FedRAMP Compliance Analyst
Location: Washington, D.C., United States
Description
We are seeking a detail-oriented FedRAMP Compliance Analyst to support our organization’s adherence to the Federal Risk and Authorization Management Program (FedRAMP) requirements. This role is critical to ensuring our cloud services maintain compliance with federal security standards and support continuous monitoring, authorization processes, and audits. The ideal candidate will have experience with NIST SP 800-53, FedRAMP documentation, and working with cloud service providers in a regulatory context.
We’re growing and looking to hire an individual who embodies our core values: People First, Customer Obsession, Strive for Excellence, and Integrity.
About Claroty:
Claroty has redefined cyber-physical systems (CPS) protection with an unrivaled industry-centric platform built to secure mission-critical infrastructure. The Claroty Platform provides the deepest asset visibility and the broadest, built-for-CPS solution set in the market comprising exposure management, network protection, secure access, and threat detection – whether in the cloud with Claroty xDome or on-premise with Claroty Continuous Threat Detection (CTD). Backed by award-winning threat research and a breadth of technology alliances, The Claroty Platform enables organizations to effectively reduce CPS risk, with the fastest time-to-value and lower total cost of ownership. Our solutions are deployed by over 1,000 organizations at thousands of sites across all seven continents.
A Great Place to Work® certified company, Claroty is headquartered in New York City with employees across the Americas, Europe, Asia-Pacific, and Tel Aviv. The company is widely recognized as the industry leader in CPS protection, with backing from the world’s largest investment firms and industrial automation vendors, recognized by KLAS Research as Best in KLAS for Healthcare IoT Security five years in a row, and ranking on the Forbes Cloud 100 and Deloitte Technology Fast 500 multiple consecutive years.
Requirements:
- Support the FedRAMP authorization and reauthorization processes, including development, review, and maintenance of system security documentation (SSP, POA&M, SAP, SAR, etc.)
- Map and analyze security controls against FedRAMP Moderate/High baselines and NIST SP 800-53 controls.
- Assist in implementing and monitoring security controls for FedRAMP-authorized systems.
- Coordinate with internal teams (engineering, operations, DevSecOps) to ensure security requirements are integrated into system design and operation.
- Maintain continuous monitoring documentation and support periodic assessments (e.g., annual assessments, penetration tests, vulnerability scans).
- Interface with Third Party Assessment Organizations (3PAOs), government customers, and internal stakeholders to support audits and assessments.
- Track and manage Plan of Action and Milestones (POA&M) items to closure.
- Provide compliance reporting, metrics, and risk analysis to management.
- Stay up-to-date with changes in FedRAMP requirements, NIST guidance, and related compliance frameworks (e.g., FISMA, CMMC).