Lead Federal AuditorThe Basics The ideal candidate has solid, hands-on experience with FedRAMP compliance processes and federal risk management frameworks, including exposure to FedRAMP High and DoD Impact Level (IL4/IL5) environments. This role supports the organization's cloud authorization activities by contributing to authorization package development, continuous monitoring, and control implementation efforts. Working under the direction of Senior GRC members, it partners closely with engineering, security, and product teams to ensure Tanium's cloud offerings meet and maintain federal compliance requirements across civilian and defense environments.
This is a hybrid position, which will require in person attendance several days each week in one of the following locations: Addison, TX; Bellevue, WA; Durham, NC; Emeryville, CA; or Reston, VA. What You'll Do - Contribute to authorization package documentation (SSPs, POA&Ms, SAPs), with attention to FedRAMP High baseline requirements
- Coordinate with 3PAOs and federal agency sponsors on scheduling, evidence collection, and artifact prep for FedRAMP and DoD IL4/IL5 assessments; respond to assessor inquiries
- Implement and document NIST SP 800-53 controls, validating effectiveness and gathering evidence across FedRAMP Moderate, High, and DoD IL4/IL5 boundaries
- Execute continuous monitoring: monthly vulnerability scanning reviews, POA&M tracking, and deliverables for sponsoring agencies and DoD stakeholders, including annual assessment support
- Assess system architectures with cloud/infrastructure teams to identify compliance gaps, and conduct gap analyses/readiness assessments ahead of 3PAO assessments
- Develop and improve FedRAMP policies, procedures, control implementation descriptions, and internal documentation standards, aligned with PMO and DoD SRG guidance
- Review and respond to federal customer security questionnaires and due diligence requests
- Prepare compliance status summaries, POA&M updates, and control assessment findings for senior leadership
- Monitor FedRAMP PMO, NIST, and DoD SRG updates and federal cybersecurity directives, flagging relevant changes to the GRC team
- Participate in cross-functional projects integrating FedRAMP High and DoD IL4/IL5 requirements into product development
- Working knowledge of NIST SP 800-53 (Rev 4/5) High baseline controls and their practical application in cloud environments
You Should be Knowledgeable In: - Familiarity with the DoD Cloud Computing SRG and IL2/IL4/IL5 requirements and how they relate to FedRAMP
- Experience contributing to authorization artifacts (SSP, SAP, SAR, POA&M, ConMon deliverables)
- Familiarity with adjacent frameworks: FedRAMP, FISMA, NIST SP 800-53, NIST SP 800-37 (RMF), NIST SP 800-171, GovRAMP, CMMC, NIST CSF
- Experience with cloud/SaaS environments, particularly AWS GovCloud, Azure Government, or other IL-accredited platforms
We're Looking for Someone With Experience
- 5+ years in information security, compliance, or risk management, with federal program exposure
- 5+ years of hands-on FedRAMP experience (CSP compliance, 3PAO assessment support, or federal agency ISSO activities); FedRAMP and DoD IL2 (IL4/IL5 preferred)
- Strong written and verbal communication skills across technical and non-technical audiences; experience producing audit findings, policies, and compliance reports
- Certifications preferred: CISSP, CISA, CAP, Security+, or equivalent
What you'll get The annual base salary range for this full-time position is $100,000 to $155,000. This range is an estimate for what Tanium will pay a new hire. The actual annual base salary offered may be adjusted based on a variety of factors, including but not limited to, location, education, skills, training, and experience.
In addition to an annual base salary, team members will receive equity awards and a generous benefits package consisting of medical, dental and vision plan, family planning benefits, health savings account, flexible spending account, transportation savings account, 401(k) retirement savings plan with company match, life, accident and disability coverage, business travel accident insurance, employee assistance programs, disability insurance, and other well-being benefits.