1

Fedramp Conmon Jobs (NOW HIRING)

Maintain Cohesity's FedRAMP Class C, GovRAMP Moderate, and CMMC L1/L2 certifications. Lead continuous monitoring (ConMon) efforts and maintenance of required documentation. • Govern the authorized ...

$198K - $247K/yr

Maintain Cohesity's FedRAMP Class C, GovRAMP Moderate, and CMMC L1/L2 certifications. Lead continuous monitoring (ConMon) efforts and maintenance of required documentation. * Govern the authorized ...

$110K - $120K/yr

Work with team lead to manage incoming FedRAMP 20x ConMon-related changes * Onboard new Motorola product teams into continuous monitoring program * Improve continuous monitoring processes with ...

$110K - $120K/yr

Work with team lead to manage incoming FedRAMP 20x ConMon-related changes * Onboard new Motorola product teams into continuous monitoring program * Improve continuous monitoring processes with ...

Security Analyst

Mclean, VA · On-site

$150K - $200K/yr

The ideal candidate brings deep expertise in NIST frameworks, FedRAMP authorization processes, continuous monitoring (ConMon), and ATO lifecycle management, along with the ability to operate in ...

The ideal candidate brings deep expertise in NIST frameworks, FedRAMP authorization processes, continuous monitoring (ConMon), cloud security, incident response, and ATO lifecycle management, along ...

Security Analyst

Mclean, VA · On-site

$150K - $200K/yr

The ideal candidate brings deep expertise in NIST frameworks, FedRAMP authorization processes, continuous monitoring (ConMon), and ATO lifecycle management, along with the ability to operate in ...

Security Engineer

Mclean, VA · On-site

$150K - $200K/yr

The ideal candidate brings deep expertise in NIST frameworks, FedRAMP authorization processes, continuous monitoring (ConMon), cloud security, incident response, and ATO lifecycle management, along ...

Continuous monitoring experience - familiar with executing automated or manual FedRAMP Continuous Monitoring (ConMon) workflows. * Defense framework exposure - complementary exposure to CMMC 2.0 or ...

Support ongoing FedRAMP and IRAP Continuous Monitoring (ConMon) activities to maintain regulatory compliance. * Monitor, investigate, and respond to security events using Microsoft Sentinel ...

Showing results 21-40

Fedramp Conmon information

What is FedRAMP Continuous Monitoring (ConMon)?

FedRAMP Continuous Monitoring (ConMon) is an ongoing process required for cloud service providers (CSPs) that are authorized under the Federal Risk and Authorization Management Program (FedRAMP). It involves regularly assessing and documenting the security posture of a cloud system to ensure it continues to meet federal security requirements after the initial authorization. ConMon includes activities such as vulnerability scanning, patch management, and reporting security incidents, helping to maintain compliance and address emerging threats. This process is essential for keeping federal data secure in cloud environments.

What are the key skills and qualifications needed to thrive as a FedRAMP Continuous Monitoring (ConMon) analyst?

To thrive as a FedRAMP ConMon Analyst, you need expertise in information security, risk assessment, and compliance frameworks, typically supported by a degree in cybersecurity or a related field and relevant experience with federal regulations. Familiarity with security assessment tools (such as Nessus or Qualys), GRC platforms, and certifications like CISSP or CAP is highly valuable. Strong analytical thinking, attention to detail, and clear communication are essential soft skills for this role. These competencies are crucial for maintaining ongoing security compliance and effectively managing risks in cloud environments subject to federal standards.

What are common challenges faced by professionals in FedRAMP Continuous Monitoring (ConMon) roles, and how can they be addressed?

Professionals in FedRAMP ConMon roles often face challenges such as staying current with evolving compliance requirements, managing a high volume of security documentation, and coordinating timely remediation of vulnerabilities with multiple stakeholders. Addressing these challenges involves establishing clear communication channels with system owners and IT teams, leveraging automation tools for security monitoring and reporting, and maintaining a well-organized schedule for periodic assessments. Proactively engaging with all involved parties and continuously updating knowledge on FedRAMP guidelines can help ensure ongoing compliance and reduce stress in this fast-paced environment.

What is the difference between Fedramp Conmon vs Fedramp Security Control Assessor?

AspectFedramp ConmonFedramp Security Control Assessor
Primary RoleContinuous monitoring and compliance oversight of cloud servicesInitial security assessment and authorization of cloud systems
CertificationsFedRAMP-specific certifications, often including security and compliance trainingFISMA, CISSP, or other security assessment certifications
Work EnvironmentGovernment agencies, cloud service providers, compliance teamsSecurity assessment firms, government agencies, cloud providers
FocusOngoing monitoring, incident response, compliance reportingInitial security assessment, authorization package review

While Fedramp Conmon focuses on continuous monitoring and maintaining compliance over time, Fedramp Security Control Assessors conduct initial security assessments to grant authorization. Both roles are essential in the FedRAMP process but serve different stages of cloud security management.

Principal, Public Sector Compliance

Washington, DC • On-site

Madrona Venture Labs
Investment Clubs and Venture Capital Companies • 1 - 10 employees

$198K - $247K/yr

Other

Medical, Life, Retirement, PTO

Posted 22 days ago


Key responsibilities

  • Own and maintain Cohesity's FedRAMP Class C, GovRAMP Moderate, and CMMC L1/L2 certifications, including continuous monitoring and documentation.

  • Manage the significant change process, review and approve changes, and ensure engineering and infrastructure teams understand notification requirements.

  • Serve as the primary interface for third-party assessors during assessment cycles, facilitate evidence gathering, and remediate findings.


Job description

We strongly prefer candidates who are currently located in or near the designated job location. Candidates outside the area should apply only if they are committed to relocating prior to their start date and have the legal right to work in the job location.

Cohesity is a leader in AI-powered data security and management. Aided by an extensive ecosystem of partners, Cohesity makes it easy to secure, protect, manage, and get value from data — across the data center, edge, and cloud. Cohesity helps organizations defend against cybersecurity threats with comprehensive data security and management capabilities, including immutable backup snapshots, AI-based threat detection, monitoring for malicious behavior, and rapid recovery at scale. We’ve been named a Leader by multiple analyst firms and have been globally recognized for Innovation, Product Strength, and Simplicity in Design. Join us on our mission to shape the future of our industry.

THE OPPORTUNITY

We're hiring a Principal, Public Sector Compliance to own our public sector authorization portfolio — FedRAMP Class C (Rev5), GovRAMP Moderate, and CMMC Level 1 and Level 2. This is a named-ownership role: you'll maintain and advance our FedRAMP certification through continuous monitoring and annual assessments, lead the organization through mandatory 2026-2027 regulatory transitions, and shape a federal product roadmap that lets Cohesity compete with peer cloud service providers. You’ll sit at the intersection of compliance, engineering, and product, with full operating autonomy and significant cross-functional influence.

WHAT YOU'LL DO HERE
  • Own authorization integrity. Maintain Cohesity’s FedRAMP Class C, GovRAMP Moderate, and CMMC L1/L2 certifications. Lead continuous monitoring (ConMon) efforts and maintenance of required documentation.
  • Govern the authorized boundary. Manage the significant change process, including review and sign off on changes, and ensuring engineering and infrastructure teams understand what triggers a formal notification requirement.
  • Lead regulatory transitions. Drive adoption of FedRAMP's Consolidated Rules, including new VDR/VER rulesets, and develop a defensible Rev5-to-20x conversion recommendation. Stay informed about evolving framework requirements and translate operational implications to leadership.
  • Own assessment cycles. Serve as the primary interface for third-party assessors across annual FedRAMP and GovRAMP assessments and the triennial CMMC Level 2 assessment — readiness, facilitation, evidence gathering, and finding remediation.
  • Translate compliance into engineering guidance. Convert control requirements into acceptance criteria that engineering and cloud operations teams can act on, and challenge implementations that fall short.
  • Shape the federal offering. Partner with Product Management and Federal Sales to deliver a compliant offering that supports business growth and drives competitive advantage.
  • Build the AI-enabled compliance program. Own machine-readable, AI-consumable artifact schemas, set the evidentiary standard automated work must meet, and help move the program from human-heavy to agent- leveraged operations.
WHAT YOU'LL BRING
  • 8–10 years of hands‑on FedRAMP program experience, including named ownership of a Cloud Service Provider authorization through multiple full 3PAO assessment cycles at Moderate and High impact levels. Direct accountability for the SSP, Collaborative ConMon, POA&M, significant change management, and 3PAO
  • Operational depth in continuous monitoring, including POA&M management, vulnerability management, ConMon deliverable production, and federal agency sponsor relationship management.
WHY JOIN COHESITY

You’ll take on named ownership of a growing public sector compliance program at a pivotal moment — helping Cohesity expand its federal authorization footprint, compete for new agency business, and build the AI-enabled compliance practices that will define how the next generation of cloud service providers operate.

Pay Range : $198,000.00-$247,500.00

The compensation noted above is based on an annualized hourly rate assuming normal full-time employment.

Data Privacy Notice for Job Candidates: For information on personal data processing, please see our Privacy Policy.

our comprehensive benefits framework, including

  • health and wellness benefits
  • vacation
  • paid holidays and refresh days
  • 401(k) retirement plan
  • life and disability insurance coverages
  • other benefits the Company may offer from time to time

Equal Employment Opportunity Employer (EEOE)

Cohesity is an Equal Employment Opportunity Employer.

All qualified applicants will receive consideration for employment without regard to race, color, creed, religion, sex, sexual orientation, national origin or nationality, ancestry, age, disability, gender identity or expression, marital status, veteran status or any other category protected by law.

If you are an individual with a disability and require a reasonable accommodation to complete any part of the application process, or are limited in the ability or unable to access or use this online application process and need an alternative method for applying, you may contact us at 1-855-9COHESITY or recruiting@cohesity.com for assistance.

In-Office Expectations

Cohesity employees who are within a reasonable commute (e.g. within a forty-five (45) minute average travel time) work out of our core offices 2-3 days a week of their choosing.

Interested candidates based outside of the designated areas are welcome to apply, provided they have the right to work in the job location.

#J-18808-Ljbffr