WHAT YOU’LL DO HERE
• Own authorization integrity. Maintain Cohesity’s FedRAMP Class C, GovRAMP Moderate, and CMMC L1/L2 certifications. Lead continuous monitoring (ConMon) efforts and maintenance of required documentation.
• Govern the authorized boundary. Manage the significant change process, including review and sign off on changes, and ensuring engineering and infrastructure teams understand what triggers a formal notification requirement.
• Lead regulatory transitions. Drive adoption of FedRAMP’s Consolidated Rules, including new VDR/VER rulesets, and develop a defensible Rev5-to-20x conversion recommendation. Stay informed about evolving framework requirements and translate operational implications to leadership.
• Own assessment cycles. Serve as the primary interface for third-party assessors across annual FedRAMP and GovRAMP assessments and the triennial CMMC Level 2 assessment — readiness, facilitation, evidence gathering, and finding remediation.
• Translate compliance into engineering guidance. Convert control requirements into acceptance criteria that engineering and cloud operations teams can act on, and challenge implementations that fall short.
• Shape the federal offering. Partner with Product Management and Federal Sales to deliver a compliant offering that supports business growth and drives competitive advantage.
• Build the AI-enabled compliance program. Own machine-readable, AI-consumable artifact schemas, set the evidentiary standard automated work must meet, and help move the program from human-heavy to agent- leveraged operations.