1

Fedramp Audit Jobs (NOW HIRING)

FedRAMP audit lead or hands-on control implementation experience * CISSP and other similar technical certifications * Experience implementing Governance, Risk, and Compliance (GRC) tools * Experience ...

All of this is accomplished through deep industry knowledge of risk, governance, internal audit ... Document control test results based on FedRAMP-defined test case procedures * Assistin completing ...

All of this is accomplished through deep industry knowledge of risk, governance, internal audit ... Document control test results based on FedRAMP-defined test case procedures * Assistin completing ...

All of this is accomplished through deep industry knowledge of risk, governance, internal audit ... Document control test results based on FedRAMP-defined test case procedures * Assistin completing ...

All of this is accomplished through deep industry knowledge of risk, governance, internal audit ... Possess strong knowledge of FedRAMP, GovRAMP, and NIST * Critical thinking, analytical, writing ...

New

All of this is accomplished through deep industry knowledge of risk, governance, internal audit ... Possess strong knowledge of FedRAMP, GovRAMP, and NIST * Critical thinking, analytical, writing ...

Showing results 21-40

Fedramp Audit information

See salary details

$61K

$120.2K

$157.5K

How much do fedramp audit jobs pay per year?

As of Sep 14, 2026, the average yearly pay for fedramp audit in the United States is $120,236.00, according to ZipRecruiter salary data. Most workers in this role earn between $104,000.00 and $136,500.00 per year, depending on experience, location, and employer.

What is a FedRAMP audit?

A FedRAMP audit is a comprehensive assessment of a cloud service provider's security controls to ensure compliance with the Federal Risk and Authorization Management Program (FedRAMP) requirements. The audit is conducted by a Third Party Assessment Organization (3PAO) and examines whether the provider meets federal security standards for protecting government data. This process includes reviewing documentation, testing security measures, and producing a report that determines if the cloud service can be used by federal agencies. Successful completion of a FedRAMP audit is required for cloud providers to offer their services to the U.S. government.

What are the key skills and qualifications needed to thrive as a FedRAMP auditor?

To thrive as a FedRAMP Auditor, you need a strong background in information security, risk assessment, and compliance, typically supported by relevant certifications such as CISSP, CISA, or Certified Third Party Assessor Organization (3PAO) credentials. Familiarity with security frameworks (like NIST SP 800-53), cloud service provider platforms, and audit management tools is essential. Attention to detail, analytical thinking, and effective communication are critical soft skills for evaluating complex systems and conveying findings to stakeholders. These skills ensure accurate assessments, regulatory compliance, and effective risk mitigation in cloud environments handling federal data.

What are some common challenges faced by professionals during a FedRAMP audit process?

One of the main challenges in a FedRAMP audit is ensuring that all required documentation and evidence are thorough and up-to-date, as the process is highly rigorous and detail-oriented. Auditors must also navigate frequent changes in compliance requirements and maintain clear communication between cloud service providers, security teams, and government stakeholders. Additionally, managing timelines can be difficult due to the complexity of system assessments and the need for multiple rounds of remediation and validation before achieving authorization.

What is the difference between Fedramp Audit vs Security Assessor?

AspectFedramp AuditSecurity Assessor
CertificationsFedRAMP-specific auditor certifications, e.g., FedRAMP Authorized AssessorISC2 CISSP, CISA, or similar security certifications
Work EnvironmentPrimarily government agencies and cloud service providers undergoing FedRAMP complianceConsulting firms, government agencies, or private sector organizations assessing security controls
Industry UsageFederal cloud service providers, government contractorsVarious industries including government, finance, healthcare

While both roles focus on security assessments, a Fedramp Audit specifically evaluates cloud service providers' compliance with FedRAMP standards, whereas a Security Assessor conducts broader security evaluations across various frameworks and industries.

More about Fedramp Audit jobs
Infographic showing various Fedramp Audit job openings in the United States as of September 2026, with employment types broken down into 1% Internship, 92% Full Time, 5% Part Time, and 2% Contract. Highlights an 85% Physical, 5% Hybrid, and 10% Remote job distribution, with an average salary of $120,236 per year, or $57.8 per hour.

Senior Security Operations Engineer, FedRAMP

Mclean, VA โ€ข On-site

Medallia
IT Servicesย โ€ขย 1 - 5K employees

$128K - $188K/yr

Other

Medical, Dental, Vision, Life, Retirement

Posted 12 days ago


Job description

Overview

Medallia is the pioneer and market leader in Experience Management. Our award-winning SaaS platform, Medallia Experience Cloud, leads the market in the management of experiences, insights, and actions for candidates, customers, employees, patients, and residents alike.

We believe that every experience is a memory that can last a lifetime. Experiences shape the way people feel about a company. And they greatly influence how likely people are to advocate, contribute, and stay. At Medallia, we are committed to creating a world where organizations are loved by their customers and their employees.

We empower exceptional people to create extraordinary experiences together.

Bring your whole self.

The Role and Team

We are looking for a motivated FedRAMP security engineer who is ready to explore the world of Federal Security (FedRAMP and beyond) and GRC Engineering. This role will have a heavy focus on GRC Engineering and FedRAMP compliance and security automation. This is a technical role that not only develops and implements security solutions but uses the solutions to combat malicious cyber attacks while satisfying FedRAMP compliance requirements. While Medallia FedRAMP is a well established FedRAMP certified CSP this is a growing and rapidly evolving landscape with an ever growing range of technologies, tools and a significant potential to grow within the team.

Responsibilities
  • Full lifecycle security tool management including selecting, deploying, integrating, maintaining, and twilight security technologies such as SIEMโ€™s, Log Management, Vulnerability Management Platforms, AV, etc.
  • Security alert and incident management with a focus on alert and threat hunting automation
  • Will provide technical support for compliance and security audits and will be the subject matter expert for FedRAMP security controls during audits
  • GRC Engineering for compliance automation
  • This is a technical hands on position that will have opportunities for coding, scripting and automation as well as continually learning and understanding new technologies

Candidates based in the Tysons vicinity will be prioritized as this role is Hybrid, 3 days per week onsite.

Qualifications Minimum Qualifications
  • Eligibility Requirement: Must reside in the U.S. and hold U.S. Citizenship or a Green Card (Lawful Permanent Resident) to meet FedRAMP compliance requirements.
  • 5+ years of progressive experience in Security Operations, cloud security, or security systems engineering (managing servers, DB, AWS cloud infrastructure, and core enterprise security tools).
  • Demonstrated experience writing Python code to build security utilities, interact with APIs, and drive system automation.
  • Proven track record directly administering, configuring, and managing enterprise security toolsets throughout their lifecycle.
Preferred Qualifications
  • Deep practical understanding of cybersecurity fundamentals, threat models, and regulatory frameworks (specifically NIST SP 800-53 and FedRAMP Moderate/High standards) and supporting continuous monitoring in FedRAMP environments.
  • Direct experience building and maintaining custom Splunk applications
  • Proven ability to translate non-technical business and regulatory requirements into scalable technical solutions.
  • Independent problem-solving capabilities with exceptional written and verbal cross-team communication skills.

Medallia is committed to equal pay and transparency. The annual base salary range for this position is $128,500- $188,000. Please note that the salary range information provided is a general guideline and combines all of the distinct labor markets within the US. It is uncommon for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on a variety of factors. Medallia considers factors such as (but not limited to) scope and responsibilities of the position, candidateโ€™s work experience, candidateโ€™s work location, education/training, key skills, internal peer equity, external market data, as well as, market and business considerations when making compensation decisions.

Medallia also offers competitive health and wellness benefits, including but not limited to medical, dental, vision, 401(k), short-term and long-term disability, life and AD&D insurance, statutory leaves, paid parental leave, and paid holidays. Benefits and eligibility may vary by location and role.

At Medallia, we celebrate diversity and recognize the value it brings to our customers and employees. Medallia is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age (40 and over), disability, genetic information, veteran status or military service, or any other status protected by state or local law. Individuals with a disability who need an accommodation to apply please contact us at ApplicantAccessibility@medallia.com. For information regarding how Medallia collects and uses personal information, please review our Privacy Policies. Applications will be accepted for 30 days from the date this role was posted or until the role has been filled.

#J-18808-Ljbffr