FedRAMP Security & Compliance Engineer
Apply NowCompany: IBM
Location: Austin, TX 78745
Description:
Introduction
A career in IBM Software means you'll be part of a team that transforms our customer's challenges into solutions.
Seeking new possibilities and always staying curious, we are a team dedicated to creating the world's leading AI-powered, cloud-native software solutions for our customers. Our renowned legacy creates endless global opportunities for our IBMers, so the door is always open for those who want to grow their career.
IBM's product and technology landscape includes Research, Software, and Infrastructure. Entering this domain positions you at the heart of IBM, where growth and innovation thrive.
Your role and responsibilities
The ideal candidate for this role will become an active member of a globally distributed team responsible for ensuring MaaS360, IBM's Unified Endpoint Management offering, is running smoothly and providing customers the quality of service they've come to expect. This role is focused on working with multiple technology and offering teams to ensure the MaaS360 is deployed, supported to achieve both corporate and regulatory compliance requirements with specific focus on FedRAMP, FBA/ FFIEC, SOC 2, and NIST 800-53. The candidate will be working in an exciting and rapidly expanding environment driving high standards while collaborating with a group of skilled engineers and developers from around the world. The successful applicant will be performing work in FedRAMP environments, and therefore, must be a U.S. Person (although US Citizen is preferred)
Required education
None
Preferred education
Associate's Degree/College Diploma
Required technical and professional expertise
Preferred technical and professional experience
ABOUT BUSINESS UNIT
IBM Software infuses core business operations with intelligence-from machine learning to generative AI-to help make organizations more responsive, productive, and resilient. IBM Software helps clients put AI into action now to create real value with trust, speed, and confidence across digital labor, IT automation, application modernization, security, and sustainability. Critical to this is the ability to make use of all data, because AI is only as good as the data that fuels it. In most organizations data is spread across multiple clouds, on premises, in private datacenters, and at the edge. IBM's AI and data platform scales and accelerates the impact of AI with trusted data, and provides leading capabilities to train, tune and deploy AI across business. IBM's hybrid cloud platform is one of the most comprehensive and consistent approach to development, security, and operations across hybrid environments-a flexible foundation for leveraging data, wherever it resides, to extend AI deep into a business.
YOUR LIFE @ IBM
In a world where technology never stands still, we understand that, dedication to our clients success, innovation that matters, and trust and personal responsibility in all our relationships, lives in what we do as IBMers as we strive to be the catalyst that makes the world work better.
Being an IBMer means you'll be able to learn and develop yourself and your career, you'll be encouraged to be courageous and experiment everyday, all whilst having continuous trust and support in an environment where everyone can thrive whatever their personal or professional background.
Our IBMers are growth minded, always staying curious, open to feedback and learning new information and skills to constantly transform themselves and our company. They are trusted to provide on-going feedback to help other IBMers grow, as well as collaborate with colleagues keeping in mind a team focused approach to include different perspectives to drive exceptional outcomes for our customers. The courage our IBMers have to make critical decisions everyday is essential to IBM becoming the catalyst for progress, always embracing challenges with resources they have to hand, a can-do attitude and always striving for an outcome focused approach within everything that they do.
Are you ready to be an IBMer?
ABOUT IBM
IBM's greatest invention is the IBMer. We believe that through the application of intelligence, reason and science, we can improve business, society and the human condition, bringing the power of an open hybrid cloud and AI strategy to life for our clients and partners around the world.
Restlessly reinventing since 1911, we are not only one of the largest corporate organizations in the world, we're also one of the biggest technology and consulting employers, with many of the Fortune 50 companies relying on the IBM Cloud to run their business.
At IBM, we pride ourselves on being an early adopter of artificial intelligence, quantum computing and blockchain. Now it's time for you to join us on our journey to being a responsible technology innovator and a force for good in the world.
IBM is proud to be an equal-opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender, gender identity or expression, sexual orientation, national origin, caste, genetics, pregnancy, disability, neurodivergence, age, veteran status, or other characteristics. IBM is also committed to compliance with all fair employment practices regarding citizenship and immigration status.
OTHER RELEVANT JOB DETAILS
IBM offers a competitive and comprehensive benefits program. Eligible employees may have access to:
We consider qualified applicants with criminal histories, consistent with applicable law.
This position was posted on the date cited in the key job details section and is anticipated to remain posted for 21 days from this date or less if not needed to fill the role.
IBM will not be providing visa sponsorship for this position now or in the future. Therefore, in order to be considered for this position, you must have the ability to work without a need for current or future visa sponsorship.
A career in IBM Software means you'll be part of a team that transforms our customer's challenges into solutions.
Seeking new possibilities and always staying curious, we are a team dedicated to creating the world's leading AI-powered, cloud-native software solutions for our customers. Our renowned legacy creates endless global opportunities for our IBMers, so the door is always open for those who want to grow their career.
IBM's product and technology landscape includes Research, Software, and Infrastructure. Entering this domain positions you at the heart of IBM, where growth and innovation thrive.
Your role and responsibilities
The ideal candidate for this role will become an active member of a globally distributed team responsible for ensuring MaaS360, IBM's Unified Endpoint Management offering, is running smoothly and providing customers the quality of service they've come to expect. This role is focused on working with multiple technology and offering teams to ensure the MaaS360 is deployed, supported to achieve both corporate and regulatory compliance requirements with specific focus on FedRAMP, FBA/ FFIEC, SOC 2, and NIST 800-53. The candidate will be working in an exciting and rapidly expanding environment driving high standards while collaborating with a group of skilled engineers and developers from around the world. The successful applicant will be performing work in FedRAMP environments, and therefore, must be a U.S. Person (although US Citizen is preferred)
- Demonstrate familiarity with current FedRAMP and NIST Security controls and technologies, including vulnerability management capabilities
- Ability to develop and lead FedRAMP documentations such as the
- Lead recurring ConMon meetings; including review and submission of required artifacts, aid annual 3PAO security assessment, and generate or facilitate deviation requests as needed.
- Conduct continuous monitoring activities to assess the effectiveness of security controls and identify potential vulnerabilities or non-compliance issues.
- Lead internal and external audits for example FedRAMP, SOC2, and Internal corporate audits.
- Develop dashboarding and metric reporting to ensure the FedRAMP Continuous Monitoring program is meeting compliance obligations.
- Flexible, self-motivated, and able to work independently in a fast paced environment
- Excellent communication skills and the proven ability to work effectively with all levels of IT and business management
- Skill in preparing and making written and oral presentations of complex technical nature
- Understand enterprise operating environments, including security posture, application environment, and associated security controls
- Understand/document information system specifications and security controls, including logical and physical diagrams, connectivity, communication, and data flow diagrams, both internal and external to the system
- Gather information, architecture diagrams and implementation of the security controls by interfacing with security engineering, operations and build teams and use inputs to develop compliance documentation.
- Assist with the FedRAMP or FISMA authorization to include, but not limited to, prep of security engineering, build, and ops teams through training & mock interviews, update implementation language in security documentation and develop processes as required in support of FedRAMP PMO/ Agency / CISO requests
- Track and oversee the vulnerability remediation efforts in order to advise leadership as required on status blockers, and escalation when needed
- Prepare and present regular reports on the status of FedRAMP compliance activities to management and relevant partners
- Drive compliance efforts including audit coordination, reporting, risk management and continuous compliance reporting
- Coordinate security audits performed by both internal and external parties
- Engage offering teams and other business units to drive compliance efforts
- Help design and work within security architecture of continuous compliance with both operations and management teams
- Partner cross-functionally across the organization to support the implementation of technical, management, and operational controls, with a focus on controls required to deliver and operate regulated environments.
Required education
None
Preferred education
Associate's Degree/College Diploma
Required technical and professional expertise
- 5+ years experience in security and compliance
- Experience working with external and internal auditors to appropriately convey compliance posture
- Working with multiple compliance standards to meet each regulation's required parameters
- Ability to build standard templates that are compliant to regulatory standards
- Technical experience running vulnerability scanning solutions such as Tenable, Nessus/Security Center, OWSAP, Twistlock
- Familiarity with vulnerability management concepts, such as CVE and CVSS
Preferred technical and professional experience
- Experience in filing deviation requests for vulnerabilities on behalf of product teams
- One or more related professional certifications (e.g. CISSP, CRISC, CISM)
- Knowledge and experience in large, hybrid FedRAMP or highly regulated programs
- Excellent communication and technical documentation skills
- Experience working in a compliance role in a SaaS organization
- Degree in Computer Science or related discipline or equivalent work experience
- Understanding of current cloud technologies and web-services concepts
- Understanding agile software development life cycle, continuous integration, continuous delivery
ABOUT BUSINESS UNIT
IBM Software infuses core business operations with intelligence-from machine learning to generative AI-to help make organizations more responsive, productive, and resilient. IBM Software helps clients put AI into action now to create real value with trust, speed, and confidence across digital labor, IT automation, application modernization, security, and sustainability. Critical to this is the ability to make use of all data, because AI is only as good as the data that fuels it. In most organizations data is spread across multiple clouds, on premises, in private datacenters, and at the edge. IBM's AI and data platform scales and accelerates the impact of AI with trusted data, and provides leading capabilities to train, tune and deploy AI across business. IBM's hybrid cloud platform is one of the most comprehensive and consistent approach to development, security, and operations across hybrid environments-a flexible foundation for leveraging data, wherever it resides, to extend AI deep into a business.
YOUR LIFE @ IBM
In a world where technology never stands still, we understand that, dedication to our clients success, innovation that matters, and trust and personal responsibility in all our relationships, lives in what we do as IBMers as we strive to be the catalyst that makes the world work better.
Being an IBMer means you'll be able to learn and develop yourself and your career, you'll be encouraged to be courageous and experiment everyday, all whilst having continuous trust and support in an environment where everyone can thrive whatever their personal or professional background.
Our IBMers are growth minded, always staying curious, open to feedback and learning new information and skills to constantly transform themselves and our company. They are trusted to provide on-going feedback to help other IBMers grow, as well as collaborate with colleagues keeping in mind a team focused approach to include different perspectives to drive exceptional outcomes for our customers. The courage our IBMers have to make critical decisions everyday is essential to IBM becoming the catalyst for progress, always embracing challenges with resources they have to hand, a can-do attitude and always striving for an outcome focused approach within everything that they do.
Are you ready to be an IBMer?
ABOUT IBM
IBM's greatest invention is the IBMer. We believe that through the application of intelligence, reason and science, we can improve business, society and the human condition, bringing the power of an open hybrid cloud and AI strategy to life for our clients and partners around the world.
Restlessly reinventing since 1911, we are not only one of the largest corporate organizations in the world, we're also one of the biggest technology and consulting employers, with many of the Fortune 50 companies relying on the IBM Cloud to run their business.
At IBM, we pride ourselves on being an early adopter of artificial intelligence, quantum computing and blockchain. Now it's time for you to join us on our journey to being a responsible technology innovator and a force for good in the world.
IBM is proud to be an equal-opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender, gender identity or expression, sexual orientation, national origin, caste, genetics, pregnancy, disability, neurodivergence, age, veteran status, or other characteristics. IBM is also committed to compliance with all fair employment practices regarding citizenship and immigration status.
OTHER RELEVANT JOB DETAILS
IBM offers a competitive and comprehensive benefits program. Eligible employees may have access to:
- Healthcare benefits including medical & prescription drug coverage, dental, vision, and mental health & well being
- Financial programs such as 401(k), the IBM Employee Stock Purchase Plan, financial counseling, life insurance, short & long- term disability coverage, and opportunities for performance based salary incentive programs
- Generous paid time off including 12 holidays, minimum 56 hours sick time, 120 hours vacation, 12 weeks parental bonding leave in accordance with IBM Policy, and other Paid Care Leave programs. IBM also offers paid family leave benefits to eligible employees where required by applicable law
- Training and educational resources on our personalized, AI-driven learning platform where IBMers can grow skills and obtain industry-recognized certifications to achieve their career goals
- Diverse and inclusive employee resource groups, giving & volunteer opportunities, and discounts on retail products, services & experiences
We consider qualified applicants with criminal histories, consistent with applicable law.
This position was posted on the date cited in the key job details section and is anticipated to remain posted for 21 days from this date or less if not needed to fill the role.
IBM will not be providing visa sponsorship for this position now or in the future. Therefore, in order to be considered for this position, you must have the ability to work without a need for current or future visa sponsorship.