1

Fedramp Program Manager Jobs in Delaware (NOW HIRING)

The candidate should be well-versed in cloud-native security controls, security posture management ... FedRAMP. Data Security: The candidate must demonstrate an understanding of data classification ...

Fedramp Program Manager information

What are the key skills and qualifications needed to thrive as a FedRAMP Program Manager, and why are they important?

To thrive as a FedRAMP Program Manager, you need expertise in cloud security, risk management, compliance frameworks, and a solid understanding of FedRAMP requirements, usually backed by a degree in IT, cybersecurity, or a related field. Familiarity with tools like GRC (Governance, Risk, and Compliance) platforms, NIST SP 800-53 controls, and certifications such as CISSP or PMP is highly beneficial. Strong project management, stakeholder communication, and problem-solving skills set candidates apart in this role. These competencies are essential for guiding organizations through complex FedRAMP authorization processes and ensuring ongoing compliance with federal security standards.

What is a FedRAMP Program Manager?

A FedRAMP Program Manager is a professional responsible for overseeing and coordinating the process of achieving and maintaining Federal Risk and Authorization Management Program (FedRAMP) compliance for cloud service providers or government agencies. They manage documentation, security assessments, and communication with stakeholders to ensure all requirements are met according to federal standards. Their role is crucial for enabling secure cloud adoption within U.S. government agencies, as they guide the project through the FedRAMP authorization process from start to finish.

What are the main challenges a FedRAMP Program Manager faces when coordinating compliance efforts across multiple teams?

A FedRAMP Program Manager often navigates complex challenges such as aligning cross-functional teams—including IT, security, legal, and operations—to meet rigorous federal cloud security requirements and tight deadlines. Coordinating documentation, ensuring continuous monitoring, and responding to security assessments demand strong project management and communication skills. Additionally, managing evolving compliance standards and liaising with external auditors or government representatives can add to the complexity. Success in this role depends on the ability to facilitate collaboration, maintain meticulous records, and quickly adapt to regulatory updates.

What is the difference between Fedramp Program Manager vs Cloud Security Manager?

AspectFedramp Program ManagerCloud Security Manager
CertificationsFedRAMP certifications, PMP, CISSPCISSP, CCSP, Cloud Security certifications
Work EnvironmentFederal agencies, cloud service providers, government projectsPrivate sector, cloud service providers, enterprise security teams
Industry UsageFederal government compliance, cloud authorizationCloud security strategy, risk management

The Fedramp Program Manager primarily focuses on managing FedRAMP compliance and federal cloud authorization processes, often working within government or contractor environments. In contrast, the Cloud Security Manager oversees overall cloud security strategies and risk mitigation in private or enterprise settings. While both roles require cloud security knowledge and certifications like CISSP, their scope and industry focus differ significantly.

What are popular job titles related to Fedramp Program Manager jobs in Delaware? For Fedramp Program Manager jobs in Delaware, the most frequently searched job titles are:
What job categories do people searching Fedramp Program Manager jobs in Delaware look for? The top searched job categories for Fedramp Program Manager jobs in Delaware are:
What cities in Delaware are hiring for Fedramp Program Manager jobs? Cities in Delaware with the most Fedramp Program Manager job openings:
Cloud Security Engineer

Cloud Security Engineer

Stefanini

Dover, DE • On-site

Other

Posted 18 days ago


Job description


Stefanini Group is hiring!
Stefanini is looking for Cloud Security Engineer in Dover, DE (Onsite)
For quick Apply, please reach out to Rachit Rastogi - call: / email:
Work Hours: M-F (37 hours)
Work Location: Dover, DE (Onsite)
Shift: 1st Shift
This role requires a highly skilled and experienced cloud security professional with a deep understanding of securing cloud workloads, tools, and services. A strong preference would be given to candidates with prior Zero Trust Network Access (ZTNA) principles and a proven track record of implementing and managing secure cloud environments across multiple platforms. The ideal candidate will possess a strong combination of technical expertise and operational leadership. A candidate that brings strong experience in Google Cloud Platform cloud services to the state's multi-cloud program would be desired.
Technical Skills:
Zero Trust Network Access (ZTNA): The candidate must have extensive experience in ZTNA engineering and automation, ensuring secure, scalable, and policy-driven access control. This includes architecting and approving ZTNA configurations, implementing identity-aware segmentation, enforcing least privilege access policies, and leading the transition from traditional VPNs to ZTNA solutions. A deep understanding of NIST 800-207 and Zero Trust Architecture best practices is essential, along with hands-on experience with ZTNA technologies, particularly Zscaler.
Cloud Platform Expertise: The candidate must demonstrate a comprehensive understanding of cloud security platforms and Infrastructure as A service (IAAS) solution providers like Google, Amazon, and Microsoft. This includes in-depth knowledge of each provider's security services (e.g., IAM, security centers, firewalls, key management, logging, and monitoring tools), as well as the ability to design and implement secure cloud architecture. The candidate should be well-versed in cloud-native security controls, security posture management (CSPM) tools, and best practices for ensuring compliance with relevant security frameworks (NIST, ISO, SOC 2).
Identity and Access Management (IAM): Working knowledge of IAM concepts and best practices is crucial, with specific experience in Okta preferred. The candidate should be proficient in implementing least privilege access controls, federation, single sign-on (SSO), and other IAM solutions across multiple cloud platforms.
Security Automation and Orchestration: The candidate should possess a strong understanding of automation pipelines and experience with scripting and automation tools such as Python, Terraform, CloudFormation, and Azure Resource Manager. The ability to automate security tasks and processes, as well as experience with Security Orchestration, Automation and Response (SOAR) platforms are highly desirable.
Security Monitoring and Incident Response: Experience with Security Information and Event Management (SIEM) logging and analysis is essential, along with an understanding of Endpoint Detection and Response (EDR) and Extended Detection and Response (XDR) concepts. The candidate must be capable of analyzing security logs and alerts, conducting threat hunting, and participating in incident response procedures and methodologies.
Security Policy, Compliance, and Governance: A working knowledge of current security policies, federal and state compliance regulations, and governance standards is necessary. The candidate should be able to implement security. controls to meet compliance requirements and have experience with cloud-specific compliance frameworks like FedRAMP.
Data Security: The candidate must demonstrate an understanding of data classification standards and experience with data loss prevention (DLP) configurations.
Network Security: A deep understanding of modern networking standards, including Zero Trust principles, is crucial. The candidate should have extensive experience with network security concepts and technologies, including firewall management, intrusion detection/prevention systems (IDS/IPS), network segmentation, VPNs, routing and switching protocols, network traffic analysis, and network security tools (e.g., Wireshark, tcpdump). Experience with Network Access Control (NAC), DNS security, load balancers, and web application firewalls (WAFs) is also highly desirable.
Endpoint Security: The candidate should possess an understanding of endpoint security concepts and technologies.
Job Requirements:
Education and Certifications (Preferred): Bachelor's or Master's degree in Computer Science, Information Security, or a related field.Relevant certifications (e.g., CISSP, CCSP, AWS Certified Security - Specialty, Google Cloud Certified Professional Cloud Security Engineer, Microsoft Certified: Azure Security Engineer Associate).
Experience Level: Minimum of 7-10 years of experience in information security, with a focus on cloud security and ZTNA.Significant experience with Google Cloud Platform, AWS, and/or Azure.Demonstrated experience in implementing and managing ZTNA solutions.
Required Skills: The candidate must have extensive experience in ZTNA engineering and automation,Experience with Security Information and Event Management (SIEM)The candidate must demonstrate an understanding of data classification standards and experience with data loss prevention (DLP) configurations.The candidate should possess an understanding of endpoint security concepts and technologies.Strong analytical and problem-solving skills are vital, along with the ability to think critically and strategically, anticipate security risks, and develop effective mitigation strategies.
Soft Skills & Experience:
Leadership and Communication: The candidate should be able to lead and mentor junior security engineers, possess excellent communication and presentation skills, and effectively explain complex technical concepts to non-technical audiences.
Problem-Solving and Critical Thinking: Strong analytical and problem-solving skills are vital, along with the ability to think critically and strategically, anticipate security risks, and develop effective mitigation strategies.
Listed salary ranges may vary based on experience, qualifications, and local market. Also, some positions may include bonuses or other incentives.
Stefanini takes pride in hiring top talent and developing relationships with our future employees. Our talent acquisition teams will never make an offer of employment without having a phone conversation with you. Those face-to-face conversations will involve a description of the job for which you have applied. We also speak with you about the process, including interviews and job offers.
About Stefanini GroupThe Stefanini Group is a global provider of offshore, onshore, and near shore outsourcing, IT digital consulting, systems integration, application, and strategic staffing services to Fortune 1000 enterprises around the world. Our presence is in countries like the Americas, Europe, Africa, and Asia, and more than four hundred clients across a broad spectrum of markets, including financial services, manufacturing, telecommunications, chemical services, technology, public sector, and utilities. Stefanini is a CMM level 5, IT consulting company with a global presence. We are CMM Level 5 company.
#LI-RR1
#LI-ONSITE