A career in IBM Software means you’ll be part of a team that transforms our customer’s challenges into solutions.
Seeking new possibilities and always staying curious, we are a team dedicated to creating the world’s leading AI-powered, cloud-native software solutions for our customers. Our renowned legacy creates endless global opportunities for our IBMers, so the door is always open for those who want to grow their career.
IBM’s product and technology landscape includes Research, Software, and Infrastructure. Entering this domain positions you at the heart of IBM, where growth and innovation thrive.
The ideal candidate for this role will become an active member of a globally distributed team responsible for ensuring MaaS360, IBM’s Unified Endpoint Management offering, is running smoothly and providing customers the quality of service they’ve come to expect. This role is focused on working with multiple technology and offering teams to ensure the MaaS360 is deployed, supported to achieve both corporate and regulatory compliance requirements with specific focus on FedRAMP, FBA/ FFIEC, SOC 2, and NIST 800-53. The candidate will be working in an exciting and rapidly expanding environment driving high standards while collaborating with a group of skilled engineers and developers from around the world. The successful applicant will be performing work in FedRAMP environments, and therefore, must be a U.S. Person (although US Citizen is preferred)
- Demonstrate familiarity with current FedRAMP and NIST Security controls and technologies, including vulnerability management capabilities
- Ability to develop and lead FedRAMP documentations such as the
- Lead recurring ConMon meetings; including review and submission of required artifacts, aid annual 3PAO security assessment, and generate or facilitate deviation requests as needed.
- Conduct continuous monitoring activities to assess the effectiveness of security controls and identify potential vulnerabilities or non-compliance issues.
- Lead internal and external audits for example FedRAMP, SOC2, and Internal corporate audits.
- Develop dashboarding and metric reporting to ensure the FedRAMP Continuous Monitoring program is meeting compliance obligations.
- Flexible, self-motivated, and able to work independently in a fast paced environment
- Excellent communication skills and the proven ability to work effectively with all levels of IT and business management
- Skill in preparing and making written and oral presentations of complex technical nature
- Understand enterprise operating environments, including security posture, application environment, and associated security controls
- Understand/document information system specifications and security controls, including logical and physical diagrams, connectivity, communication, and data flow diagrams, both internal and external to the system
- Gather information, architecture diagrams and implementation of the security controls by interfacing with security engineering, operations and build teams and use inputs to develop compliance documentation.
- Assist with the FedRAMP or FISMA authorization to include, but not limited to, prep of security engineering, build, and ops teams through training & mock interviews, update implementation language in security documentation and develop processes as required in support of FedRAMP PMO/ Agency / CISO requests
- Track and oversee the vulnerability remediation efforts in order to advise leadership as required on status blockers, and escalation when needed
- Prepare and present regular reports on the status of FedRAMP compliance activities to management and relevant partners
- Drive compliance efforts including audit coordination, reporting, risk management and continuous compliance reporting
- Coordinate security audits performed by both internal and external parties
- Engage offering teams and other business units to drive compliance efforts
- Help design and work within security architecture of continuous compliance with both operations and management teams
- Partner cross-functionally across the organization to support the implementation of technical, management, and operational controls, with a focus on controls required to deliver and operate regulated environments.
- 5+ years experience in security and compliance
- Experience working with external and internal auditors to appropriately convey compliance posture
- Working with multiple compliance standards to meet each regulation’s required parameters
- Ability to build standard templates that are compliant to regulatory standards
- Technical experience running vulnerability scanning solutions such as Tenable, Nessus/Security Center, OWSAP, Twistlock
- Familiarity with vulnerability management concepts, such as CVE and CVSS
- Experience in filing deviation requests for vulnerabilities on behalf of product teams
- One or more related professional certifications (e.g. CISSP, CRISC, CISM)
- Knowledge and experience in large, hybrid FedRAMP or highly regulated programs
- Excellent communication and technical documentation skills
- Experience working in a compliance role in a SaaS organization
- Degree in Computer Science or related discipline or equivalent work experience
- Understanding of current cloud technologies and web-services concepts
- Understanding agile software development life cycle, continuous integration, continuous delivery