Logo
Pager

Security Compliance ConMon Specialist Toronto

Pager, San Francisco, California, United States, 94199


PagerDuty empowers teams of all kinds to do the critical work that moves business forward through the PagerDuty Operations Cloud.PagerDuty is seeking a Security Compliance ConMon Specialist to join our diverse, customer-focused team! As a Security Compliance ConMon Specialist, you will report to the Senior Manager of Customer Trust & GRC, partnering across the business to play a crucial role in ensuring ongoing compliance with the Federal Risk and Authorization Management (FedRAMP) and SOC 2 programs for PagerDuty. You will be responsible for monitoring, assessing, and reporting on the security posture of our cloud services, ensuring adherence to established security controls and regulations. This is an exciting opportunity to support the development of our FedRAMP program and will play a key role in Customer Trust and Security Compliance. The ideal candidate will be a true team player, demonstrate expertise with security compliance programs such as SOC 2, FedRAMP, NIST, etc., know how to establish security compliance best practices, and possess great written and verbal communication skills.This role is expected to come into our Toronto office one day per month, so you can thrive in your new role and fully embrace being a Dutonian!KEY RESPONSIBILITIESEstablish and operate a FedRAMP Vulnerability Management program, including objectives, goals, and metrics.Serve as the primary author for updating, maintaining, and submitting the monthly FedRAMP Continuous Monitoring Package: Plan of Actions and Milestones (POA&M), Deviation Request Forms, inventory workbook, and supporting evidence for POA&M closures.Perform continuous monitoring activities in accordance with FedRAMP requirements to ensure ongoing compliance with 800-53 r5 security controls.Lead the development and improvement and scalability of processes, procedures, and documentation related to FedRAMP and SOC 2 compliance.Debrief external stakeholders on the monthly Continuous Monitoring Package, including, but not limited to, Third-Party Assessment Organizations (3PAO), Federal Agencies, and the FedRAMP Program Management Office.Participate and support FedRAMP assessment activities, including Significant Change Requests (SCR), feature onboarding, annual assessments, and agency Authority to Operate (ATO) Reviews.Support customer trust programs, including the Third-Party Risk Program and play the role of SME in external audits.Support information security risk assessments and compliance audits; directing the development and operational effectiveness of IT security controls.Review information security risk findings and non-compliance with business leaders and propose solutions to mitigate risks.Actively drive automation and the continuous improvement of team processes to ensure minimal SLAs for each process.BASIC QUALIFICATIONS3+ years of FedRAMP experience; 6 years of Security & Compliance experience in a tech/security environment, leading at least one compliance program such as SOC 2, HITECH or similar.Experience establishing, creating and managing audit workflows across multiple teams.Strong analytical and organizational skills with the ability to successfully manage multiple priorities and deadlines.Metrics driven, with a strong bias towards action and getting stuff done.A focus on process improvement (automation, single pane of glass, continuous improvement).PREFERRED QUALIFICATIONSDeep understanding of relevant information security frameworks, including FedRAMP, NIST 800-53, Cybersecurity Maturity Model Certification (CMMC), and DoD Cloud Security Requirements Guide (SRG).Experience in managing a FedRAMP continuous monitoring program within a Software as a Service (SaaS) company.Past experience in a FedRAMP assessment, having participated either as an assessor or as a Cloud Service Provider (CSP) throughout the entire audit process, from initiation to completion.Knowledgeable with FedRAMP requirements, processes, templates, and guidance.Familiar with SaaS security tools (such as Sumo Logic, Datadog, Crowdstrike, Wiz, Snyk, and Qualys). Familiarity with contemporary risk and issue management tools (such as JIRA, Lucidchart, UpGuard and Hyperproof).Proficient in utilizing Excel or Google Sheets to manipulate, analyze, and visualize vulnerability report data.Familiarity with Cloud Native and SaaS constructs including architectures, DevOps, CI/CD, SecOps disciplines.The base salary range for this position is 97,000 - 142,000 CAD. This role may also be eligible for bonus, commission, equity, and/or benefits.Apply anyway! We extend opportunities to a broad array of candidates, including those with diverse workplace experiences and backgrounds. Whether you're new to the corporate world, returning to work after a gap in employment, or simply looking to take the next step in your career path, we are excited to connect with you.About PagerDutyPagerDuty, Inc. (NYSE:PD) is a global leader in digital operations management. The PagerDuty Operations Cloud revolutionizes how critical work gets done, and powers the agility that drives digital transformation.PagerDuty is committed to creating a diverse environment and is an equal opportunity employer. PagerDuty does not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, parental status, veteran status, or disability status.

#J-18808-Ljbffr