Federal Compliance Manager

Palantir Palantir · Enterprise · Washington, DC · Information Security

Palantir is seeking a Federal Compliance Manager to manage and architect their Federal Compliance program, including FedRAMP, IL5, and IL6. The role involves working with various teams to scale the program, identify automation opportunities, and provide guidance on technical architecture, documentation, and operational concerns within complex Federal regulatory frameworks.

What you'd actually do

  1. Oversee operational and regulatory outcomes across our US Government client portfolio, including FedRAMP, IL5, and IL6 continuous monitoring and compliance audits.
  2. Propose and implement ideas for operational improvements and facilitate automation for procedural compliance controls.
  3. Evaluate and advise the business on new and evolving US Government certification programs (ex. FedRAMP 20x), requirements, and technologies.
  4. Maintain and lead partnerships with various agencies (DoD, HHS, etc.) and the FedRAMP PMO, staying atop of all industry updates and changes to the program.
  5. Drive enterprise-wide compliance strategies and cross-functional initiatives.

Skills

Required

  • FedRAMP
  • IL5
  • IL6
  • FISMA
  • NIST 800-53
  • NIST 800-171
  • US Government ATOs
  • cloud infrastructure
  • security controls
  • distributed applications
  • AWS
  • Azure
  • Project Management
  • encryption
  • authentication
  • continuous monitoring tools

Nice to have

  • PCI
  • SOC2
  • HIPAA
  • containers
  • Tenable Security Center
  • Burp
  • SIEMs

What the JD emphasized

  • 7+ years experience with compliance audits (FedRAMP, PCI, SOC2, HIPAA, etc.) and prior US Government compliance and audit experience (FedRAMP, FISMA, NIST 800-53, NIST 800-171, US Government ATOs, etc).
  • Experience with managing distributed compliance teams and scaling programs.
  • Deep understanding of complex cloud infrastructure and security concepts, including ephemeral technologies (ex. containers).
  • Experience implementing security controls and assessing compliance in distributed applications on cloud infrastructure (e.g Amazon AWS, Microsoft Azure).
  • Proficiency with security concepts (encryption, authentication, etc.) and tooling for continuous monitoring (Tenable Security Center, Burp, SIEMs, etc.).