Senior Compliance Engineering Architect (FedRAMP 20x)
UberEther · Sterling, VA · 1 mo ago
$170k–$210k/yrFull-time
Responsibilities
- Serve as the principal technical authority translating FedRAMP 20x KSI requirements into platform architecture decisions for the engagement
- Define and maintain the technical roadmap for mapping all KSIs across the FedRAMP KSI families to concrete GCP services, configurations, and evidence sources for the Advantage compliance model
- Lead architecture reviews and design sessions with engineering leadership to ensure GCP deployments satisfy FedRAMP 20x assessment requirements
- Drive technical decision-making on control inheritance, continuous monitoring strategy, and KSI verification approach for a GCP-hosted identity platform
- Partner with the Compliance BU leadership team to translate FedRAMP 20x milestones into technical initiatives and delivery rocks
- Establish architectural standards and design patterns for KSI-mapped platform components that can be reused across future GCP engagements
- Own the end-to-end technical architecture that maps all FedRAMP 20x KSIs onto concrete Advantage GCP service configurations, IAM policies, and network controls
- Lead the design of Infrastructure as Code templates (Terraform, Deployment Manager) that encode KSI requirements directly into GCP deployments
- Drive automation initiatives that generate continuous compliance evidence directly from GCP-native logging, monitoring, and security services
- Provide architectural guidance on GCP IAM, VPC Service Controls, Cloud KMS, and Security Command Center as they relate to KSI satisfaction
- Collaborate with the Engineering team to align GCP-specific automation with UberEther's existing GitLab and Terraform tooling
- Champion a KSI-first design approach so security and compliance controls are architected in from day one, not retrofitted
- Serve as the escalation point for complex FedRAMP 20x KSI questions from the engineering and Customer Success teams
- Lead technical architecture workshops with stakeholders to walk through KSI-to-control mappings and remediation paths
- Provide expert guidance on translating KSI evidence requirements into System Security Plan (SSP) and machine readable/OSCAL-based technical documentation
- Support pre-sales and advisory activities by explaining FedRAMP 20x architecture decisions during customer briefings
- Translate platform requirements into technical designs that align with Advantage delivery model
- Drive continuous improvement of the KSI mapping based on assessor feedback, CR26 verification results, and evolving FedRAMP 20x guidance
- Work closely with the DevOps and Support functions to ensure GCP monitoring, dashboards, and alerting align with KSI evidence requirements
- Lead the technical design of automated KSI verification, including how each of the KSI families is evidenced on an ongoing basis
- Provide architectural guidance for remediation runbooks and system hardening standards specific to GCP-hosted workloads
- Support 3PAO assessments and FedRAMP 20x reviews by explaining the platform architecture and how it satisfies each KSI
- Ensure proper integration between GCP-native security tooling and UberEther's compliance automation approach
- Foster technical collaboration between UberEther's Compliance BU and engineering team through regular architecture syncs
- Mentor engineers on GCP architecture, FedRAMP 20x KSI requirements, and secure design principles
- Lead retrospectives focused on improving the KSI-to-architecture mapping process for future GCP engagements
- Develop training content to help engineers understand FedRAMP 20x KSI requirements and their architectural implications
- Serve as a technical ambassador for UberEther's FedRAMP 20x advisory capabilities with future GCP customers
Qualifications
- Bachelor's degree in Computer Science, Engineering, Cybersecurity, or related technical field; Master's degree preferred
- 10+ years of experience in cloud architecture, security engineering, or compliance-focused technical roles
- 5+ years of experience architecting solutions on Google Cloud Platform (GCP) in a security- or compliance-sensitive environment
- Proven track record of translating FedRAMP, DoD, or other federal compliance frameworks into technical architecture
- Expert-level knowledge of Google Cloud Platform (GCP) services, security controls, and compliance capabilities, with relevant certifications (Professional Cloud Architect or Professional Cloud Security Engineer preferred)
- Strong understanding of FedRAMP 20x Key Security Indicators (KSIs) and how they map to concrete platform controls
- Deep expertise in Infrastructure as Code tools (Terraform, Deployment Manager) and GitOps workflows
- Comprehensive knowledge of Identity and Access Management solutions and Zero Trust architecture principles
- Experience with compliance automation and evidence-generation tooling, including OSCAL and Policy as Code frameworks
- Expert understanding of FedRAMP 20x requirements, KSI families, and continuous compliance obligations
- Deep knowledge of NIST 800-53 security controls and their technical implementation on Google Cloud Platform
- Strong familiarity with FedRAMP authorization processes and Assessment & Authorization (A&A) activities
- Experience with FISMA, FIPS 140-2, and related federal security requirements
- Proven ability to translate compliance requirements directly into technical architectures and control implementations
- Exceptional communication skills with ability to explain complex KSI and compliance concepts to engineers, assessors, and executives
- Prior experience supporting a FedRAMP 20x pilot engagement
- Background in software or platform architecture on Google Cloud Platform specifically
- Published thought leadership in cloud security, compliance automation, or FedRAMP 20x
- Experience with compliance automation frameworks such as OSCAL, InSpec, or similar Policy as Code tools