About this role
Elastic, the Search AI Company, enables everyone to find the answers they need in real time, using all their data, at scale — unleashing the potential of businesses and people. The Elastic Search AI Platform, used by more than 50% of the Fortune 500, brings together the precision of search and the intelligence of AI to enable everyone to accelerate the results that matter. By taking advantage of all structured and unstructured data — securing and protecting private information more effectively — Elastic’s complete, cloud-based solutions for search, security, and observability help organizations deliver on the promise of AI.
What Is The Role :
Join our team as a Principal Security Compliance Analyst , where you'll take the lead in managing our FedRAMP Moderate program . You'll be part of a fantastic team that values a strong security culture, allowing you to contribute meaningfully to our mission while collaborating with like-minded professionals. Your expertise will help us maintain and enhance our compliance efforts in a supportive and engaging environment.
What You Will Be Doing :
• Manage the FedRAMP Moderate authorization and continuous monitoring program.
• Maintain the System Security Plan, policies, procedures, evidence, inventories, diagrams, and other required documentation.
• Coordinate assessments and reviews with our 3PAO, federal agency partners, consultants, and internal teams.
• Track security findings and POA&M items through remediation.
• Work with Security, Engineering, IT, Product, and Legal teams to implement and maintain required controls.
• Monitor program deadlines, risks, and compliance metrics and report progress to leadership.
• Review system and product changes for potential FedRAMP impact.
• Help control owners understand their responsibilities and prepare appropriate evidence.
What You Bring :
• 5+ years of experience managing or supporting a FedRAMP Moderate program.
• Strong understanding of FedRAMP, NIST SP 800-53, and continuous monitoring requirements.
• Experience with SSPs, POA&Ms, control evidence, vulnerability management, and security assessments.
• Strong project-management and organizational skills.
• Ability to communicate effectively with technical teams, auditors, government stakeholders, and company leadership.
• Eligible to work in Department of Defense (DoD) Impact Level 4 or above cloud service environments.
Compensation for this role is in the form of base salary. This role does not have a variable compensation component.
The typical starting salary range for new hires in this role is listed below. In select locations (including Seattle WA, Los Angeles CA, the San Francisco Bay Area CA, and the New York City Metro Area), an alternate range may apply as specified below.
These ranges represent the lowest to highest salary we reasonably and in good faith believe we would pay for this role at the time of