WalkMe-posted 3 months ago
$100,000 - $130,000/Yr
Full-time • Senior
New York, NY
1,001-5,000 employees

WalkMe is seeking a FedRAMP Senior Compliance Analyst to lead and mature our public-sector FedRAMP program, currently in Ready status, with the goal of achieving full Authorization (ATO) and maintaining Continuous Monitoring. This role involves authoring policies, maintaining FedRAMP documentation, coordinating evidence across engineering teams, collaborating with FedRAMP advisors and auditors to ensure successful assessments and renewals, and serving as the FedRAMP compliance focal point for R&D where U.S. citizenship is required for hands-on system operations. This position is ideal for a self-starter with a can-do attitude, strong English communication skills (oral and written) and a technical background who excels at translating NIST controls into practical engineering outcomes.

  • Own the FedRAMP RMF lifecycle, including defining/maintaining the authorization boundary, driving control implementation evidence, writing and reviewing the System Security Plan (SSP), and managing System Assessment Plan (SAP)/System Assessment Report (SAR), Plan of Action & Milestones (POA&M), and Continuous Monitoring submissions.
  • Author and maintain security and compliance policies, standards, and procedures, aligning with NIST 800-53r5 and organizational standards.
  • Drive vulnerability management, including vulnerability scanning, patching cadence enforcement, and tracking remediation.
  • Liaise with external FedRAMP advisors/3PAO and authorizing stakeholders, scheduling walkthroughs, coordinating requests, and resolving findings.
  • Serve as the U.S. citizenship compliance focal point for technical operations in the FedRAMP production environment.
  • Collaborate with Security (GRC/AppSec/IR), Cloud Engineering/SRE, and IT teams to operationalize NIST 800-53 Rev. 5 controls and ensure traceable evidence.
  • Influence engineering best practices by embedding security and compliance requirements into CI/CD pipelines, IaC, and operational processes.
  • Report program status, risks, and metrics to the GRC Lead/CISO, and prepare materials for audits, renewals, and leadership reviews.
  • Minimum 7 years of compliance experience in FedRAMP.
  • Prior experience leading a FedRAMP Authorization to Operate (ATO) or renewal, including preparing for agency or JAB authorization.
  • Prior, hands-on FedRAMP experience in documentation, RMF, POA&M management, Continuous Monitoring, and FIPS-validated cryptography (FIPS 140-3).
  • Strong working knowledge of NIST 800-53r5 and RMF (NIST 800-37), with the ability to map technical controls to evidence.
  • Demonstrated ability to author policies, review SSPs and collaborate effectively with 3PAOs/advisors and engineering teams.
  • Excellent documentation, communication, and stakeholder management skills.
  • U.S. citizenship (required due to federal program requirements).
  • Positive, can-do attitude with a collaborative approach, and proven ability to take ownership and drive complex initiatives to completion.
  • Exposure to AWS/Azure/GCP (GovCloud experience a plus), Kubernetes, Terraform, CI/CD, logging/monitoring (Splunk, CloudWatch, ELK, Datadog).
  • Familiarity with NIST 800-171/172, ISO 27001, SOC 2, vulnerability management practices, and security testing (BC/DR, IR exercises).
  • Experience with GRC/evidence tools (e.g., Jira/Confluence, ServiceNow, Drata/Vanta/Archer/OneTrust).
  • Prior SaaS/public-sector or enterprise compliance experience.
  • Hybrid Work Arrangement: We offer a hybrid work schedule to perfectly combine the benefits of remote work and the essential connections and collaborations of onsite work.
  • Supportive Culture: We focus on the whole person, celebrating what makes us unique, and create space for community.
  • Professional Development: We encourage continuous learning and offer opportunities for career development through our career compass offering.
  • Wellness@WalkMe: Enjoy quarterly wellness reimbursements, daily BrightBreaks to recharge, and WalkMe’s annual Wellness Month every July.
  • Health coverage options to ensure employees have access to essential medical benefits.
  • Generous annual leave policy tailored to meet regional standards.
  • RefreshMe Days throughout the year to strengthen our commitment to work/life balance.
  • Robust Retirement Contributions.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service