Senior Compliance Engineering Architect (FedRAMP 20x)
Remote
Full Time
Compliance
Experienced
The Team
UberEther is a leader in the hyper-secure infrastructure space for Identity and Access Management (IAM), #ZeroTrust and compliance acceleration. Our platform and expert services team enable government and commercial customers to have ultimate control over access to critical information. We are employee first, with outstanding benefits and a track record of upskilling and fostering growth. We're looking for employees who get excited about pioneering novel solutions to new, complex challenges.This role sits within UberEther's Compliance Business Unit, supporting a FedRAMP 20x advisory project built on Google Cloud Platform (GCP). As Senior Compliance Architect, you will serve as the technical bridge between FedRAMP 20x compliance requirements and platform engineering, translating Key Security Indicators (KSIs) into a concrete, defensible GCP-native platform architecture — ensuring the environment meets assessor expectations and holds up under continuous monitoring.
Responsibilities
Strategic Technical Leadership
- Serve as the principal technical authority translating FedRAMP 20x KSI requirements into platform architecture decisions for the engagement
- Define and maintain the technical roadmap for mapping all KSIs across the FedRAMP KSI families to concrete GCP services, configurations, and evidence sources for the Advantage compliance model
- Lead architecture reviews and design sessions with engineering leadership to ensure GCP deployments satisfy FedRAMP 20x assessment requirements
- Drive technical decision-making on control inheritance, continuous monitoring strategy, and KSI verification approach for a GCP-hosted identity platform
- Partner with the Compliance BU leadership team to translate FedRAMP 20x milestones into technical initiatives and delivery rocks
- Establish architectural standards and design patterns for KSI-mapped platform components that can be reused across future GCP engagements
GCP Platform Architecture & KSI Mapping
- Own the end-to-end technical architecture that maps all FedRAMP 20x KSIs onto concrete Advantage GCP service configurations, IAM policies, and network controls
- Lead the design of Infrastructure as Code templates (Terraform, Deployment Manager) that encode KSI requirements directly into GCP deployments
- Drive automation initiatives that generate continuous compliance evidence directly from GCP-native logging, monitoring, and security services
- Provide architectural guidance on GCP IAM, VPC Service Controls, Cloud KMS, and Security Command Center as they relate to KSI satisfaction
- Collaborate with the Engineering team to align GCP-specific automation with UberEther's existing GitLab and Terraform tooling
- Champion a KSI-first design approach so security and compliance controls are architected in from day one, not retrofitted
Customer Success & Technical Advisory
- Serve as the escalation point for complex FedRAMP 20x KSI questions from the engineering and Customer Success teams
- Lead technical architecture workshops with stakeholders to walk through KSI-to-control mappings and remediation paths
- Provide expert guidance on translating KSI evidence requirements into System Security Plan (SSP) and machine readable/OSCAL-based technical documentation
- Support pre-sales and advisory activities by explaining FedRAMP 20x architecture decisions during customer briefings
- Translate platform requirements into technical designs that align with Advantage delivery model
- Drive continuous improvement of the KSI mapping based on assessor feedback, CR26 verification results, and evolving FedRAMP 20x guidance
Compliance Architecture & Continuous Monitoring
- Work closely with the DevOps and Support functions to ensure GCP monitoring, dashboards, and alerting align with KSI evidence requirements
- Lead the technical design of automated KSI verification, including how each of the KSI families is evidenced on an ongoing basis
- Provide architectural guidance for remediation runbooks and system hardening standards specific to GCP-hosted workloads
- Support 3PAO assessments and FedRAMP 20x reviews by explaining the platform architecture and how it satisfies each KSI
- Drive adoption of Policy as Code and OSCAL-based evidence generation across the platform
- Ensure proper integration between GCP-native security tooling and UberEther's compliance automation approach
Cross-Team Collaboration & Mentorship
- Foster technical collaboration between UberEther's Compliance BU and engineering team through regular architecture syncs
- Mentor engineers on GCP architecture, FedRAMP 20x KSI requirements, and secure design principles
- Lead retrospectives focused on improving the KSI-to-architecture mapping process for future GCP engagements
- Participate in Level 10 (L10) meetings, providing technical insight on progress and cross-team dependencies
- Develop training content to help engineers understand FedRAMP 20x KSI requirements and their architectural implications
- Serve as a technical ambassador for UberEther's FedRAMP 20x advisory capabilities with future GCP customers
Primary Qualifications
Education & Experience
- Bachelor's degree in Computer Science, Engineering, Cybersecurity, or related technical field; Master's degree preferred
- 10+ years of experience in cloud architecture, security engineering, or compliance-focused technical roles
- 5+ years of experience architecting solutions on Google Cloud Platform (GCP) in a security- or compliance-sensitive environment
- Proven track record of translating FedRAMP, DoD, or other federal compliance frameworks into technical architecture
- Deep experience with federal compliance frameworks, including NIST 800-53, FedRAMP 20x, Risk Management Framework (RMF), and continuous monitoring requirements
Technical Expertise
- Expert-level knowledge of Google Cloud Platform (GCP) services, security controls, and compliance capabilities, with relevant certifications (Professional Cloud Architect or Professional Cloud Security Engineer preferred)
- Strong understanding of FedRAMP 20x Key Security Indicators (KSIs) and how they map to concrete platform controls
- Deep expertise in Infrastructure as Code tools (Terraform, Deployment Manager) and GitOps workflows
- Strong understanding of containerization technologies (Docker, Kubernetes/GKE) in secure, compliance-focused environments
- Comprehensive knowledge of Identity and Access Management solutions and Zero Trust architecture principles
- Experience with compliance automation and evidence-generation tooling, including OSCAL and Policy as Code frameworks
Compliance & Security Knowledge
- Expert understanding of FedRAMP 20x requirements, KSI families, and continuous compliance obligations
- Deep knowledge of NIST 800-53 security controls and their technical implementation on Google Cloud Platform
- Strong familiarity with FedRAMP authorization processes and Assessment & Authorization (A&A) activities
- Experience with FISMA, FIPS 140-2, and related federal security requirements
- Proven ability to translate compliance requirements directly into technical architectures and control implementations
Leadership & Communication
- Exceptional communication skills with ability to explain complex KSI and compliance concepts to engineers, assessors, and executives
- Proven ability to lead without direct authority, influencing technical direction across UberEther and customer engineering teams
- Strong customer-facing skills with experience presenting technical architectures to federal customers and compliance assessors
- Demonstrated project management skills with ability to manage a KSI mapping effort across multiple workstreams
- Track record of building consensus and driving technical decisions in fast-paced, dynamic environments
Differentiators
- Professional certifications: CISSP, CISA, CISM, Google Professional Cloud Architect/Security Engineer, or TOGAF
- Prior experience supporting a FedRAMP 20x pilot engagement
- Background in software or platform architecture on Google Cloud Platform specifically
- Published thought leadership in cloud security, compliance automation, or FedRAMP 20x
- Experience with compliance automation frameworks such as OSCAL, InSpec, or similar Policy as Code tools
Location
This role is offered as a hybrid or remote position based out of our Sterling, VA office. Please ensure you meet all eligibility requirements before applying.Salary
The base salary range for this position is between $170,000 - $210,000 depending on experience.Benefits
We understand the value of such people, reward them accordingly, and provide best-in-class benefits to support them and their family's well-being. Full-time employees are eligible to receive top-notch Medical, Dental, Vision, 401K savings plan, Life Insurance, and Short and Long-term Disability benefits as well as generous paid flex-time, education and technology reimbursement.This includes:
- 100% employer covered health care premiums for employee AND dependents
- 100% match up to 6% 401k
- Education and professional development budget
- 25 PTO days per year, which increases with tenure
- Annual technology budget
Core Values
UberEther's Core Values are a set of guiding principles that define our expectations of employees. Please be prepared to discuss these in your interview process and provide examples of where you have demonstrated these core values.- Grow With Purpose - Continuously develop your skills and knowledge while helping others grow
- Confident, Not Cocky - Bring expertise with humility and openness to learning
- The IT Factor - Demonstrate passion, initiative, and the ability to make things happen
- Team Player - Collaborate effectively and put team success ahead of individual recognition
- Whole Authentic Self - Bring your complete, genuine self to work every day
All qualified applicants will receive consideration for employment without regard to race, color, religion, sexual orientation, gender identity, national origin, age, disability or protected veteran status, or any other legally protected basis, in accordance with applicable law.
Apply for this position
Required*