Senior Manager, FedRAMP Advisory | Remote US

United States

Coalfire

Coalfire is a cybersecurity and compliance services company that works with enterprises and tech businesses in FedRAMP, cloud migration, AI Risk, pen…

View all jobs at Coalfire

Apply now Apply later

About Coalfire
Coalfire is on a mission to make the world a safer place by solving our clients’ hardest cybersecurity challenges. We work at the cutting edge of technology to advise, assess, automate, and ultimately help companies navigate the ever-changing cybersecurity landscape. We are headquartered in Denver, Colorado with offices across the U.S. and U.K., and wesupport clients around the world.
But that’s not who we are – that’s just what we do. We are thought leaders, consultants, and cybersecurity experts, but above all else, we are a team of passionate problem-solvers who are hungry to learn, grow, and make a difference.
Job Summary
As a Senior Manager, you'll manage a team of consultants, manage client escalations, and lead engagements. This role will have a detailed understanding of compliance framework requirements, perform advisory consulting support, and develop compliance-related reports/documentation for clients. You will also provide quality control and peer review to other members of the delivery staff, and work closely with Project Managers, Directors, Senior Directors and other Delivery team members to effectively manage project timelines and deliverables. You’ll be responsible for directly managing and mentoring 3-6 team members and lead various projects for clients. For each engagement, you’ll focus on the success of the project and achieving overall client satisfaction. You’ll work directly with the Director or Senior Director to implement strategic plans to grow the service line and enhance the overall team’s capabilities and skillsets.

What You'll Do

  • Manage priorities, tasks and hours on projects in conjunction with the project manager and management to achieve delivery utilization targets.
  • Escalates client and project issues to management in a timely manner to inform and engage the necessary resources to address the issue.
  • Interfaces with clients through entire engagement, interacting will all levels of client organizations.
  • Establish and maintain positive, collaborative relationships with clients and stakeholders.
  • Collaborate with project managers, quality management, sales and other delivery team members to drive customer satisfaction and meet project deliverables.
  • Manage team, responsible for talent decisions in regard to performance management, compensation and hiring.
  • Provide mentorship and coaching to team members in areas of technology, consulting, technical review and writing. 
  • Maintain strong depth of knowledge in the practice area, seek professional development opportunities, and maintain industry specific certifications.
  • Establish account relationships and identifies upsell and cross sell opportunities and escalates to sales.
  • Ensure team members are achieving project margins and utilization targets
  • Lead complex and less complex projects, guiding the customer and all resources successfully through the project lifecycle.
  • Lead advisory projects from start to finish to include workshops, gap analyses, document development projects, and ad hoc consulting support
  • Execute examine, interview, and test procedures in accordance with compliance advisory security control framework (NIST, FISMA, FedRAMP, StateRAMP, DoD, etc.), etc.) requirements
  • Ensure cybersecurity policies are adhered to and that required controls are implemented
  • Validate respective information system security plans or policy/procedure documentation to ensure compliance advisory control requirements are met.
  • Author recommendations associated with findings on how to improve the customer’s security posture
  • Closely follow industry development and trends to develop and maintain industry-specific policies, procedures, and training.
  • Lead IT system security consultation within cloud-based and on-premises environments in accordance with framework specific (NIST SP 800-53, 800-37, OMB, HITRUST CSF, ISO 27002, and other authoritative IT) security guidance
  • Develop System Security Plans, Configuration Management, IT Contingency, and Incident Response Plans, security policies/procedures, risk assessment plan or other requirements in accordance with compliance framework requirements
  • Prepare, review and/or update, and maintain IT Security supporting artifacts
  • Provide guidance to Information System Owners
  • Identify information security problems and challenges, researching and developing technical solutions to rectify them
  • Demonstrate expertise in the control requirements and test procedures of NIST, FISMA, FedRAMP, StateRAMP, DoD, etc.  or other security compliance frameworks.
  • Ensure cybersecurity policies are adhered to and that required controls are implemented.  If the required controls are not implemented provide recommendations to the client to improve their security posture.
  • Validate respective information system security plans to ensure control requirements are met.
  • Develop technical content, such as procedures and policies, risk management tools, etc., that will be used by clients to assist them in elevating/build out their security programs for system authorization.
  • Mentor all project team members on compliance (NIST, FISMA, FedRAMP, StateRAMP, DoD, etc.) specific consulting methodologies.
  • Performing interviews of potential new hires for an intern, associate, consultant, senior consultant and senior manager roles.

What You'll Bring

  • Minimum of 5 years or more of working experience in information technology, information security, technical assessment, or audits
  • Substantial knowledge of security control requirements (NIST, FISMA, FedRAMP, StateRAMP, DoD, etc.) and how they overlap with additional frameworks
  • Significant experience in understanding and applying relevant technical knowledge in FISMA/FedRAMP and other compliance framework assessments within moderate and large hyperscale CSP environments
  • Knowledge in conducting multi-framework consolidated compliance assessment activities
  • Detailed understanding of IT security technologies including network and application security, firewalls, access management, and data protection 
  • Experience with virtualization and cloud technologies 
  • Experience with client-server and traditional on-premises architecture 
  • Familiarity with statutes and regulations across multiple industries relevant to IT  
  • Demonstrated ability to lead moderately complex system assessments/consulting engagements independently
  • Demonstrated ability to assist team members with proper artifact collection and interviewing clients to ascertain control implementation details
  • Demonstrated ability to read and interpret all control families
  • Demonstrated ability to read and interpret firewall rulesets and to create network/boundary/data flow diagrams 
  • Strong written and verbal communication skills including the ability to explain technical matters to a non-technical audience 
  • Strong consulting skills; ability to advise and challenge the status quo while building strong relationships 
  • Ability to build high-trust relationship and credibility quickly 
  • Ability to lead projects successfully and delegate up and across  
  • Ability to prioritize and manage multiple initiatives/projects.    
  • Strong excel skills with ability to develop worksheets with complex formulas  
  • Ability to lead teams small to large teams in the assessment and internal environments
  • Ability to speak to Cloud Service Providers to resolve issues and come to a conclusion of the assessment
  • At least one of the following Advanced certifications or equivalent in cybersecurity or cloud: CISSP, CISA, CISM, CAP, CRISC, and/or cloud specific certification (AWS, GCP, or Azure) or specialty certification in security 
  • Bachelor's degree (four-year college or university) or equivalent education and experience 

Bonus Points

  • Strong knowledge of container-based architectures
  • Knowledge of various cloud environments, including AWS, GCP, and Azure
  • Bachelors of Science degree in a technical field (CIS, MIS, IT, Engineering, or related field)


Why You’ll Want to Join Us
At Coalfire, you’ll find the support you need to thrive personally and professionally. In many cases, we provide a flexible work model that empowers you to choose when and where you’ll work most effectively – whether you’re at home or an office.
Regardless of location, you’ll experience a company that prioritizes connection and wellbeing and be part of a team where people care about each other and our communities. You’ll have opportunities to join employee resource groups, participate in in-person and virtual events, and more. And you’ll enjoy competitive perks and benefits to support you and your family, like paid parental leave, flexible time off, certification and training reimbursement, digital mental health and wellbeing support membership, and comprehensive insurance options.
At Coalfire, equal opportunity and pay equity is integral to the way we do business. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. Coalfire is committed to providing access, equal opportunity, and reasonable accommodation for individuals with disabilities in employment, its services, programs, and activities. To request reasonable accommodation to participate in the job application or interview process, our Human Resources team at HumanResourcesMB@coalfire.com.
Apply now Apply later
  • Share this job via
  • or

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Job stats:  3  0  0
Category: Leadership Jobs

Tags: Application security Audits AWS Azure CISA CISM CISSP Cloud Compliance CRISC DoD FedRAMP Firewalls FISMA GCP HITRUST Incident response ISO 27002 NIST NIST 800-53 Risk assessment Risk management System Security Plan

Perks/benefits: Career development Competitive pay Equity / stock options Flex hours Flex vacation Health care Insurance Parental leave Salary bonus Team events

Regions: Remote/Anywhere North America
Country: United States

More jobs like this

Explore more InfoSec / Cybersecurity career opportunities

Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.