pipelines and indicator health tracking.
What You'll Bring
- 3 years minimum in FedRAMP program management and technical compliance.
- 4-7 years of experience in information security, compliance, or GRC.
- Demonstrated ability to run a FedRAMP Moderate program, including SSP authorship, ConMon execution, POA&M management, and assessor coordination.
- Deep working knowledge of NIST SP 800-53 controls and their practical implementation in cloud environments.
- Strong familiarity with FedRAMP 20x concepts, especially Key Security Indicators (KSIs), machine-readable evidence frameworks, and continuous assessment models.
- The ability to interpret and define KSIs in the context of BeyondTrust's compliance posture.
- Demonstrated ability to coordinate across engineering, infrastructure, legal, and operations teams to gather evidence and drive remediation to closure.
- Experience building or supporting automated compliance evidence pipelines.
- Experience with GRC tooling for findings management, evidence collection, and program tracking.
- Ability to track and manage multiple concurrent workstreams, surface blockers, and maintain delivery cadences.
- Strong written and verbal communication skills to translate technical compliance information to varying audiences.
Nice To Have
- Strong familiarity with AI security
- Experience using AI to develop and deploy applications
- Experience with GovRAMP, TX-RAMP, IRAP, or other public-sector compliance frameworks.
- Familiarity with FedRAMP High or DoD IL4/IL5 authorization environments.
- CISSP or CISA certification.
- Background in cybersecurity product companies or multi-product SaaS environments.
- Bachelor's degree in information security, computer science, or a related field.