Black Duck Software, Inc. helps organizations build secure, high-quality software, minimizing risks while maximizing speed and productivity. Black Duck, a recognized pioneer in application security, provides SAST, SCA, and DAST solutions that enable teams to quickly find and fix vulnerabilities and defects in proprietary code, open source components, and application behavior. With a combination of industry-leading tools, services, and expertise, only Black Duck helps organizations maximize security and quality in DevSecOps and throughout the software development life cycle.
Security Architect (for FedRAMP)
Description
We are seeking an experienced Security Architect for FedRAMP to serve as the primary technical lead for our FedRAMP authorization and ongoing continuous monitoring (ConMon) compliance. In this role, you'll own the technical interface between our contracted GRC vendor-partner, internal engineering teams, and FedRAMP stakeholders while driving remediation activities across the organization.
You'll hold authority to halt deployments and reject ConMon packages that do not meet FedRAMP evidence and SLA requirements. You'll coordinate technical implementation of NIST 800-53 Rev 5 security controls, ensure effectiveness and auditability, and serve as the final technical quality gate for control implementations and evidence schemas before submission.
As the primary technical point of contact with our GRC vendor, you'll ensure seamless collaboration on monthly ConMon deliverables including vulnerability deltas, configuration scan results, updated POA&M, inventory, access reviews, and disaster recovery documentation. You'll coordinate engineering Subject Matter Experts (SME) for Third Party Assessment Organizations (3PAO) audits and control demonstrations and lead technical discussions with FedRAMP Program Management Office (PMO) and Agency Sponsors.
Eligibility requirement:
US-based with ability to work Eastern Standard Time core business hours.
Key job responsibilities
As an experienced security professional, you will:
Basic Qualifications
Preferred Qualifications
Reporting Structure
Reports directly to the Director of Cybersecurity Governance with dotted-line responsibility to Product and Engineering Leadership. Direct communication authority with GRC Vendor, FedRAMP PMO, and U.S. Government Agency Sponsor.
Additional, as-required responsibilities:
Assist GRC and Security Operations functions in support of operational business needs.
Black Duck considers all applicants for employment without regard to race, color, religion, sex, gender preference, national origin, age, disability, or status as a Covered Veteran in accordance with federal law. In addition, Black Duck complies with applicable state and local laws prohibiting discrimination in employment in every jurisdiction in which it maintains facilities. Black Duck also provides reasonable accommodation to individuals with a disability in accordance with applicable laws.
Black Duck Software, Inc. develops automated solutions for securing and managing open source software, targeting organizations striving for high-quality, secure software development. As a leader in application security, their offerings include SAST, SCA, and DAST tools that empower teams to swiftly identify and remediate vulnerabilities across both proprietary and open source components, integrating seamlessly into the software development lifecycle.
Please mention you found this job on AI Jobs. It helps us get more startups to hire on our site. Thanks and good luck!
Understand the required skills and qualifications, anticipate the questions you may be asked, and study well-prepared answers using our sample responses.
Architect Q&A's