Lead Federal Auditor

TaniumDurham, NC
$100,000 - $155,000Hybrid

About The Position

The ideal candidate has solid, hands-on experience with FedRAMP compliance processes and federal risk management frameworks, including exposure to FedRAMP High and DoD Impact Level (IL4/IL5) environments. This role supports the organization's cloud authorization activities by contributing to authorization package development, continuous monitoring, and control implementation efforts. Working under the direction of Senior GRC members, it partners closely with engineering, security, and product teams to ensure Tanium's cloud offerings meet and maintain federal compliance requirements across civilian and defense environments. This is a hybrid position, which will require in person attendance several days each week in one of the following locations: Addison, TX; Bellevue, WA; Durham, NC; Emeryville, CA; or Reston, VA.

Requirements

  • Working knowledge of NIST SP 800-53 (Rev 4/5) High baseline controls and their practical application in cloud environments
  • Familiarity with the DoD Cloud Computing SRG and IL2/IL4/IL5 requirements and how they relate to FedRAMP
  • Experience contributing to authorization artifacts (SSP, SAP, SAR, POA&M, ConMon deliverables)
  • Familiarity with adjacent frameworks: FedRAMP, FISMA, NIST SP 800-53, NIST SP 800-37 (RMF), NIST SP 800-171, GovRAMP, CMMC, NIST CSF
  • Experience with cloud/SaaS environments, particularly AWS GovCloud, Azure Government, or other IL-accredited platforms
  • 5+ years in information security, compliance, or risk management, with federal program exposure
  • 5+ years of hands-on FedRAMP experience (CSP compliance, 3PAO assessment support, or federal agency ISSO activities); FedRAMP and DoD IL2 (IL4/IL5 preferred)
  • Strong written and verbal communication skills across technical and non-technical audiences; experience producing audit findings, policies, and compliance reports

Nice To Haves

  • Certifications preferred: CISSP, CISA, CAP, Security+, or equivalent

Responsibilities

  • Contribute to authorization package documentation (SSPs, POA&Ms, SAPs), with attention to FedRAMP High baseline requirements
  • Coordinate with 3PAOs and federal agency sponsors on scheduling, evidence collection, and artifact prep for FedRAMP and DoD IL4/IL5 assessments; respond to assessor inquiries
  • Implement and document NIST SP 800-53 controls, validating effectiveness and gathering evidence across FedRAMP Moderate, High, and DoD IL4/IL5 boundaries
  • Execute continuous monitoring: monthly vulnerability scanning reviews, POA&M tracking, and deliverables for sponsoring agencies and DoD stakeholders, including annual assessment support
  • Assess system architectures with cloud/infrastructure teams to identify compliance gaps, and conduct gap analyses/readiness assessments ahead of 3PAO assessments
  • Develop and improve FedRAMP policies, procedures, control implementation descriptions, and internal documentation standards, aligned with PMO and DoD SRG guidance
  • Review and respond to federal customer security questionnaires and due diligence requests
  • Prepare compliance status summaries, POA&M updates, and control assessment findings for senior leadership
  • Monitor FedRAMP PMO, NIST, and DoD SRG updates and federal cybersecurity directives, flagging relevant changes to the GRC team
  • Participate in cross-functional projects integrating FedRAMP High and DoD IL4/IL5 requirements into product development

Benefits

  • Equity awards
  • Medical plan
  • Dental plan
  • Vision plan
  • Family planning benefits
  • Health savings account
  • Flexible spending account
  • Transportation savings account
  • 401(k) retirement savings plan with company match
  • Life coverage
  • Accident coverage
  • Disability coverage
  • Business travel accident insurance
  • Employee assistance programs
  • Disability insurance
  • Other well-being benefits
  • 5 days set aside as volunteer time off (VTO)
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service