Jobs · Virginia

Senior Compliance Engineering Architect (FedRAMP 20x)

UberEther · Sterling, VA · 1 mo ago
$170k–$210k/yrFull-time

Responsibilities

  • Serve as the principal technical authority translating FedRAMP 20x KSI requirements into platform architecture decisions for the engagement
  • Define and maintain the technical roadmap for mapping all KSIs across the FedRAMP KSI families to concrete GCP services, configurations, and evidence sources for the Advantage compliance model
  • Lead architecture reviews and design sessions with engineering leadership to ensure GCP deployments satisfy FedRAMP 20x assessment requirements
  • Drive technical decision-making on control inheritance, continuous monitoring strategy, and KSI verification approach for a GCP-hosted identity platform
  • Partner with the Compliance BU leadership team to translate FedRAMP 20x milestones into technical initiatives and delivery rocks
  • Establish architectural standards and design patterns for KSI-mapped platform components that can be reused across future GCP engagements
  • Own the end-to-end technical architecture that maps all FedRAMP 20x KSIs onto concrete Advantage GCP service configurations, IAM policies, and network controls
  • Lead the design of Infrastructure as Code templates (Terraform, Deployment Manager) that encode KSI requirements directly into GCP deployments
  • Drive automation initiatives that generate continuous compliance evidence directly from GCP-native logging, monitoring, and security services
  • Provide architectural guidance on GCP IAM, VPC Service Controls, Cloud KMS, and Security Command Center as they relate to KSI satisfaction
  • Collaborate with the Engineering team to align GCP-specific automation with UberEther's existing GitLab and Terraform tooling
  • Champion a KSI-first design approach so security and compliance controls are architected in from day one, not retrofitted
  • Serve as the escalation point for complex FedRAMP 20x KSI questions from the engineering and Customer Success teams
  • Lead technical architecture workshops with stakeholders to walk through KSI-to-control mappings and remediation paths
  • Provide expert guidance on translating KSI evidence requirements into System Security Plan (SSP) and machine readable/OSCAL-based technical documentation
  • Support pre-sales and advisory activities by explaining FedRAMP 20x architecture decisions during customer briefings
  • Translate platform requirements into technical designs that align with Advantage delivery model
  • Drive continuous improvement of the KSI mapping based on assessor feedback, CR26 verification results, and evolving FedRAMP 20x guidance
  • Work closely with the DevOps and Support functions to ensure GCP monitoring, dashboards, and alerting align with KSI evidence requirements
  • Lead the technical design of automated KSI verification, including how each of the KSI families is evidenced on an ongoing basis
  • Provide architectural guidance for remediation runbooks and system hardening standards specific to GCP-hosted workloads
  • Support 3PAO assessments and FedRAMP 20x reviews by explaining the platform architecture and how it satisfies each KSI
  • Ensure proper integration between GCP-native security tooling and UberEther's compliance automation approach
  • Foster technical collaboration between UberEther's Compliance BU and engineering team through regular architecture syncs
  • Mentor engineers on GCP architecture, FedRAMP 20x KSI requirements, and secure design principles
  • Lead retrospectives focused on improving the KSI-to-architecture mapping process for future GCP engagements
  • Develop training content to help engineers understand FedRAMP 20x KSI requirements and their architectural implications
  • Serve as a technical ambassador for UberEther's FedRAMP 20x advisory capabilities with future GCP customers

    Qualifications

    • Bachelor's degree in Computer Science, Engineering, Cybersecurity, or related technical field; Master's degree preferred
    • 10+ years of experience in cloud architecture, security engineering, or compliance-focused technical roles
    • 5+ years of experience architecting solutions on Google Cloud Platform (GCP) in a security- or compliance-sensitive environment
    • Proven track record of translating FedRAMP, DoD, or other federal compliance frameworks into technical architecture
    • Expert-level knowledge of Google Cloud Platform (GCP) services, security controls, and compliance capabilities, with relevant certifications (Professional Cloud Architect or Professional Cloud Security Engineer preferred)
    • Strong understanding of FedRAMP 20x Key Security Indicators (KSIs) and how they map to concrete platform controls
    • Deep expertise in Infrastructure as Code tools (Terraform, Deployment Manager) and GitOps workflows
    • Comprehensive knowledge of Identity and Access Management solutions and Zero Trust architecture principles
    • Experience with compliance automation and evidence-generation tooling, including OSCAL and Policy as Code frameworks
    • Expert understanding of FedRAMP 20x requirements, KSI families, and continuous compliance obligations
    • Deep knowledge of NIST 800-53 security controls and their technical implementation on Google Cloud Platform
    • Strong familiarity with FedRAMP authorization processes and Assessment & Authorization (A&A) activities
    • Experience with FISMA, FIPS 140-2, and related federal security requirements
    • Proven ability to translate compliance requirements directly into technical architectures and control implementations
    • Exceptional communication skills with ability to explain complex KSI and compliance concepts to engineers, assessors, and executives
    • Prior experience supporting a FedRAMP 20x pilot engagement
    • Background in software or platform architecture on Google Cloud Platform specifically
    • Published thought leadership in cloud security, compliance automation, or FedRAMP 20x
    • Experience with compliance automation frameworks such as OSCAL, InSpec, or similar Policy as Code tools

Similar jobs