Job Closed
This listing is no longer active.
Manage, protect and monitor all your organization's passwords, secrets and remote connections with zero-trust security
Senior Security Compliance Engineer, AWS – FedRAMP High / DoD IL5
Location
California + 1 moreAll locations: California | Illinois
Posted
101 days ago
Salary
0
Seniority
Senior
Job Description
Senior Security Compliance Engineer, AWS – FedRAMP High / DoD IL5
Keeper Security, Inc.
• Serve as the technical lead for FedRAMP High and DoD IL5 compliance, including continuous monitoring, control validation, and authorization activities • Implement, operate, and validate AWS security controls aligned with NIST 800-53 High baseline and DoD SRG requirements • Partner with cloud and platform engineering teams to review architectures, challenge non-compliant designs, and guide secure implementation • Author, manage, and track POA&Ms, including root cause analysis, remediation planning, and reporting to 3PAOs, sponsoring agencies, and DoD stakeholders • Coordinate vulnerability remediation and patching across AWS infrastructure and supporting services • Lead audit readiness and evidence collection efforts, including improving automation for recurring FedRAMP and IL5 deliverables • Provide secondary technical support for SOC 2, PCI DSS, and ISO 27001 compliance initiatives
Job Requirements
- Bachelor’s degree in Information Security, Computer Science, Engineering, or equivalent practical experience
- 7+ years of experience in cloud security or security compliance engineering
- 5+ years of direct, hands-on experience supporting FedRAMP High environments
- Strong working knowledge of NIST 800-53 controls, DoD SRG requirements, and continuous monitoring processes
- 5+ years of hands-on experience securing AWS environments, including IAM, logging and monitoring, encryption, and vulnerability management
- 5+ years of experience working directly with 3PAOs, auditors, and government stakeholders
- Demonstrated ability to translate regulatory requirements into practical, enforceable technical controls
- Due to the role’s involvement with GovCloud and DoD environments, candidates must be a U.S. Person.
Benefits
- Medical, Dental & Vision (inclusive of domestic partnerships)
- Employer Paid Life Insurance & Employee/Spouse/Child Supplemental life
- Voluntary Short/Long Term Disability Insurance
- 401K (Roth/Traditional)
- A generous PTO plan that celebrates your commitment and seniority (including paid Bereavement/Jury Duty, etc)
- Above market annual bonuses
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Information Security Engineer
Keeper Security, Inc.Manage, protect and monitor all your organization's passwords, secrets and remote connections with zero-trust security
• Support and execute security incident response activities, including triage, investigation support, containment coordination, lessons learned, and corrective action tracking • Develop and maintain incident response playbooks, runbooks, and escalation paths; participate in and help run tabletop exercises • Operate and improve enterprise security controls and tooling (e.g., endpoint protection/EDR, SaaS security controls, email security, access control workflows), ensuring reliable configuration and ongoing effectiveness • Partner with Observability Engineering to ensure security-relevant telemetry is available for investigations and response (without owning SIEM/telemetry platform administration) • Partner with Vulnerability Management to drive remediation execution, validate fixes where appropriate, and reduce repeat findings through hardening and control improvements • Coordinate security investigations with DevOps, IT, and Engineering teams; track actions through to closure and document outcomes • Support access governance and least-privilege initiatives, including periodic access reviews, privileged access workflows, and secure authentication controls • Create and maintain security documentation for processes, controls, and operational procedures to enable consistency across teams and geographies • Assist with security control evidence and operational readiness activities for compliance frameworks (e.g., SOC 2, ISO 27001, FedRAMP/GovRAMP, NIST 800-53) in partnership with Compliance and platform teams • Identify opportunities for automation to improve security operations efficiency (ticketing workflows, control checks, integrations, scripting)
• The Facility Security Officer (FSO) manages, administers and coordinates DoD and/or other agency industrial security programs and other security activities to ensure compliance with government and company security policies and procedures • The FSO will process personnel security clearance investigations and maintain all security documentation, files, clearance, and suitability rosters in accordance with government requirements • Responsibilities include administrating personnel security clearance processes, coordinating initial clearance submissions and periodic reinvestigations of staff, providing guidance and instruction to staff, collection of electronic fingerprinting, and providing follow-up clearance report statuses to managers for specific contracts • Maintain all security documentation and files in accordance with DCSA requirements • Provide Federal Agency or component personnel suitability processing support and coordination • Provide and document new employee security briefings and exit debriefings • Monitor and enforce annual refresher training completion and other annual employee security documentation requirements in the Learning Management System (LMS) • Investigate and report security incidents and Insider Threat reports • Provide security support to Human Resources, Contracts, and Proposal teams • Advise personnel of their reporting requirements • Interpret government policies for the development and implementation of security plans and procedures • Maintain strong working relationships with DCSA and/or other Federal Agency representatives to facilitate accurate information sharing, incident resolution, and Insider Threat response • Participate in the development and execution of security education programs including initial and annual refresher training
Security Manager
ShippoFounded in 2013, Shippo is a logistics and supply company that provides shipping services to retailers, ecommerce platforms, marketplaces, and more. Operating f
• Define and own Shippo’s security strategy, translating business goals, customer trust needs, and regulatory requirements into a clear, prioritized security roadmap. • Plan and execute quarterly security initiatives that deliver meaningful risk reduction and enable business growth. • Continuously assess Shippo’s threat landscape and adjust priorities as the company, product surface area, and customer needs evolve. • Secure Shippo’s cloud and application environments, with deep ownership of AWS security architecture and controls. • Partner with Engineering teams to embed security into the SDLC, including application security reviews, SAST/DAST, dependency management, and secure design practices. • Own security operations, including incident readiness, response, and post-incident learning. • Lead security incidents end-to-end - from investigation and containment to postmortems and long-term remediation. • Conduct security risk assessments across applications, infrastructure, vendors, and processes; clearly communicate findings and recommendations to stakeholders. • Serve as the primary security point of contact for customer and partner security inquiries, audits, and escalations. • Lead, coach, and support a small security team, setting clear expectations, providing actionable feedback, and fostering a culture of learning and ownership.
• Define and execute a multi-year product/security strategy and roadmap • Lead a product security organization including hiring and performance management • Engage directly with customers as security SME during sales cycles • Ensure security is integrated into agile delivery through developer training and automated testing • Evaluate customer agreements for alignment with internal capabilities • Serve as a senior security advisor to engineering leadership


