Senior Federal Security Compliance Analyst

Full Time
1 month ago

Get to know OktaOkta is The World’s Identity Company. We free everyone to safely use any technology—anywhere, on any device or app. Our Workforce and Customer Identity Clouds enable secure yet flexible access, authentication, and automation that transforms how people move through the digital world, putting Identity at the heart of business security and growth. At Okta, we celebrate a variety of perspectives and experiences. We are not looking for someone who checks every single box - we’re looking for lifelong learners and people who can make us better with their unique experiences. Join our team! We’re building a world where Identity belongs to you.

This position is for a Senior Federal Security Compliance Analyst on the Okta Security GRC team. This team’s mission is to strengthen Okta’s position as the leading Identity-as-a-Service solution through a security-first approach to compliance. This team is largely focused on working with internal and external stakeholders to maintain our FedRAMP authorizations for our Okta government systems. 

As a Senior Federal Security Compliance Analyst on this team, you will support security initiatives by engaging various process owners in the design, documentation, implementation, monitoring of the appropriate controls in our computing environments. This candidate will also work with internal and external stakeholders to improve our compliance posture, security controls, and compliance related processes. 

The ideal candidate will have hands-on experience with the technical implementation or evaluation of FedRAMP Moderate, High, DoD Impact Level 4 and Level 5 controls in cloud-based environments using tools such as Okta, AWS, ServiceNow, JIRA, and others.  This position requires a unique set of skills including project management, technical competency, knowledge of federal compliance frameworks, and an eye towards future standards and regulations that will impact federal service offerings.

Job Duties and Responsibilities:

  • Work with internal and external stakeholders to support FedRAMP and DoD audits of the company’s federal cloud offerings
  • Collaborate with team members and engineering stakeholders to manage continuous monitoring program across all federal environments, including internal and external reporting on vulnerabilities and developing continuous monitoring presentations
  • Work with process and control owners to help them understand the control requirements, audit results, and provide advisory around remediation options
  • Interpret requirements across multiple compliance frameworks (specifically FedRAMP), and provide clarification to engineering teams seeking compliance advice 
  • Assess security and compliance impact of changes to the federal systems and applications. Work with internal and external stakeholders to ensure high impact changes are handled appropriately
  • Coordinate with multiple distributed teams to communicate requirements and gather necessary artifacts and information to support compliance audit requirements
  • Lead efforts to analyze gaps between current status and future compliance framework needs for new products 
  • Collaborate with private sector compliance teams (SOC, PCI, HITRUST, etc.) to maintain and expand a common controls framework for Okta 
  • Work with cross functional teams to ensure alignment between GRC, Security, Marketing, Sales, Engineering, and Product 
  • Assist with development of compliance and security documentation, including system security plans, information security policies, and risk assessment procedures

 

Minimum REQUIRED Knowledge, Skills, and Abilities:

  • Bachelor’s degree or higher in Computer Science or Management Information Systems, Accounting Information Systems, or equivalent experience
  • Strong working experience and understanding of industry/regulatory security compliance frameworks - primarily NIST SP 800-53 and FedRAMP
  • At least 4 years of experience working with the FedRAMP control framework
  • Strong understanding of NIST 800-53 security controls and experienced in applying NIST 800-53 controls to a wide range of systems and applications 
  • In-depth knowledge in IT security frameworks and best practices, such as NIST-800 publications, FedRAMP, CoBIT, CCM, and Trust Principles and Criteria
  • Expert knowledge of terms and concepts used in information security, privacy, and risk assessments
  • Possesses technical understanding of how systems and applications work in a cloud environment. The candidate should understand how various infrastructure components (IaaS provider, networking components, operating systems, databases) work with and support a cloud application. 
  • Understanding of information systems processes, such as access management, authentication, change management, disaster recovery, software development lifecycle, data flows and encryption, and key management operations
  • Strong analytical and problem-solving skills and the ability to “think-out-of-the-box”
  • Strong oral, written and presentation communication skills
  • Able to work both independently and with a team

 

Helpful Certifications / Skills:

  • Certified Information System Auditor (CISA)
  • GIAC Security Essentials (GSEC)
  • Certified Information Systems Security Professional (CISSP or Associate CISSP)
  • Certificate of Cloud Security Knowledge (CCSK)
  • AWS Cloud Practitioner Certifications
  • Familiarity with JIRA and Okta
  • Technical background

Additional requirements:

  • This position requires the ability to access federal environments and/or have access to protected federal data.  As a condition of employment for this position, the successful candidate must be able to submit documentation establishing U.S. Person status (e.g. a U.S. Citizen, National, Lawful Permanent Resident, Refugee, or Asylee. 22 CFR 120.15) upon hire.

#LI-REMOTE

The annual base salary range for this position for candidates located in the San Francisco Bay area is between: $126,720—$190,080 USD

Below is the annual base salary range for candidates located in California, Colorado, New York and Washington. Your actual base salary will depend on factors such as your skills, qualifications, experience, and work location. In addition, Okta offers equity (where applicable), bonus, and benefits, including health, dental and vision insurance, 401(k), flexible spending account, and paid leave (including PTO and parental leave) in accordance with our applicable plans and policies. To learn more about our Total Rewards program please visit: https://rewards.okta.com/us.   

The annual base salary range for this position for candidates located in California (excluding San Francisco Bay Area), Colorado, New York, and Washington is between:$112,860—$170,280 USD

What you can look forward to as an Full-Time Okta employee!

  • Amazing Benefits
  • Making Social Impact
  • Fostering Diversity, Equity, Inclusion and Belonging at Okta 

Okta cultivates a dynamic work environment, providing the best tools, technology and benefits to empower our employees to work productively in a setting that best and uniquely suits their needs. Each organization is unique in the degree of flexibility and mobility in which they work so that all employees are enabled to be their most creative and successful versions of themselves, regardless of where they live. Find your place at Okta today! https://www.okta.com/company/careers/.

Okta is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, ancestry, marital status, age, physical or mental disability, or status as a protected veteran. We also consider for employment qualified applicants with arrest and convictions records, consistent with applicable laws. If reasonable accommodation is needed to participate in the job application or interview process, please use this Form to request an accommodation.

Okta is committed to complying with applicable data privacy and security laws and regulations. For more information, please see our Privacy Policy at https://www.okta.com/privacy-policy/.