Security certification (CISSP, CISM, CCSP) * Demonstrated technical writing capability: can produce ... Remote-first; occasional workshops may be requested (typically minimal travel). * No clearance ...
Quick apply
Security certification (CISSP, CISM, CCSP) * Demonstrated technical writing capability: can produce ... Remote-first; occasional workshops may be requested (typically minimal travel). * No clearance ...
Quick apply
Security certification (CISSP, CISM, CCSP) * Demonstrated technical writing capability: can produce ... Remote-first; occasional workshops may be requested (typically minimal travel). * No clearance ...
Smyrna, TN · On-site +1
Support secure remote access and vendor access controls for manufacturing support scenarios ... Security certifications such as CISSP, CISM, GIAC/GICSP, Security+, or Microsoft Security ...
Smyrna, TN · On-site +1
Support secure remote access and vendor access controls for manufacturing support scenarios ... Security certifications such as CISSP, CISM, GIAC/GICSP, Security+, or Microsoft Security ...
Goodlettsville, TN · Remote
$107K - $147K/yr
In-depth understanding of PKI, VPN/remote access technologies (CyberArk Alero, GlobalProtect), and ... CISSP, CISM, CISSP-ISSAP, Palo Alto PCNSE, Splunk Certified Architect, or GCP Cloud Security ...
Goodlettsville, TN · Remote
$107K - $147K/yr
In-depth understanding of PKI, VPN/remote access technologies (CyberArk Alero, GlobalProtect), and ... CISSP, CISM, CISSP-ISSAP, Palo Alto PCNSE, Splunk Certified Architect, or GCP Cloud Security ...
Nashville, TN · On-site +1
$132K - $156K/yr
CISA, CRISC, CIPP, CISSP, and CISM. * At least (5) years of experience in IT audit or consulting ... remote and hybrid options What's in it for you: - Working with an industry leader : Be part of a ...
Nashville, TN · On-site +1
$132K - $156K/yr
CISA, CRISC, CIPP, CISSP, and CISM. * At least (5) years of experience in IT audit or consulting ... remote and hybrid options What's in it for you: - Working with an industry leader : Be part of a ...
$15.71 - $16.24
7% of jobs
$16.76 is the 25th percentile. Wages below this are outliers.
$16.24 - $16.78
19% of jobs
$16.78 - $17.32
5% of jobs
$17.32 - $17.85
3% of jobs
$17.85 - $18.39
14% of jobs
The median wage is $18.52 / hr.
$18.39 - $18.92
6% of jobs
$18.92 - $19.46
0% of jobs
$19.46 - $19.99
0% of jobs
$19.99 - $20.53
0% of jobs
$20.95 is the 75th percentile. Wages above this are outliers.
$20.53 - $21.06
26% of jobs
$21.06 - $21.60
20% of jobs
$15
$19
$21
As a Remote CISM, one of the main challenges is maintaining effective oversight and coordination of security policies across diverse, distributed teams and systems. Communicating complex security requirements to non-technical stakeholders, handling real-time incident responses remotely, and staying up-to-date with rapidly evolving cyber threats can also be demanding. However, strong collaboration tools, clear processes, and proactive engagement with IT and business teams make these challenges manageable. Remote CISMs often need to adapt quickly and foster a strong security culture despite not being physically present, which can build valuable leadership and influence skills for career advancement.
To thrive as a Remote CISM (Certified Information Security Manager), you need a solid background in information security governance, risk management, and incident response, supported by a relevant degree and the CISM certification. Familiarity with security frameworks such as ISO 27001, NIST, and proficiency in tools for risk assessment, SIEM, and compliance tracking are critical. Strong communication, leadership, and analytical thinking skills help in coordinating with remote teams and managing security projects effectively. These competencies are essential for ensuring robust information security controls and for successfully mitigating cyber risks in a distributed work environment.
A Remote CISM (Certified Information Security Manager) job involves overseeing and managing an organization's information security program from a remote location. Responsibilities typically include developing security policies, assessing risks, ensuring compliance, and leading incident response efforts. Remote CISM professionals collaborate with teams to protect sensitive data and mitigate cybersecurity threats while working outside of a traditional office setting. Strong communication skills, strategic planning, and knowledge of industry standards like ISO 27001 and NIST frameworks are essential.

Contractor
Posted 24 days ago
C2 Labs is hiring a Senior FedRAMP Consultant (GRC Analyst III equivalent) to act as a lead technical writer for FedRAMP authorization packages and ongoing ConMon operations. If you can translate real-world cloud security implementations into crisp FedRAMP documentation—and you care about making ConMon sustainable—this is a strong fit.
What you’ll do
• Lead drafting of FedRAMP artifacts (20X KSI summaries and/or legacy SSP/policies/plans) and drive iterations to completion.
• Maintain control/KSI-to-evidence traceability in RegScale and keep the evidence library audit-ready.
• Partner with cloud architecture/security engineering resources to ensure technical accuracy.
• Support assessor/sponsor readiness: walkthroughs, responses, and updates.
Role summary
Lead author and coordinator for FedRAMP documentation and evidence traceability. This role functions as a technical writer with security and cloud fluency—able to capture architecture and control/KSI implementations from engineering teams and translate them into FedRAMP artifacts. The Senior Consultant owns the quality of first drafts and mentors junior writers.
Key responsibilities
• Lead customer interviews/workshops to capture system boundary, data flows, shared responsibility model, and control/KSI implementations.
• Draft and iterate FedRAMP artifacts (e.g., 20X KSI implementation summaries and/or legacy SSP sections, policies, and plans).
• Build and maintain traceability between controls/KSIs, evidence, validation methods, and ConMon cadence in RegScale.
• Coordinate evidence collection and organize artifacts into a clean evidence library aligned to the package structure.
• Partner with the Cloud Architect and Security Engineer to ensure technical accuracy of narratives and diagrams.
• Support assessment readiness: conduct package walkthroughs, respond to questions, and update artifacts based on feedback.
• Mentor Junior Consultants on writing standards, template fidelity, and evidence hygiene.
Key deliverables / outputs
• FedRAMP first drafts of major package artifacts (KSI summaries and/or SSP sections).
• Policy and plan artifacts aligned to FedRAMP expectations (e.g., IRP, CP, CMP, ISCM, Rules of Behavior as required).
• Control/KSI-to-evidence traceability in RegScale with validation cadence documented.
• Assessment-ready evidence library with consistent naming/versioning and completeness checks.
Required qualifications
• 5+ years experience in GRC/compliance, security documentation, or audit support roles.
• Security certification (CISSP, CISM, CCSP)
• Demonstrated technical writing capability: can produce clear, consistent narratives for complex systems and controls.
• Working knowledge of NIST 800-53 controls and evidence expectations; familiarity with FedRAMP package structure and templates.
• Comfort collaborating with engineers and architects to accurately describe technical implementations.
• Strong attention to detail (templates, cross-references, tables, and evidence mapping).
Preferred / nice to have
• Bachelors degree in IT, Cybersecurity, or related field
• Prior experience drafting FedRAMP SSPs and/or supporting artifacts (Low/Moderate/High).
• Experience with FedRAMP 20X concepts (KSIs, validation cycles, automation-first evidence).
• Experience working in RegScale or similar GRC tools.
• Audit-related experience.
Tools & environment
• RegScale (controls/KSIs, evidence, workflows, POA&M management)
• Microsoft Word/Excel (FedRAMP templates), Visio/Lucidchart (diagrams) as available
• Ticketing systems for remediation tracking (Jira/Azure DevOps/ServiceNow as customer uses)
Engagement details
• 1099 independent contractor (initial engagement); project-based with potential extension into ConMon operations.
• Remote-first; occasional workshops may be requested (typically minimal travel).
• No clearance required; must be able to pass a standard background check and sign NDA/SOW.
• Hours scale with customer phase (heavy during package drafting; lighter during steady-state ConMon).
EEO Statement
We are an equal opportunity employer. All qualified applicants will be considered without discrimination based on race, color, religion, sex, national origin, age, disability, or protected veteran status. Employment offers will be contingent on passing a pre-employment drug screen.
Practical AI Application