Senior Site Reliability Engineer (FedRAMP)

Nozomi NetworksSan Francisco, CA
$155,584 - $199,012Onsite

About The Position

Nozomi Networks is expanding its product portfolio and US public sector footprint and is hiring a Site Reliability Engineer to take ownership of their FedRAMP-authorized environment. This role is responsible for the day-to-day reliability, security posture, and compliance operations of this environment, including patching, deployment, and continuous monitoring. The engineer will work closely with the Switzerland-based SRE team and the Security & Compliance organization. This position offers a high degree of autonomy and responsibility, with the engineer being the primary owner of the FedRAMP environment and its outcomes.

Requirements

  • US citizenship or lawful permanent residency, with all work performed from within the United States, and the ability to pass applicable background investigations (per FedRAMP and agency requirements)
  • Proven professional experience as an SRE, DevOps, or Cloud engineer, including experience operating in a FedRAMP, FISMA, DoD IL, or similarly regulated environment
  • Ability to work autonomously and communicate effectively in an async-first setup with a team based in a different time zone (Central European Time)
  • Working knowledge of NIST SP 800-53 controls and the FedRAMP continuous monitoring process (scanning, POA&Ms, deviation requests, annual assessments)
  • Strong hands-on experience with Kubernetes
  • Hands-on experience with AWS, ideally AWS GovCloud (US)
  • Experience with vulnerability management tooling (e.g., Tenable/Nessus, Qualys) and interpreting scan results into actionable remediation plans
  • Good knowledge and understanding of at least one programming language (Ruby, Python, Go)
  • Experience defining infrastructure as code using tools such as Terraform or CloudFormation
  • Experience in the definition of CI/CD pipelines using technologies like Jenkins, GitHub Actions, or similar
  • Demonstrable experience using AI-enabled tools as part of day-to-day work to improve efficiency, quality, or decision-making, while applying sound professional judgement and maintaining accountability for outputs — within the constraints of a regulated environment

Nice To Haves

  • Experience preparing for or maintaining a FedRAMP Authorization to Operate (ATO), including SSP contributions and control narratives
  • Familiarity with STIG/CIS hardening automation (e.g., Ansible, OpenSCAP)
  • Familiarity with SIEM/log aggregation and audit log retention requirements in federal environments
  • Experience working with 3PAOs, agency ISSOs/ISSMs, or the FedRAMP PMO
  • Relevant certifications (e.g., AWS certifications, CISSP, Security+, CKA)

Responsibilities

  • Embody the Nozomi Networks Cultural Pillars and our mission to protect what matters most with transparency and trust
  • Act as the primary owner of our FedRAMP environment, ensuring its availability, performance, and continuous compliance with the FedRAMP baseline
  • Build and maintain the cloud infrastructure and related services within the FedRAMP authorization boundary (AWS GovCloud)
  • Own the patching and vulnerability remediation lifecycle, meeting FedRAMP remediation SLAs (30/90/180 days by severity) and maintaining associated evidence
  • Execute and improve the Continuous Monitoring (ConMon) program: monthly vulnerability scanning, POA&M creation and tracking, deviation requests, and monthly deliverables to our 3PAO and agency sponsors
  • Manage deployments and change control within the boundary, ensuring changes follow the approved Configuration Management process and Significant Change Request procedures where applicable
  • Maintain system hardening against CIS/STIG benchmarks and FIPS-validated cryptography requirements
  • Promote and implement automated solutions across application deployment, patching, evidence collection, and operational activities
  • Troubleshoot issues across the entire stack, from network and OS to applications
  • Support annual assessments and audits (3PAO), producing artifacts and demonstrating control implementation
  • Drive post-incident analysis according to our no-blame culture, including incident reporting obligations to agency stakeholders and US-CERT/CISA where required
  • Participate in periodic on-call duties for the FedRAMP environment
  • Operate in settings with strong confidentiality and data privacy protocols

Benefits

  • medical
  • dental
  • vision
  • life insurance
  • disability insurance
  • equity program
  • variable bonus program
  • 401(k) plan
  • employer matching program
  • flexible paid time off
  • paid holidays
  • paid parental leave
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service