Lead FedRamp Analyst

  • R9354
  • MA, United States
  • Arlington, VA, United States

Lead FedRamp Analyst


This role is for someone who is looking to positively impact Rapid7’s future with US public sector cybersecurity programs. Previous robust experience driving complex compliance programs as FedRamp would set up for success in this position. Your ability to successfully carry out cross-functional work will require strong communication skills, patience, and a solution-oriented attitude

In this role you will be part of an energized team that cares deeply about the success of these initiatives, and leadership that values work-life balance, an inclusive culture, and your ongoing career development.

About the Team


Rapid7’s Trust & Governance team functions within the Information Security group and plays a crucial role in supporting the organization’s mission. We ensure we meet our duty of care to our customers, employees, and shareholders by creating effective governance for upholding internal security policies, identifying and managing security risk, distributing foundational security expertise across every department to create an exceptional security culture, and bolstering customer and community trust by providing accessible and transparent information about our internal security program. This role partners closely with other InfoSec teams, Engineering, Platform, Legal, Procurement, and many other teams at Rapid7.

About the Role


We’re looking for a Lead FedRamp Analyst to own, drive and improve Rapid7’s FedRamp compliance program and shape the future of US public sector cybersecurity programs. 

In this role, you will:

  • Upgrade Rapid7’s US Cybersecurity Compliance program to the next level

  • Lead and orchestrate the management of the FedRamp compliance program ensuring regulatory requirements and security policies are followed

  • Act as main point of contact for all FedRamp compliance activities coordinating and managing relationships with all stakeholders (Internal and external)

  • Update and coordinate documentation changes in key documents, authorization packages and compliance reports 

  • Ensure readiness for ATO assessments and ConMon reporting 

  • Analyze Control Implementation Summaries (CIS) and Customer Responsibility Matrixes (CRMs) from Rapid7 vendors and analyze and define Rapid7’s CIS and CRM Strive for process improvement and proactive risk identification and mitigation

  • Report and provide visibility of FedRamp status and other Public Sector related initiatives to senior management and wide variety of stakeholders

  • Influence engineering team to ensure seamless adoptions of regulatory requirements

  • Partner with sales and customer success management to simplify the customers experience understanding FedRamp compliance 

The skills you’ll bring include:

  • 7+ years of experience in security compliance programs

  • 5+ years of experience at FedRamp

  • Certifications as CISSP, CISA, CRISC or CISA highly desirable

  • Experience with GRC tools such as Diligent or OneTrust

  • Strong knowledge of NIST 800-53 rev5 and foundational knowledge of NIST 800-171 and FIPS 199

  • Foundational knowledge of CMMC, FISMA, StateRamp and the Federal acquisition process (FAR/DFAR)

  • Experience with Secure Software Development Cycle and equivalent best practices as NIST 800-218, familiar with SBOMs (Software Bill of Materials)  and supply chain risk management

  • Context on the Executive Order 14028 and other big regulatory developments in the US that will impact the present and future of cybersecurity

  • Strong background leading and orchestrating Business Continuity Plans, Disaster Recovery Plans and Contingency plans and related activities 

  • Experience interfacing with Federal Agencies (for security), 3PAOs and other applicable stakeholders

  • Knowledge of AWS and other big SaaS players 

  • Strong communication skills with the ability to translate complex technical concepts into business language

We know that the best ideas and solutions come from multi-dimensional teams. That’s because these teams reflect a variety of backgrounds and professional experiences. If you are excited about this role and feel your experience can make an impact, please don’t be shy - apply today.

 

About Rapid7


Rapid7 (NASDAQ: RPD) helps organizations across the globe protect what matters most so innovation can thrive in an increasingly connected world. Our comprehensive technology, services, and community-focused research simplify the complex for security teams, helping them reduce vulnerabilities, monitor for malicious behavior, be in 10 places at once, and shut down attacks. We’re on a mission to make security solutions easier to use and access so we can bring safety and resilience to more people.  With more than 10,000 customers across 140+ countries, Rapid7 is a leader in cybersecurity that has earned numerous industry accolades and recognition for our technology and culture.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, protected veteran status or any other status protected by applicable national, federal, state or local law.

Security and Compliance
Rapid7 is committed to keeping customers secure. As a first line of defense, all employees are expected to uphold the highest standards of security and privacy, ensuring the protection of sensitive information and compliance with relevant regulations.

Apply Now

Not You?

We have emailed you a code to verify your identity. Please check your spam/junk folder if you don't receive the email in your inbox.

Application loading...

 

Jobs you may be interested in

Renewal Account Manager L2

R9234 Utrecht Netherlands Utrecht, Netherlands Sales & BD Sales Full_time JOB_LEVEL-3-13
Renewal Account Manager L2 We are seeking a proactive and results-driven Renewal Account Manager to oversee and manage the renewal process for clients in our existing customer base. The ideal candidate will have a proven track record in renewals m...

Vice President, Financial Planning & Analysis

R9423 Boston MA United States Boston, MA, United States Finance Finance Full_time JOB_LEVEL-3-52
VP of Financial Planning & Analysis  Rapid7’s Vice President of Financial Planning & Analysis will be a key strategic partner to the executive team, responsible for shaping Rapid7’s financial roadmap and ensuring that investment allocation is alig...

Senior Program Manager, Managed Services

R9203 Tampa. Boston. Austin FL. MA. TX United States Tampa, FL, United States. Boston, MA, United States. Austin, TX, United States Business Support Program & Project Management Full_time JOB_LEVEL-3-24
Senior Program Manager We seek a highly skilled and experienced professional to join our organization as a Senior Program Manager of, Managed Services Program Management Office (PMO). This role requires a strategic thinker with a strong backgroun...

Senior Incident Responder

R9348 United States United States Security Services Professional Services Full_time JOB_LEVEL-3-25
Senior Incident Responder  About the Team The Rapid7 Incident Response team is considered the tip of the spear within Rapid7's Detection & Response practice. This team is primarily responsible for ensuring 24/7 breach response coverage for Rapid7'...

Apply Now

Not You?

We have emailed you a code to verify your identity. Please check your spam/junk folder if you don't receive the email in your inbox.

Application loading...