Job Description
Marathon TS is seeking a highly experienced Senior FedRAMP Consultant to support a client who continues to build out their ADVISORY practice in the FedRAMP / CMMC Advisory space. All candidates MUST HAVE experience the development and execution of FedRAMP High + DoD IL5 authorization packages. This role is for a senior, hands-on practitioner with deep expertise in FedRAMP High, IL5 requirements, FedRAMP 20x, and KSI-driven automation.
The position is an individual contributor role with a strong expectation of independent execution while working collaboratively with other senior advisors, engineers, and client stakeholders. The primary focus of this role will be authoring, validating, and assembling a FedRAMP High IL5 authorization package that is technically accurate, defensible, and audit-ready.
Compensation is commensurate with experience.
- Duties & Responsibilities:FedRAMP High & IL5 Advisory
- Serve as a senior subject matter expert for FedRAMP High and DoD IL5 authorizations
- Lead technical contribution to FedRAMP High IL5 package development, including:
- System Security Plan (SSP) authoring
- Control implementation narratives
- Supporting artifacts aligned to FedRAMP High and IL5 expectations
- Interpret and apply:
- FedRAMP High baseline requirements
- DoD SRG IL5 overlays and constraints
- Agency- and assessor-specific expectations
- Work directly with:
- 3PAOs and assessors
- Customer security, platform, and compliance teams
- Peer bladestack.io advisors embedded on the same engagement
- FedRAMP 20x & KSI Automation
- Apply FedRAMP 20x principles to High / IL5 environments
- Design and support KSI-driven security models, including:
- Mapping KSIs to NIST 800-53 controls and FedRAMP High baselines
- Implementing automated evidence collection and validation
- Integrating KSIs into CI/CD pipelines and cloud-native telemetry
- Support continuous assessment and continuous monitoring models aligned with FedRAMP 20x objectives
- Minimize manual compliance effort while maintaining audit defensibility
- Azure GCC High Technical Expertise
- Act as a hands-on technical advisor for Microsoft Azure, with strong preference for:
- Azure Government / GCC High
- FedRAMP High and IL5-aligned architectures
- Provide architectural guidance for:
- Secure landing zones
- Identity, networking, logging, and monitoring architectures
- Boundary definition and control inheritance
- Understand Infrastructure-as-Code implementations (Bicep, ARM, Terraform)
- Deep familiarity with:
- Azure-native security services
- Logging, monitoring, and compliance tooling required for High / IL5
- AI & Emerging Technology (Preferred)
- Experience or familiarity with AI/ML technologies in regulated cloud environments
- Ability to advise on:
- Security and compliance implications of AI-enabled workloads
- FedRAMP High and IL5 considerations for AI services
- Governance, monitoring, and risk management for AI systems
- Documentation & Package Development
- Primary responsibility for authoring and assembling FedRAMP High IL5 documentation, including:
- SSPs
- Control narratives
- Security architecture documentation
- Produce original, technically accurate documentation, not template-only rewording
- Ensure documentation reflects actual system implementations, architectures, and security controls
- Support development of engineering artifacts capturing:
- System security requirements
- Application security design
- Continuous monitoring and automated compliance workflows
- Working Style & Collaboration
- Operate independently and efficiently with minimal oversight
- Integrate seamlessly with:
- Other senior advisors on the engagement
- Client engineers, security teams, and stakeholders
- Communicate clearly in both technical and compliance contexts
- Maintain strong personal discipline in task tracking, delivery timelines, and documentation quality
- Required Experience & Qualifications
- Direct, hands-on FedRAMP High experience is required
- FedRAMP High + DoD IL5 experience is highly preferred
- Proven experience assembling FedRAMP High authorization packages
- Strong understanding of:
- NIST 800-53
- NIST RMF
- FedRAMP High baselines
- DoD IL5 SRG requirements
- Strong technical background in Azure, preferably Azure GCC High
Experience working directly with auditors, assessors, and engineering teams #CJJOBS
Marathon TS is committed to the development of a creative, diverse and inclusive work environment. In order to provide equal employment and advancement opportunities to all individuals, employment decisions at Marathon TS will be based on merit, qualifications, and abilities. Marathon TS does not discriminate against any person because of race, color, creed, religion, sex, national origin, disability, age or any other characteristic protected by law (referred to as "protected status ").
Apply tot his job
Apply To this Job