FedRAMP Manager
Denver, CO
Aprio
Future-focused business advisory and accounting services for entrepreneurs, businesses, investors and families.Join Aprio's Information Assurance Services Team and you will help clients maximize their opportunities. Aprio is a progressive, fast-growing firm looking for a FedRAMP Manager to join their dynamic team. Managers are primarily responsible for hands-on project execution and have, or are working towards, specialization in one or more service lines and are assigned to projects accordingly. Managers are assigned to a specific service delivery principal who is responsible for supervising their career development. Additionally, Managers’ daily activities are closely supervised by the management teams of their assigned projects. Managers may supervise associates and/or senior associates when serving as a member of a project management team. As a FedRAMP Manager at Aprio, you'll be able to work with the latest cloud services and technology companies, all of which are looking to test their systems against the tried and true prescriptive controls provided by NIST 800-53.Working with this team will lead to the natural honing of your technical skills in a variety of fields including cryptography, network structures, system security tools, and CI/CD. Yo will also improve your understanding of organizational controls such as security training programs, configuration management/ system development, and incident response processes. But more than that, a career at Aprio will also support outside opportunities for further education through additional training and the pursuit of industry-accepted certifications such as CISA, CISSP, and others.
Position Responsibilities:
- Review and validate System Security Plans (SSPs), POA&Ms (Plan of Actions and Milestones), and associated artifacts.
- Prepare and deliver detailed assessment reports for Authorization to Operate (ATO) decisions.
- Collaborate with CSP teams to identify gaps in their security posture and recommend remediation strategies.
- Perform in-depth security assessments of cloud service providers (CSPs) against FedRAMP Moderate and High baseline requirements.
- Evaluate technical controls across cloud environments, including access control, encryption, and system monitoring.
- Validate the effectiveness of incident response plans, vulnerability scans, Continuous monitoring, and remediation activities.
- Perform a variety of responsibilities from start to finish during a project, including:
- Interviewing cloud service providers (CSP) Subject Matter Experts for different fields of the organization, such as Human Resources, SecDevOps, SOC/NOC, and Internal Compliance
- Performing walkthroughs of various cloud infrastructure-as-a-service architectures (e.g., AWS, Azure, or OCI)
- Reviewing system security configurations as they pertain to NIST 800-53 security control baselines
- Analyzing vulnerability reports, validating encryption configurations, and much more!
Education, Work Experience and Certifications:
- Bachelor’s degree in Information Technology, Cybersecurity, Computer Science, or a related field; or equivalent professional experience in cybersecurity, cloud compliance, or a similar domain.
- Minimum 5+ years of relevant professional services experience in financial auditing, operational auditing, information systems auditing, internal auditing, information security management or consulting and/or risk consulting.
- Maintain
sone or more of the following FedRAMP required R311 certifications: - Cisco Certified Network Associate Security (CCNA Security)
- Cisco Certified Network Associate Cyber Security Operations (CCNA Cyber Ops)
- Cybersecurity Analyst (CySA+)
- GIAC Certified Incident Handler (GCIH)
- GIAC Systems and Network Auditor (GSNA)
- GIAC Certified Intrusion Analyst (GCIA)
- Certified Information Systems Auditor (CISA)
- Certified Information System Security Professional or Associate (CISSP or Associate)
- Certified Secure Software Lifecycle Professional (CSSLP)
- Certified Information Systems Security Officer (CISSO)
- CyberSec First Responder (CFR)
- CompTIA Advanced Security Practitioner Continuing Education (CASP+) Continuing Education (CE)
- CompTIA Cloud+ (Cloud+)
- Global Industrial Cyber Security Professional (GICSP)
- Securing Cisco® Networks with Threat Detection Analysis (SCYBER)
Additional Qualifications:
- Working knowledge of cybersecurity consulting services, methodology, and relevant professional standards.
- Requisite knowledge of applicable technology and security domains.
- High level of attention to detail and quality of work product.
- Client service oriented.
- Excellent time management, organizational, and verbal and written communication skills.
- Ability to work on-site or remotely as a valuable contributor to a collaborative team.
- Capable of simultaneously managing assigned tasks for multiple projects.
- Proficient using Microsoft Word, Excel, and PowerPoint, as well as Aprio’s service delivery applications
Why work for Aprio:Whether you are just starting out, looking to advance into management or searching for your next leadership role, Aprio offers an opportunity to grow with a future-focused, innovative firm.
Perks/Benefits we offer for full-time team members:- Medical, Dental, and Vision Insurance on the first day of employment- Flexible Spending Account and Dependent Care Account- 401k with Profit Sharing- 9+ holidays and discretionary time off structure- Parental Leave – coverage for both primary and secondary caregivers- Tuition Assistance Program and CPA support program with cash incentive upon completion- Discretionary incentive compensation based on firm, group and individual performance- Incentive compensation related to origination of new client sales- Top rated wellness program- Flexible working environment including remote and hybrid options What’s in it for you:- Working with an industry leader: Be part of a high-growth firm that is passionate for what’s next.- An awesome culture: Thirty-one fundamental behaviors guide our culture every day ensuring we always deliver an exceptional team-member and client experience. We call it the Aprio Way. This shared mindset creates lasting relationships between team members and with clients.- A great team: Work with a high-energy, passionate, caring and ambitious team of professionals in a collaborative culture.- Entrepreneurship: Have the freedom to innovate and bring your ideas to help us grow to become the CPA firm of choice nationally.- Growth opportunities: Grow professionally in an environment that fosters continuous learning and advancement.- Competitive compensation: You will be rewarded with competitive compensation, industry-leading benefits and a flexible work environment to enjoy work/life balance.
EQUAL OPPORTUNITY EMPLOYERAprio is an Equal Opportunity Employer encouraging diversity in the workplace. All qualified applicants will receive consideration for employment without regard to race; color; religion; national origin; sex; pregnancy; sexual orientation; gender identity and/or expression; age; disability; genetic information, citizenship status; military service obligations or any other category protected by applicable federal, state, or local law.
Aprio, LLP and Aprio Advisory Group, LLC, operate in an alternative business structure, with Aprio Advisory Group, LLC providing non-attest tax and consulting services, and Aprio, LLP providing CPA firm services.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Audits AWS Azure CASP+ CI/CD CISA CISSP Cloud Compliance CompTIA Computer Science Cryptography CSSLP Encryption FedRAMP GCIA GCIH GIAC GICSP GSNA Incident response Industrial Monitoring NIST NIST 800-53 Security assessment SOC System Security Plan Threat detection Vulnerability scans
Perks/benefits: 401(k) matching Career development Competitive pay Flex hours Flexible spending account Flex vacation Health care Insurance Medical leave Parental leave Wellness
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.