高级联邦IT审计师
Senior Federal IT Auditor
**高级联邦IT审计师**
**基本要求**
理想的候选人具备扎实的FedRAMP合规流程和联邦风险管理框架的实际经验,包括对FedRAMP High和国防部影响等级(IL4/IL5)环境的了解。该职位通过参与授权包开发、持续监控和控制实施工作,支持组织的云授权活动。在高级GRC成员的指导下,与工程、安全和产品团队紧密合作,确保Tanium的云产品在民用和国防环境中满足并保持联邦合规要求。
**你将负责:**
- 参与授权包文档(SSP、POA&Ms、SAPs)的编写,关注FedRAMP High基线要求
- 与3PAOs和联邦机构赞助方协调,安排评估时间、收集证据和准备评估材料,应对评估员的询问
- 实施并记录NIST SP 800-53控制措施,验证其有效性,并在FedRAMP Moderate、High和DoD IL4/IL5边界内收集证据
- 执行持续监控:每月漏洞扫描审查、POA&M跟踪以及向资助机构和DoD利益相关者交付成果,包括年度评估支持
- 与云/基础设施团队一起评估系统架构,识别合规差距,并在3PAO评估前进行差距分析/准备度评估
- 制定和改进FedRAMP政策、程序、控制实施描述和内部文档标准,符合PMO和DoD SRG指导
- 审阅并回应联邦客户的网络安全问卷和尽职调查请求
- 准备合规状态摘要、POA&M更新和控制评估结果,供高层领导参考
- 监控FedRAMP PMO、NIST和DoD SRG的更新及联邦网络安全指令,向GRC团队报告相关变更
- 参与跨职能项目,将FedRAMP High和DoD IL4/IL5要求整合到产品开发中
- 熟悉NIST SP 800-53(Rev 4/5)的High基线控制措施及其在云环境中的实际应用
**你应该熟悉:**
- 了解DoD云计算SRG和IL2/IL4/IL5要求,以及它们与FedRAMP的关系
- 有参与授权文件(SSP、SAP、SAR、POA&M、ConMon交付物)的经验
- 熟悉FedRAMP和DoD IL4/IL5合规流程
查看英文原文
**Senior Federal IT Auditor**
**The Basics**
The ideal candidate has solid, hands-on experience with FedRAMP compliance processes and federal risk management frameworks, including exposure to FedRAMP High and DoD Impact Level (IL4/IL5) environments. This role supports the organization's cloud authorization activities by contributing to authorization package development, continuous monitoring, and control implementation efforts. Working under the direction of Senior GRC members, it partners closely with engineering, security, and product teams to ensure Tanium's cloud offerings meet and maintain federal compliance requirements across civilian and defense environments.
**What You'll Do**
- Contribute to authorization package documentation (SSPs, POA&Ms, SAPs), with attention to FedRAMP High baseline requirements
- Coordinate with 3PAOs and federal agency sponsors on scheduling, evidence collection, and artifact prep for FedRAMP and DoD IL4/IL5 assessments; respond to assessor inquiries
- Implement and document NIST SP 800-53 controls, validating effectiveness and gathering evidence across FedRAMP Moderate, High, and DoD IL4/IL5 boundaries
- Execute continuous monitoring: monthly vulnerability scanning reviews, POA&M tracking, and deliverables for sponsoring agencies and DoD stakeholders, including annual assessment support
- Assess system architectures with cloud/infrastructure teams to identify compliance gaps, and conduct gap analyses/readiness assessments ahead of 3PAO assessments
- Develop and improve FedRAMP policies, procedures, control implementation descriptions, and internal documentation standards, aligned with PMO and DoD SRG guidance
- Review and respond to federal customer security questionnaires and due diligence requests
- Prepare compliance status summaries, POA&M updates, and control assessment findings for senior leadership
- Monitor FedRAMP PMO, NIST, and DoD SRG updates and federal cybersecurity directives, flagging relevant changes to the GRC team
- Participate in cross-functional projects integrating FedRAMP High and DoD IL4/IL5 requirements into product development
- Working knowledge of NIST SP 800-53 (Rev 4/5) High baseline controls and their practical application in cloud environments
**You Should be Knowledgeable In:**
- Familiarity with the DoD Cloud Computing SRG and IL2/IL4/IL5 requirements and how they relate to FedRAMP
- Experience contributing to authorization artifacts (SSP, SAP, SAR, POA&M, ConMon deliverables)
- Familiarity with adjacent frameworks: FedRAMP, FISMA, NIST SP 800-53, NIST SP 800-37 (RMF), NIST SP 800-171, GovRAMP, CMMC, NIST CSF
- Experience with cloud/SaaS environments, particularly AWS GovCloud, Azure Government, or other IL-accredited platforms
**We're Looking for Someone With**
_Experience_
- 5+ years in information security, compliance, or risk management, with federal program exposure
- 5+ years of hands-on FedRAMP experience (CSP compliance, 3PAO assessment support, or federal agency ISSO activities); FedRAMP and DoD IL2 (IL4/IL5 preferred)
- Strong written and verbal communication skills across technical and non-technical audiences; experience producing audit findings, policies, and compliance reports
- Certifications preferred: CISSP, CISA, CAP, Security+, or equivalent
**About Tanium**
Tanium is the Autonomous IT company. Driven by AI and real-time endpoint intelligence, Tanium Autonomous IT empowers IT and security teams to make their organizations unstoppable.
Many of the world’s leading organizations trust Tanium’s single, unified platform for endpoint management and security to innovate faster, stay resilient and move business forward with confidence, at scale. To learn how Tanium delivers Autonomous IT for unstoppable business – visit [www.tanium.com](http://www.tanium.com/) and follow us on [LinkedIn](https://www.linkedin.com/company/tanium) and [X](https://twitter.com/Tanium).
**On a mission. Together.**
At Tanium, we are stewards of a culture that emphasizes the importance of collaboration, respect, and diversity. In our pursuit of revolutionizing the way some of the largest enterprises and governments in the world solve their most difficult IT challenges, we are strengthened by our unique perspectives and by our collective actions.
As a global organization with stakeholders around the world, it’s imperative that the diversity of our customers and communities is reflected internally in our team members. We strive to create a diverse and inclusive environment where everyone feels they have opportunities to succeed and grow because we know that only together can we do great things.
Our commitment to excellence and innovation has earned us a place on the Forbes Cloud 100 list for ten consecutive years, and we continue to be recognized worldwide as a great place to work.
Each of our team members has 5 days set aside as volunteer time off (VTO) to contribute to the communities they live in and give back to the causes they care about most.
**What you’ll get**
The annual base salary range for this full-time position is $131,000 to $201,000. This range is an estimate for what Tanium will pay a new hire. The actual annual base salary offered may be adjusted based on a variety of factors, including but not limited to, location, education, skills, training, and experience.
In addition to an annual base salary, team members will receive equity awards and a generous benefits package consisting of medical, dental and vision plan, family planning benefits, health savings account, flexible spending account, transportation savings account, 401(k) retirement savings plan with company match, life, accident and disability coverage, business travel accident insurance, employee assistance programs, disability insurance, and other well-being benefits.
Tanium is an Equal Opportunity and Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, gender identity, sexual orientation, disability, protected Veteran status, or other legally protected categories. If you require a reasonable accommodation in searching for a job opening, completing an application, interviewing, or completing any pre-employment testing or requirements, please contact [accommodations@tanium.com](mailto:accommodations@tanium.com). For more information refer to the “Know Your Rights” poster which is available here - [https://www.eeoc.gov/poster](https://www.eeoc.gov/poster).
Please be aware of job offers coming from people claiming to be Tanium employees. Tanium employees will only use @tanium.com email addresses to communicate with you, will have video interviews with you, and will never ask you for money.
[This link](https://www.cigna.com/legal/compliance/machine-readable-files) leads to the machine readable files that are made available in response to the federal Transparency in Coverage Rule and includes negotiated service rates and out-of-network allowed amounts between health plans and healthcare providers. The machine-readable files are formatted to allow researchers, regulators, and application developers to more easily access and analyze data.
For more information on how Tanium processes your personal data, please see our [Privacy Policy](https://www.tanium.com/privacy-policy/).