FedRAMP Security Consultant

<p style="line-height:1.2;text-align:center;"></p><p style="line-height:1.2;text-align:center;"><span style="font-size:16pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:'Helvetica Neue', sans-serif;"><span style="color:#512a2e;"><span style="font-weight:700;"><span style="font-style:normal;"><span style="text-decoration:none;">FedRAMP Security Consultant (1099)</span></span></span></span></span></span></p> <p style="line-height:1.2;"><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:'Helvetica Neue', sans-serif;"><span style="color:#000000;"><span style="font-weight:700;"><span style="font-style:normal;"><span style="text-decoration:none;">Location: 100% Remote – U.S. Preferred</span></span></span></span></span></span></p><p style="line-height:1.2;"><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:'Helvetica Neue', sans-serif;"><span style="color:#000000;"><span style="font-weight:700;"><span style="font-style:normal;"><span style="text-decoration:none;">Type: Contracted / Project-Based / Potential Permanent</span></span></span></span></span></span></p><p style="line-height:1.2;"><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:'Helvetica Neue', sans-serif;"><span style="color:#000000;"><span style="font-weight:700;"><span style="font-style:normal;"><span style="text-decoration:none;">Pay: $100,000-$140,000</span></span></span></span></span></span></p><p style="line-height:1.2;"><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:'Helvetica Neue', sans-serif;"><span style="color:#000000;"><span style="font-weight:700;"><span style="font-style:normal;"><span style="text-decoration:none;">Travel: Minimal (Remote audit model; occasional onsite support if required)</span></span></span></span></span></span></p> <h2 style="line-height:1.2;"><span style="font-size:13.999999999999998pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:'Helvetica Neue', sans-serif;"><span style="color:#702231;"><span style="font-weight:700;"><span style="font-style:normal;"><span style="text-decoration:none;">About Us:</span></span></span></span></span></span></h2><p style="line-height:1.2;margin-bottom:16px;"><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:'Helvetica Neue', sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">RSI Security is a trusted leader in cybersecurity compliance and assessment services, supporting organizations across federal, commercial, and emerging regulatory frameworks.</span></span></span></span></span></span></p><p style="line-height:1.2;margin-bottom:16px;"><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:'Helvetica Neue', sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">We bring deep experience across both advisory and formal assessment services, including operating as a PCI QSA Company, a CMMC C3PAO, and a HITRUST CSF assessor. Our teams deliver high-quality, evidence-based engagements across frameworks such as PCI DSS, CMMC, FedRAMP, SOC 2, and ISO standards.</span></span></span></span></span></span></p><p style="line-height:1.2;margin-bottom:16px;"><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:'Helvetica Neue', sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">Our approach emphasizes technical depth, practical implementation, and actionable guidance, helping organizations meet compliance requirements while building sustainable security programs.</span></span></span></span></span></span></p><p style="line-height:1.2;margin-bottom:16px;"><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:'Helvetica Neue', sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">We operate in a collaborative, remote-first environment focused on flexibility, quality delivery, and continuous improvement.</span></span></span></span></span></span></p><h2 style="line-height:1.2;"><span style="font-size:13.999999999999998pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:'Helvetica Neue', sans-serif;"><span style="color:#702231;"><span style="font-weight:700;"><span style="font-style:normal;"><span style="text-decoration:none;">About the Role:</span></span></span></span></span></span></h2><p style="line-height:1.2;margin-bottom:16px;"><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:'Helvetica Neue', sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">As a FedRAMP Security Consultant, you will support cloud service providers in preparing for FedRAMP authorization through readiness assessments, gap analysis, and development of required security documentation.</span></span></span></span></span></span></p><p style="line-height:1.2;margin-bottom:16px;"><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:'Helvetica Neue', sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">This role focuses on FedRAMP advisory and readiness activities, including aligning client environments to NIST SP 800-53 requirements, supporting the development of System Security Plans (SSP), POA&Ms, and related artifacts, and guiding organizations through the FedRAMP authorization process.</span></span></span></span></span></span></p><p style="line-height:1.2;margin-bottom:16px;"><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:'Helvetica Neue', sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">You will work directly with client stakeholders to evaluate cloud environments, interpret control requirements, and provide clear, actionable recommendations to support authorization readiness.</span></span></span></span></span></span></p><p style="line-height:1.2;margin-bottom:16px;"><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:'Helvetica Neue', sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">This position requires a high degree of ownership, strong technical judgment, and the ability to operate effectively in client-facing engagements involving complex cloud and compliance environments.</span></span></span></span></span></span></p><p style="line-height:1.2;margin-bottom:16px;"><span style="font-size:13.999999999999998pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:'Helvetica Neue', sans-serif;"><span style="color:#702231;"><span style="font-weight:700;"><span style="font-style:normal;"><span style="text-decoration:none;">What You’ll Do</span></span></span></span></span></span></p><ul><li style="list-style-type:disc;"><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:'Helvetica Neue', sans-serif;"><span style="color:#000000;"><span style="font-weight:700;"><span style="font-style:normal;"><span style="text-decoration:none;">Lead FedRAMP Readiness & Advisory Engagements:</span></span></span></span></span></span><br><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:'Helvetica Neue', sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">Work directly with cloud service providers to assess FedRAMP readiness, identify control gaps, and develop actionable remediation roadmaps aligned with NIST SP 800-53 and FedRAMP requirements.</span></span></span></span></span></span></li><li style="list-style-type:disc;"><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:'Helvetica Neue', sans-serif;"><span style="color:#000000;"><span style="font-weight:700;"><span style="font-style:normal;"><span style="text-decoration:none;">Perform Gap Assessments & Control Analysis:</span></span></span></span></span></span><br><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:'Helvetica Neue', sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">Evaluate current-state security programs against FedRAMP requirements, including technical, operational, and documentation controls, and clearly articulate gaps and risk implications.</span></span></span></span></span></span></li><li style="list-style-type:disc;"><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:'Helvetica Neue', sans-serif;"><span style="color:#000000;"><span style="font-weight:700;"><span style="font-style:normal;"><span style="text-decoration:none;">Develop Core FedRAMP Artifacts:</span></span></span></span></span></span><br><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:'Helvetica Neue', sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">Support and/or lead the development of key deliverables such as System Security Plans (SSP), POA&Ms, policies, and supporting documentation required for FedRAMP authorization.</span></span></span></span></span></span></li><li style="list-style-type:disc;"><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:'Helvetica Neue', sans-serif;"><span style="color:#000000;"><span style="font-weight:700;"><span style="font-style:normal;"><span style="text-decoration:none;">Interpret NIST Controls in Real Environments:</span></span></span></span></span></span><br><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:'Helvetica Neue', sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">Translate NIST SP 800-53 control requirements into practical implementations within cloud environments (AWS, Azure, GCP), including shared responsibility and inherited controls.</span></span></span></span></span></span></li><li style="list-style-type:disc;"><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:'Helvetica Neue', sans-serif;"><span style="color:#000000;"><span style="font-weight:700;"><span style="font-style:normal;"><span style="text-decoration:none;">Advise on Architecture & Control Implementation:</span></span></span></span></span></span><br><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:'Helvetica Neue', sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">Provide guidance on security architecture, control design, and implementation strategies to align client environments with FedRAMP expectations.</span></span></span></span></span></span></li><li style="list-style-type:disc;"><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:'Helvetica Neue', sans-serif;"><span style="color:#000000;"><span style="font-weight:700;"><span style="font-style:normal;"><span style="text-decoration:none;">Engage with Client Stakeholders:</span></span></span></span></span></span><br><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:'Helvetica Neue', sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">Lead technical discussions and workshops with engineering, security, and compliance teams to validate implementations and drive progress toward authorization readiness.</span></span></span></span></span></span></li><li style="list-style-type:disc;"><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:'Helvetica Neue', sans-serif;"><span style="color:#000000;"><span style="font-weight:700;"><span style="font-style:normal;"><span style="text-decoration:none;">Support Future Assessment Capability:</span></span></span></span></span></span><br><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:'Helvetica Neue', sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">Contribute to RSI’s development of FedRAMP assessment methodologies, templates, and processes as the organization progresses toward 3PAO readiness.</span></span></span></span></span></span></li><li style="list-style-type:disc;"><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:'Helvetica Neue', sans-serif;"><span style="color:#000000;"><span style="font-weight:700;"><span style="font-style:normal;"><span style="text-decoration:none;">Collaborate Across Internal Teams:</span></span></span></span></span></span><br><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:'Helvetica Neue', sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">Partner with delivery, sales, and leadership to scope engagements, support proposals, and refine service offerings.</span></span></span></span></span></span></li></ul><h2 style="line-height:1.2;"><span style="font-size:13.999999999999998pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:'Helvetica Neue', sans-serif;"><span style="color:#702231;"><span style="font-weight:700;"><span style="font-style:normal;"><span style="text-decoration:none;">What You’ll Bring</span></span></span></span></span></span></h2><ul><li style="list-style-type:disc;"><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:'Helvetica Neue', sans-serif;"><span style="color:#000000;"><span style="font-weight:700;"><span style="font-style:normal;"><span style="text-decoration:none;">Experience:</span></span></span></span></span></span><br><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:'Helvetica Neue', sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">5+ years in cybersecurity, compliance, or risk assessment roles, with demonstrated experience supporting or leading structured security or compliance engagements</span></span></span></span></span></span></li><li style="list-style-type:disc;"><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:'Helvetica Neue', sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">At least 2–3 years working with NIST-based frameworks (e.g., NIST SP 800-53, RMF, FedRAMP, FISMA, or similar)</span></span></span></span></span></span></li><li style="list-style-type:disc;"><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:'Helvetica Neue', sans-serif;"><span style="color:#000000;"><span style="font-weight:700;"><span style="font-style:normal;"><span style="text-decoration:none;">FedRAMP / NIST Expertise:</span></span></span></span></span></span><br><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:'Helvetica Neue', sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">Hands-on experience supporting FedRAMP or NIST SP 800-53-based initiatives, including readiness assessments, gap analyses, or documentation development (SSP, POA&M, or similar)</span></span></span></span></span></span></li><li style="list-style-type:disc;"><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:'Helvetica Neue', sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">Strong ability to interpret control intent and apply it to real-world cloud environment</span></span></span></span></span></span></li><li style="list-style-type:disc;"><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:'Helvetica Neue', sans-serif;"><span style="color:#000000;"><span style="font-weight:700;"><span style="font-style:normal;"><span style="text-decoration:none;">Advisory & Problem-Solving Skills:</span></span></span></span></span></span></li><li style="list-style-type:disc;"><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:'Helvetica Neue', sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">Experience guiding clients through compliance challenges, including defining remediation strategies, prioritizing gaps, and aligning technical implementations to regulatory expectations</span></span></span></span></span></span></li><li style="list-style-type:disc;"><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:'Helvetica Neue', sans-serif;"><span style="color:#000000;"><span style="font-weight:700;"><span style="font-style:normal;"><span style="text-decoration:none;">Cloud & Technical Understanding:</span></span></span></span></span></span><br><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:'Helvetica Neue', sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">Familiarity with AWS, Azure, or GCP environments, including identity and access management, logging/monitoring, network architecture, and secure configuration practices</span></span></span></span></span></span></li><li style="list-style-type:disc;"><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:'Helvetica Neue', sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">Ability to understand system architecture diagrams and data flows</span></span></span></span></span></span></li><li style="list-style-type:disc;"><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:'Helvetica Neue', sans-serif;"><span style="color:#000000;"><span style="font-weight:700;"><span style="font-style:normal;"><span style="text-decoration:none;">Client-Facing Capability:</span></span></span></span></span></span><br><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:'Helvetica Neue', sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">Proven ability to lead discussions with technical and non-technical stakeholders, ask effective questions, and drive engagements forward</span></span></span></span></span></span></li><li style="list-style-type:disc;"><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:'Helvetica Neue', sans-serif;"><span style="color:#000000;"><span style="font-weight:700;"><span style="font-style:normal;"><span style="text-decoration:none;">Certifications:</span></span></span></span></span></span><br><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:'Helvetica Neue', sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">CISSP, CISA, CISM, CCSP, or similar</span></span></span></span></span></span></li><li style="list-style-type:disc;"><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:'Helvetica Neue', sans-serif;"><span style="color:#000000;"><span style="font-weight:700;"><span style="font-style:normal;"><span style="text-decoration:none;">Strongly Preferred (But Not Required):</span></span></span></span></span></span></li><li style="list-style-type:disc;"><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:'Helvetica Neue', sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">Experience supporting FedRAMP ATO efforts or working with a 3PAO</span></span></span></span></span></span></li><li style="list-style-type:disc;"><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:'Helvetica Neue', sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">Experience with adjacent frameworks such as CMMC, FISMA, or DoD RMF</span></span></span></span></span></span></li></ul><h2 style="line-height:1.2;"><span style="font-size:13.999999999999998pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:'Helvetica Neue', sans-serif;"><span style="color:#702231;"><span style="font-weight:700;"><span style="font-style:normal;"><span style="text-decoration:none;">Mindset We Value</span></span></span></span></span></span></h2><ul><li style="list-style-type:disc;"><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:'Helvetica Neue', sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">Take ownership and deliver high-quality work independently</span></span></span></span></span></span></li><li style="list-style-type:disc;"><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:'Helvetica Neue', sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">Stay organized and manage multiple engagements effectively</span></span></span></span></span></span></li><li style="list-style-type:disc;"><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:'Helvetica Neue', sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">Apply critical thinking and professional skepticism when reviewing evidence</span></span></span></span></span></span></li><li style="list-style-type:disc;"><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:'Helvetica Neue', sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">Communicate clearly and professionally with clients and internal teams</span></span></span></span></span></span></li><li style="list-style-type:disc;"><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:'Helvetica Neue', sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">Maintain flexibility and adaptability in a project-based environment</span></span></span></span></span></span></li></ul><h2 style="line-height:1.2;"><span style="font-size:13.999999999999998pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:'Helvetica Neue', sans-serif;"><span style="color:#702231;"><span style="font-weight:700;"><span style="font-style:normal;"><span style="text-decoration:none;">Why Join RSI?</span></span></span></span></span></span></h2><p style="line-height:1.2;"><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:'Helvetica Neue', sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:normal;"><span style="text-decoration:none;">You will be working with a team supporting complex federal compliance initiatives, including FedRAMP authorization efforts across diverse cloud environments. This role offers flexibility, exposure to high-impact projects, and the opportunity to work with experienced cybersecurity professionals in a fully remote setting.</span></span></span></span></span></span></p> <p style="line-height:1.2;"><span style="font-size:11pt;font-variant:normal;white-space:pre-wrap;"><span style="font-family:'Helvetica Neue', sans-serif;"><span style="color:#000000;"><span style="font-weight:400;"><span style="font-style:italic;"><span style="text-decoration:none;">RSI Security is an Equal Opportunity Employer. We prioritize competence, qualifications, and the integrity of the certification process in all hiring decisions.</span></span></span></span></span></span></p><br> 

Back to blog