Staff Federal Security Compliance Analyst at Okta
Washington, District of Columbia, USA -
Full Time


Start Date

Immediate

Expiry Date

08 Jul, 25

Salary

241000.0

Posted On

08 Apr, 25

Experience

0 year(s) or above

Remote Job

Yes

Telecommute

Yes

Sponsor Visa

No

Skills

Information Security, Disaster Recovery, Documentation, Control Framework, Databases, Ccm, Communication Skills, Encryption, Cobit, Perspectives, Software Development, Information Systems, Regulations, Operating Systems, Nist, Jira, Automation, Authentication

Industry

Information Technology/IT

Description

GET TO KNOW OKTA

Okta is The World’s Identity Company. We free everyone to safely use any technology—anywhere, on any device or app. Our Workforce and Customer Identity Clouds enable secure yet flexible access, authentication, and automation that transforms how people move through the digital world, putting Identity at the heart of business security and growth.
At Okta, we celebrate a variety of perspectives and experiences. We are not looking for someone who checks every single box - we’re looking for lifelong learners and people who can make us better with their unique experiences.
Join our team! We’re building a world where Identity belongs to you.
This position is for a Staff Federal Security Compliance Analyst on the Okta Federal Security and Compliance team. This team’s mission is to strengthen Okta’s position as the leading Identity-as-a-Service solution through a security-first approach to compliance. This team is largely focused on working with internal and external stakeholders to maintain our FedRAMP authorizations for our Okta government systems.
As a Staff Federal Security Compliance Analyst on this team, you will support security initiatives by engaging various process owners in the design, documentation, implementation, monitoring of the appropriate controls in our computing environments. This candidate will also work with internal and external stakeholders to improve our compliance posture, security controls, and compliance related processes.
The ideal candidate will have hands-on experience with the technical implementation or evaluation of FedRAMP Moderate, High, DoD Impact Level 4 and Level 5 controls in cloud-based environments using tools such as Okta, AWS, ServiceNow, JIRA, and others. This position requires a unique set of skills including project management, technical competency, knowledge of federal compliance frameworks, and an eye towards future standards and regulations that will impact federal service offerings.

MINIMUM REQUIRED KNOWLEDGE, SKILLS, AND ABILITIES:

  • Bachelor’s degree or higher in Computer Science or Management Information Systems, Accounting Information Systems, or equivalent experience
  • Strong working experience and understanding of industry/regulatory security compliance frameworks - primarily NIST SP 800-53 and FedRAMP
  • At least 4 years of experience working with the FedRAMP control framework
  • Strong understanding of NIST 800-53 security controls and experienced in applying NIST 800-53 controls to a wide range of systems and applications
  • In-depth knowledge in IT security frameworks and best practices, such as NIST-800 publications, FedRAMP, CoBIT, CCM, and Trust Principles and Criteria
  • Expert knowledge of terms and concepts used in information security, privacy, and risk assessments
  • Possesses technical understanding of how systems and applications work in a cloud environment. The candidate should understand how various infrastructure components (IaaS provider, networking components, operating systems, databases) work with and support a cloud application.
  • Understanding of information systems processes, such as access management, authentication, change management, disaster recovery, software development lifecycle, data flows and encryption, and key management operations
  • Strong analytical and problem-solving skills and the ability to “think-out-of-the-box”
  • Strong oral, written and presentation communication skills
  • Able to work both independently and with a team

HELPFUL CERTIFICATIONS / SKILLS:

  • Certified Information System Auditor (CISA)
  • GIAC Security Essentials (GSEC)
  • Certified Information Systems Security Professional (CISSP or Associate CISSP)
  • Certificate of Cloud Security Knowledge (CCSK)
  • AWS Cloud Practitioner Certifications
  • Familiarity with JIRA and Okta
  • Technical background

ADDITIONAL REQUIREMENTS:

  • This position requires the ability to access federal environments and/or have access to protected federal data. As a condition of employment for this position, the successful candidate must be able to submit documentation establishing U.S. Person status (e.g. a U.S. Citizen, National, Lawful Permanent Resident, Refugee, or Asylee. 22 CFR 120.15) upon hire.
Responsibilities
  • Work with internal and external stakeholders to support FedRAMP and DoD audits of the company’s federal cloud offerings
  • Collaborate with team members and engineering stakeholders to manage continuous monitoring program across all federal environments, including internal and external reporting on vulnerabilities and developing continuous monitoring presentations
  • Work with process and control owners to help them understand the control requirements, audit results, and provide advisory around remediation options
  • Interpret requirements across multiple compliance frameworks (specifically FedRAMP), and provide clarification to engineering teams seeking compliance advice
  • Assess security and compliance impact of changes to the federal systems and applications. Work with internal and external stakeholders to ensure high impact changes are handled appropriately
  • Coordinate with multiple distributed teams to communicate requirements and gather necessary artifacts and information to support compliance audit requirements
  • Lead efforts to analyze gaps between current status and future compliance framework needs for new products
  • Collaborate with private sector compliance teams (SOC, PCI, HITRUST, etc.) to maintain and expand a common controls framework for Okta
  • Work with cross functional teams to ensure alignment between GRC, Security, Marketing, Sales, Engineering, and Product
  • Assist with development of compliance and security documentation, including system security plans, information security policies, and risk assessment procedures
Loading...