If you can translate real-world cloud security implementations into crisp FedRAMP documentation--and you care about making ConMon sustainable--this is a strong fit. What you'll do * Lead drafting of ...
Quick apply
If you can translate real-world cloud security implementations into crisp FedRAMP documentation--and you care about making ConMon sustainable--this is a strong fit. What you'll do * Lead drafting of ...
Quick apply
If you can translate real-world cloud security implementations into crisp FedRAMP documentation--and you care about making ConMon sustainable--this is a strong fit. What you'll do * Lead drafting of ...
Lead and maintain FedRAMP authorization and ongoing Continuous Monitoring (ConMon) efforts, including coordination with Third Party Assessment Organizations (3PAOs), federal agency sponsors, monthly ...
Lead and maintain FedRAMP authorization and ongoing Continuous Monitoring (ConMon) efforts, including coordination with Third Party Assessment Organizations (3PAOs), federal agency sponsors, monthly ...
Herndon, VA ยท On-site
Ensure compliance with relevant security standards and regulations (e.g., NIST, FedRAMP, FISMA ... Strong knowledge of continuous monitoring (ConMon) systems and processes * Proficiency in using ...
Herndon, VA ยท On-site
Ensure compliance with relevant security standards and regulations (e.g., NIST, FedRAMP, FISMA ... Strong knowledge of continuous monitoring (ConMon) systems and processes * Proficiency in using ...
Ensure compliance with relevant security standards and regulations (e.g., NIST, FedRAMP, FISMA ... Strong knowledge of continuous monitoring (ConMon) systems and processes * Proficiency in using ...
Ensure compliance with relevant security standards and regulations (e.g., NIST, FedRAMP, FISMA ... Strong knowledge of continuous monitoring (ConMon) systems and processes * Proficiency in using ...
Ability to respond effectively to customer's concerns regarding ConMon activities Qualifications ... Experience with FedRAMP and/or other authorization processes and NIST risk management framework
Ability to respond effectively to customer's concerns regarding ConMon activities Qualifications ... Experience with FedRAMP and/or other authorization processes and NIST risk management framework
Ability to respond effectively to customer's concerns regarding ConMon activities Qualifications ... Experience with FedRAMP and/or other authorization processes and NIST risk management framework
Ability to respond effectively to customer's concerns regarding ConMon activities Qualifications ... Experience with FedRAMP and/or other authorization processes and NIST risk management framework
As a Compliance Analyst - FedRAMP, you will play a key role in ensuring Fortra's cloud ... CONMON) of security controls and remediation of POA&M items. * Conduct risk assessments for cloud ...
As a Compliance Analyst - FedRAMP, you will play a key role in ensuring Fortra's cloud ... CONMON) of security controls and remediation of POA&M items. * Conduct risk assessments for cloud ...
... FedRAMP High/Class D security and compliance program. You will own security requirement ... Experience supporting Security Impact Assessments, Significant Change Requests, POA&M/ConMon ...
... FedRAMP High/Class D security and compliance program. You will own security requirement ... Experience supporting Security Impact Assessments, Significant Change Requests, POA&M/ConMon ...
... FedRAMP High/Class D security and compliance program. You will own security requirement ... Experience supporting Security Impact Assessments, Significant Change Requests, POA&M/ConMon ...
... FedRAMP High/Class D security and compliance program. You will own security requirement ... Experience supporting Security Impact Assessments, Significant Change Requests, POA&M/ConMon ...
$150 - $200/hr
Implement continuous monitoring tooling - connect CSPM and GRC platforms into agency pipelines under FedRAMP's Collaborative Continuous Monitoring (CCM) model to replace point-in-time ConMon ...
$150 - $200/hr
Implement continuous monitoring tooling - connect CSPM and GRC platforms into agency pipelines under FedRAMP's Collaborative Continuous Monitoring (CCM) model to replace point-in-time ConMon ...
$49.50 - $67.25/hr
FedRAMP Compliance & Security * Ensure database environments comply with FedRAMP and NIST SP 800-53 ... Support annual assessments, ATO activities, Continuous Monitoring (ConMon), and auditor reviews.
Quick apply
$49.50 - $67.25/hr
FedRAMP Compliance & Security * Ensure database environments comply with FedRAMP and NIST SP 800-53 ... Support annual assessments, ATO activities, Continuous Monitoring (ConMon), and auditor reviews.
Itasca, IL ยท On-site +1
$49.50 - $67.25/hr
FedRAMP Compliance & Security * Ensure database environments comply with FedRAMP and NIST SP 800-53 ... Support annual assessments, ATO activities, Continuous Monitoring (ConMon), and auditor reviews.
Itasca, IL ยท On-site +1
$49.50 - $67.25/hr
FedRAMP Compliance & Security * Ensure database environments comply with FedRAMP and NIST SP 800-53 ... Support annual assessments, ATO activities, Continuous Monitoring (ConMon), and auditor reviews.
Itasca, IL ยท On-site
$49.50 - $67.25/hr
FedRAMP Compliance & Security * Ensure database environments comply with FedRAMP and NIST SP 800-53 ... Support annual assessments, ATO activities, Continuous Monitoring (ConMon), and auditor reviews.
Itasca, IL ยท On-site
$49.50 - $67.25/hr
FedRAMP Compliance & Security * Ensure database environments comply with FedRAMP and NIST SP 800-53 ... Support annual assessments, ATO activities, Continuous Monitoring (ConMon), and auditor reviews.
$110K - $130K/yr
Ensure continuous monitoring outputs meet FedRAMP/FISMA/NIST/CMMC requirements and are always audit-ready. * Identify trends, recurring issues, or systemic risks surfaced through ConMon activities ...
$110K - $130K/yr
Ensure continuous monitoring outputs meet FedRAMP/FISMA/NIST/CMMC requirements and are always audit-ready. * Identify trends, recurring issues, or systemic risks surfaced through ConMon activities ...
$120K - $140K/yr
Ability to ensure product engineering solutions align to and meet NIST SP 800-53, FIPS requirements, and the FedRAMP Continuous Monitoring (ConMon) framework. * Problem Solving: Ability to transform ...
$120K - $140K/yr
Ability to ensure product engineering solutions align to and meet NIST SP 800-53, FIPS requirements, and the FedRAMP Continuous Monitoring (ConMon) framework. * Problem Solving: Ability to transform ...
Ensure continuous monitoring outputs meet FedRAMP/FISMA/NIST/CMMC requirements and are always auditready. * Identify trends, recurring issues, or systemic risks surfaced through ConMon activities and ...
Ensure continuous monitoring outputs meet FedRAMP/FISMA/NIST/CMMC requirements and are always auditready. * Identify trends, recurring issues, or systemic risks surfaced through ConMon activities and ...
Ensure continuous monitoring outputs meet FedRAMP/FISMA/NIST/CMMC requirements and are always auditready. * Identify trends, recurring issues, or systemic risks surfaced through ConMon activities and ...
Ensure continuous monitoring outputs meet FedRAMP/FISMA/NIST/CMMC requirements and are always auditready. * Identify trends, recurring issues, or systemic risks surfaced through ConMon activities and ...
... ConMon) automation, and the security engineering interface with our FedRAMP and ATO boundary partner, for our Federal team in Tysons, Virginia. The ideal candidate will ensure Federal deployments ...
... ConMon) automation, and the security engineering interface with our FedRAMP and ATO boundary partner, for our Federal team in Tysons, Virginia. The ideal candidate will ensure Federal deployments ...
$110K - $120K/yr
Work with team lead to manage incoming FedRAMP 20x ConMon-related changes * Onboard new Motorola product teams into continuous monitoring program * Improve continuous monitoring processes with ...
$110K - $120K/yr
Work with team lead to manage incoming FedRAMP 20x ConMon-related changes * Onboard new Motorola product teams into continuous monitoring program * Improve continuous monitoring processes with ...
Raleigh, NC ยท On-site
$150 - $200/hr
FedRAMP Continuous Monitoring*** Provide oversight and direction for the FedRAMP Continuous Monitoring program, ensuring all ConMon obligations are met in accordance with FedRAMP requirements*
Raleigh, NC ยท On-site
$150 - $200/hr
FedRAMP Continuous Monitoring*** Provide oversight and direction for the FedRAMP Continuous Monitoring program, ensuring all ConMon obligations are met in accordance with FedRAMP requirements*
| Aspect | Fedramp Conmon | Fedramp Security Control Assessor |
|---|---|---|
| Primary Role | Continuous monitoring and compliance oversight of cloud services | Initial security assessment and authorization of cloud systems |
| Certifications | FedRAMP-specific certifications, often including security and compliance training | FISMA, CISSP, or other security assessment certifications |
| Work Environment | Government agencies, cloud service providers, compliance teams | Security assessment firms, government agencies, cloud providers |
| Focus | Ongoing monitoring, incident response, compliance reporting | Initial security assessment, authorization package review |
While Fedramp Conmon focuses on continuous monitoring and maintaining compliance over time, Fedramp Security Control Assessors conduct initial security assessments to grant authorization. Both roles are essential in the FedRAMP process but serve different stages of cloud security management.
Knoxville, TN โข Remote
Contractor
Re-posted 9 hours ago
C2 Labs is hiring a Senior FedRAMP Consultant (GRC Analyst III equivalent) to act as a lead technical writer for FedRAMP authorization packages and ongoing ConMon operations. If you can translate real-world cloud security implementations into crisp FedRAMP documentation—and you care about making ConMon sustainable—this is a strong fit.
What you’ll do
• Lead drafting of FedRAMP artifacts (20X KSI summaries and/or legacy SSP/policies/plans) and drive iterations to completion.
• Maintain control/KSI-to-evidence traceability in RegScale and keep the evidence library audit-ready.
• Partner with cloud architecture/security engineering resources to ensure technical accuracy.
• Support assessor/sponsor readiness: walkthroughs, responses, and updates.
Role summary
Lead author and coordinator for FedRAMP documentation and evidence traceability. This role functions as a technical writer with security and cloud fluency—able to capture architecture and control/KSI implementations from engineering teams and translate them into FedRAMP artifacts. The Senior Consultant owns the quality of first drafts and mentors junior writers.
Key responsibilities
• Lead customer interviews/workshops to capture system boundary, data flows, shared responsibility model, and control/KSI implementations.
• Draft and iterate FedRAMP artifacts (e.g., 20X KSI implementation summaries and/or legacy SSP sections, policies, and plans).
• Build and maintain traceability between controls/KSIs, evidence, validation methods, and ConMon cadence in RegScale.
• Coordinate evidence collection and organize artifacts into a clean evidence library aligned to the package structure.
• Partner with the Cloud Architect and Security Engineer to ensure technical accuracy of narratives and diagrams.
• Support assessment readiness: conduct package walkthroughs, respond to questions, and update artifacts based on feedback.
• Mentor Junior Consultants on writing standards, template fidelity, and evidence hygiene.
Key deliverables / outputs
• FedRAMP first drafts of major package artifacts (KSI summaries and/or SSP sections).
• Policy and plan artifacts aligned to FedRAMP expectations (e.g., IRP, CP, CMP, ISCM, Rules of Behavior as required).
• Control/KSI-to-evidence traceability in RegScale with validation cadence documented.
• Assessment-ready evidence library with consistent naming/versioning and completeness checks.
Required qualifications
• 5+ years experience in GRC/compliance, security documentation, or audit support roles.
• Security certification (CISSP, CISM, CCSP)
• Demonstrated technical writing capability: can produce clear, consistent narratives for complex systems and controls.
• Working knowledge of NIST 800-53 controls and evidence expectations; familiarity with FedRAMP package structure and templates.
• Comfort collaborating with engineers and architects to accurately describe technical implementations.
• Strong attention to detail (templates, cross-references, tables, and evidence mapping).
Preferred / nice to have
• Bachelors degree in IT, Cybersecurity, or related field
• Prior experience drafting FedRAMP SSPs and/or supporting artifacts (Low/Moderate/High).
• Experience with FedRAMP 20X concepts (KSIs, validation cycles, automation-first evidence).
• Experience working in RegScale or similar GRC tools.
• Audit-related experience.
Tools & environment
• RegScale (controls/KSIs, evidence, workflows, POA&M management)
• Microsoft Word/Excel (FedRAMP templates), Visio/Lucidchart (diagrams) as available
• Ticketing systems for remediation tracking (Jira/Azure DevOps/ServiceNow as customer uses)
Engagement details
• 1099 independent contractor (initial engagement); project-based with potential extension into ConMon operations.
• Remote-first; occasional workshops may be requested (typically minimal travel).
• No clearance required; must be able to pass a standard background check and sign NDA/SOW.
• Hours scale with customer phase (heavy during package drafting; lighter during steady-state ConMon).
EEO Statement
We are an equal opportunity employer. All qualified applicants will be considered without discrimination based on race, color, religion, sex, national origin, age, disability, or protected veteran status. Employment offers will be contingent on passing a pre-employment drug screen.
Practical AI Application