Security Compliance ConMon Specialist

3 weeks ago


Remote, Oregon, United States PagerDuty Full time

PagerDuty empowers teams of all kinds to do the critical work that moves business forward through the PagerDuty Operations Cloud.

Visit our careers site to explore life at PagerDuty, discover opportunities, and sign-up for job alerts


PagerDuty is seeking a Security Compliance ConMon Specialist to join our diverse, customer-focused team As a Security Compliance ConMon Specialist, you will report to the Senior Manager of Customer Trust & GRC, partnering across the business to play a crucial role in ensuring ongoing compliance with the Federal Risk and Authorization Management (FedRAMP) and SOC 2 programs for PagerDuty. You will be responsible for monitoring, assessing, and reporting on the security posture of our cloud services, ensuring adherence to established security controls and regulations. This is an exciting opportunity to support the development of our FedRAMP program and will play a key role in Customer Trust and Security Compliance. The ideal candidate will be a true team player, demonstrate expertise with security compliance programs such as SOC 2, FedRAMP, NIST, etc., know how to establish security compliance best practices, and possess great written and verbal communication skills.

KEY RESPONSIBILITIES

  • Establish and operate a FedRAMP Vulnerability Management program, including objectives, goals, and metrics.
  • Serve as the primary author for updating, maintaining, and submitting the monthly FedRAMP Continuous Monitoring Package: Plan of Actions and Milestones (POA&M), Deviation Request Forms, inventory workbook, and supporting evidence for POA&M closures.
  • Perform continuous monitoring activities in accordance with FedRAMP requirements to ensure ongoing compliance with r5 security controls.
  • Lead the development and improvement and scalability of processes, procedures, and documentation related to FedRAMP and SOC 2 compliance.
  • Debrief external stakeholders on the monthly Continuous Monitoring Package, including, but not limited to, Third-Party Assessment Organizations (3PAO), Federal Agencies, and the FedRAMP Program Management Office.
  • Participate and support FedRAMP assessment activities, including Significant Change Requests (SCR), feature onboarding, annual assessments, and agency Authority to Operate (ATO) Reviews.
  • Support customer trust programs, including the Third-Party Risk Program and play to role of SME in external audits
  • Supports information security risk assessments and compliance audits; directing the development and operational effectiveness of IT security controls.
  • Review information security risk findings and non-compliance with business leaders and propose solutions to mitigate risks.
  • Actively drives automation and the continuous improvement of team processes to ensure minimal SLAs for each process.

BASIC QUALIFICATIONS

  • 3+ years of FedRAMP experience; 6 years of Security & Compliance experience in a tech/security environment, leading at least one compliance program such as SOC 2, HITECH or similar.
  • Experience establishing, creating and managing audit workflows across multiple teams.
  • Strong analytical and organizational skills with the ability to successfully manage multiple priorities and deadlines.
  • Metrics driven, with a strong bias towards action and getting stuff done.
  • A focus on process improvement (automation, single pane of glass, continuous improvement).

PREFERRED QUALIFICATIONS

Deep understanding of relevant information security frameworks, including FedRAMP, NIST 800-53, Cybersecurity Maturity Model Certification (CMMC), and DoD Cloud Security Requirements Guide (SRG).

  • Experience in managing a FedRAMP continuous monitoring program within a Software as a Service (SaaS) company.

Past experience in a FedRAMP assessment, having participated either as an assessor or as a Cloud Service Provider (CSP) throughout the entire audit process, from initiation to completion.

  • Knowledgeable with FedRAMP requirements, processes, templates, and guidance.
  • Familiar with SaaS security tools (such as Sumo Logic, Datadog, Crowdstrike, Wiz, Snyk, and Qualys). Familiarity with contemporary risk and issue management tools (such as JIRA, Lucidchart, UpGuard and Hyperproof).
  • Proficient in utilizing Excel or Google Sheets to manipulate, analyze, and visualize vulnerability report data.
  • Familiarity with Cloud Native and SaaS constructs including architectures, DevOps, CI/CD, SecOps disciplines.

The base salary range for this position is 99, ,000 USD. This role may also be eligible for bonus, commission, equity, and/or benefits.

Our base salary ranges are determined by role, level, and location. The range, which is subject to change based on primary work location, reflects the minimum and maximum base salary we expect to pay newly hired employees for the position. Within the range, we determine pay for an individual based on a number of factors including market location, job-related knowledge, skills/competencies and experience.

Your recruiter can share more about the specific offerings for this role, as well as the salary range for your primary work location during the hiring process.


Not sure if you qualify?

Apply anyway We extend opportunities to a broad array of candidates, including those with diverse workplace experiences and backgrounds. Whether you're new to the corporate world, returning to work after a gap in employment, or simply looking to take the next step in your career path, we are excited to connect with you.

Where we work

PagerDuty currently has offices in Atlanta, Lisbon, London, San Francisco, Santiago, Sydney, Tokyo, and Toronto. We offer a hybrid, flexible workplace. We also provide ample opportunities for in-person and virtual connection, like team offsites and volunteering events.

How we work

Our values are deeply embedded in how we operate and the people we bring on board. You will see our values ingrained in how we support our customers, collaborate with our colleagues, develop our products and foster an inclusive and empathetic work culture.

  • Champion the Customer | Put users first to design great products and experiences.
  • Run Together | Build strong teams that amplify our impact on users.
  • Take the Lead | Disrupt and invent to be the first choice for users.
  • Ack + Own | Take ownership and action to deliver more efficiently to users.
  • Bring Your Self | Bring your best self to build empathy and trust with users.

What we offer

One way we ensure our employees are inspired to do their best is through a comprehensive total rewards approach that supports them and their loved ones. As a global organization, our programs are competitive with industry standards and aligned with local laws and regulations. Learn more, including country-specific offerings, on our benefits site.

Your package may include:

  • Competitive salary
  • Comprehensive benefits package from day one
  • Flexible work arrangements
  • Generous paid vacation time
  • Paid holidays and sick leave
  • Dutonian Wellness Days - scheduled company-wide paid days off in addition to PTO
  • Company equity*
  • ESPP (Employee Stock Purchase Program)*
  • Retirement or pension plan*
  • Paid parental leave - up to 22 weeks for pregnant parent, up to 12 weeks for non-pregnant parent (some countries have longer leave standards and we comply with local laws)*
  • HibernationDuty - an annual company paid week off when everyone at PagerDuty, with the exception of a small, coverage crew, is asked to take a much needed break to truly disconnect and recharge
  • Paid volunteer time off - 20 hours per year
  • Company-wide hack weeks
  • Mental wellness programs

*Eligibility may vary by role, region, and tenure

About PagerDuty

PagerDuty, Inc. (NYSE:PD) is a global leader in digital operations management. The PagerDuty Operations Cloud revolutionizes how critical work gets done, and powers the agility that drives digital transformation. Customers rely on the PagerDuty Operations Cloud to compress costs, accelerate productivity, win revenue, sustain seamless digital experiences, and earn customer trust. More than half of the Fortune 500 and more than two thirds of the Fortune 100 trust PagerDuty including Cisco, Cox Automotive, DoorDash, Electronic Arts, Genentech, Shopify, Zoom and more.

Led by CEO Jennifer Tejada, PagerDuty's Board of Directors is 50% female and 62% URP representation. We strive to build a more equitable world by investing 1% each of company equity, product, and employee volunteer time.

PagerDuty is Great Place to Work-certifiedTM, a Fortune Best Workplace for Millennials, a Fortune Best Medium Workplace, a Fortune Best Workplace in Technology, and a top rated product on TrustRadius and G2.

Go behind-the-scenes on our careers site and @pagerduty on Instagram.

Additional Information

PagerDuty is committed to creating a diverse environment and is an equal opportunity employer. PagerDuty does not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, parental status, veteran status, or disability status.

PagerDuty is committed to providing reasonable accommodations for qualified individuals with disabilities in our job application process. Should you require accommodation, please email and we will work with you to meet your accessibility needs.

PagerDuty uses the E-Verify employment verification program.



  • Remote, Oregon, United States WorkWave Full time

    POSITION SUMMARY:We are looking for a proficient and knowledgeable Cyber Security Compliance Specialist to enhance our innovative team. The successful candidate will have a solid grasp of compliance and security standards, with a focus on PCI DSS, SOC, ISO frameworks, and PrivacyShield. This position entails collaborating with multiple departments to ensure...


  • Remote, Oregon, United States WorkWave Full time

    POSITION SUMMARY:We are looking for a talented and knowledgeable Cyber Security Compliance Engineer to enhance our innovative team. The successful candidate will have a solid grasp of compliance and security frameworks, with a focus on standards such as PCI DSS, SOC, ISO, and PrivacyShield. This position requires collaboration with multiple departments to...


  • Remote, Oregon, United States WorkWave Full time

    POSITION SUMMARY:We are looking for a knowledgeable and dedicated Cyber Security Compliance Engineer to enhance our proactive security measures. The successful candidate will have a comprehensive grasp of compliance and security frameworks, particularly in PCI DSS, SOC, ISO standards, and PrivacyShield. This position requires collaboration across various...


  • Remote, Oregon, United States INSPYR Solutions Full time

    Position: Regulatory Compliance SpecialistLocation: RemoteContract Duration: 6+ month engagementCompany: INSPYR Solutions - Compensation: $25-28/hr.Eligibility: US Citizens, Green Card Holders, or individuals authorized to work in the U.S.Overview:The Regulatory Compliance Specialist will collaborate closely with team members to address regulatory compliance...


  • Remote, Oregon, United States Consensus Cloud Solutions Full time

    Consensus Cloud Solutions is a publicly traded, leading digital cloud fax and interoperability solutions organization in the United States and globally, focusing on connecting and empowering healthcare providers, payers, care teams, and technology innovators to unify multiple systems that wouldn't otherwise talk to each other. Consensus is a trailblazer in...


  • Remote, Oregon, United States reddit Full time

    Company OverviewReddit is a vibrant community platform where diverse interests and authentic conversations thrive. With millions of active users and communities, Reddit serves as a significant source of information and engagement on the internet.Team OverviewThe SPACE (Security, Privacy, And Compliance Engineering) team is dedicated to safeguarding Reddit's...


  • Remote, Oregon, United States Prepaid Wireless Wholesale LLC Full time

    Job SummaryWe are seeking a detail-oriented Compliance and Audit Specialist to join our team at Prepaid Wireless Wholesale LLC. As a key member of our compliance and risk management team, you will be responsible for ensuring adherence to verification processes, addressing compliance inquiries and escalations, conducting audits, and working closely with...


  • Remote, Oregon, United States WorkWave Full time

    Job SummaryWe are seeking a highly skilled and experienced Cyber Security Engineer to join our dynamic team at WorkWave. As a key member of our security team, you will be responsible for implementing and maintaining compliance with industry standards, conducting regular audits and assessments, and developing and updating policies and procedures to support...

  • Compliance Analyst

    2 months ago


    Remote, Oregon, United States MicroVentures Full time

    MicroVentures, a leading equity crowdfunding platform, is seeking a Compliance Analyst. The compliance team is responsible for investment, communications, and document review to ensure the Firm meets its obligations relative to applicable federal and state securities regulations.The Compliance Analyst role is an integral function with the MicroVentures team,...


  • Remote, Oregon, United States Codeworks L.L.C Full time

    Job OverviewCodeworks L.L.C is a prominent IT Services organization based in Southeastern Wisconsin, recognized for our unwavering dedication to excellence and our direct engagement with clients.Who We Are Seeking:Our client is in search of a seasoned Cyber Security Specialist II to become a vital member of their Information and Data Security Team. The ideal...


  • Remote, Oregon, United States reddit Full time

    Company OverviewReddit is a vibrant platform that fosters communities based on shared interests and authentic discussions. With millions of daily active users, it stands as one of the largest sources of information on the internet.Team OverviewThe SPACE (Security, Privacy, And Compliance Engineering) team is dedicated to safeguarding Reddit's workforce and...


  • Remote, Oregon, United States infinite Computing Systems Full time

    Summary:Iowa Vocational Rehabilitation Services is recruiting a technical specialist/developer to enhance the Iowa Rehabilitation Services System (IRSS) for case management.Job description:Iowa Vocational Rehabilitation Services is recruiting a technical specialist/developer to enhance the Iowa Rehabilitation Services System (IRSS) for case management. This...


  • Remote, Oregon, United States The Chemours Company Full time

    Job DescriptionJob Summary:The Chemours Company is seeking a highly skilled Global Substance Registration Project Manager to join our team. As a key member of our regulatory compliance team, you will be responsible for developing and implementing the substance registration strategy, coordinating with regulatory experts and consultants to prepare registration...


  • Remote, Oregon, United States CSI Pharmacy Full time

    Job SummaryCareer Opportunity at CSI PharmacyAbout the RoleWe are seeking a highly skilled Revenue Cycle Audit Specialist to join our team at CSI Pharmacy. As a key member of our revenue cycle team, you will play a critical role in ensuring the accuracy and compliance of our medical claims submissions.Key ResponsibilitiesConduct thorough audits of commercial...

  • Compliance Associate

    4 weeks ago


    Remote, Oregon, United States Atomic Invest Full time

    About AtomicWe are a fast-growing, mission-driven company powering the expansion of financial services and wealth creation globally. We build critical financial infrastructure that allows consumer-facing companies to offer engaging investing experiences to their customers in a frictionless way. We host advanced investing capabilities ranging from ESG...

  • Compliance Analyst

    1 month ago


    Remote, Oregon, United States Mbanq Full time

    DescriptionAbout Us:Mbanq is a Banking-as-a-Service provider with operations and customers in the United States. Mbanq was established to provide the technological capabilities necessary to create and operate digital financial services. Mbanq's solutions are suitable for both retail and corporate clients. Consumer use cases supported range from the basic...


  • Remote, Oregon, United States WorkWave Full time

    Job SummaryWe are seeking a highly skilled and experienced Cyber Security Engineer to join our dynamic team at WorkWave. The ideal candidate will possess a strong understanding of both compliance and security principles, including expertise in industry standards and regulatory requirements.Key ResponsibilitiesCompliance and Security: Implement and maintain...


  • Remote, Oregon, United States Level Access Full time

    Working with the Director of Information Security, the Senior Security Engineer role at Level Access will be responsible for helping Level Access scale its goal of being the most secure company in digital accessibility. Primary responsibilities include: leading the multi-framework compliance program; designing and implementing an appropriately-sized...


  • Remote, Oregon, United States myGwork Full time

    About Us: We are a proud member of myGwork, the premier global platform dedicated to the LGBTQ+ business community. Our organization is committed to fostering an inclusive environment where diversity thrives. Position Overview: We are seeking a seasoned professional to lead our Compliance and Regulatory Affairs team. This role is pivotal as we expand our...

  • Director, FED Sales

    1 month ago


    Remote, Oregon, United States Orca Security Full time

    Location: North East- DC/VAABOUT USDive right in. Swim with our pod. At Orca, in the right environment and with the right team, talent has no boundaries. This team spirit, together with our drive to always aim high, has quickly earned us unicorn status and turned us into a global cloud security innovation leader. So if you're ready to join an amazing team of...