Principal Security Compliance Analyst, Public Sector, InfoSec

Elastic

Confirmed live yesterday High trust

Quick summary

Work type
On-site
Location
Salary
$159,800–$252,800 / yr
Posted
5 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

Above market

How this pay compares to similar roles

Similar $163k
This role $206k
$109k most similar roles pay here $268k

This role pays more than 81% of similar roles. Most pay $135,000–$191,800 — the shaded band above. At the midpoint, this role pays about $206k versus about $163k for comparable roles.

Based on 240 similar postings.

Employer

About Elastic

Elastic is the company behind Elasticsearch and the Elastic Stack (Elasticsearch, Kibana, Beats, and Logstash). It sells search, observability, and security products built on that search engine, primarily through its Elastic Cloud managed service.

Elastic currently has 256 open roles on FindRole.

Listed pay typically runs $133,100–$204,000 across 91 roles with salary data.

Most-posted roles

View all roles at Elastic

At a glance

TL;DR · Principal Security Compliance Analyst, Public Sector, InfoSec

As a Principal Security Compliance Analyst, you will join the InfoSec team to lead the management of the FedRAMP Moderate program. You will be responsible for managing the authorization and continuous monitoring program while maintaining critical documentation including System Security Plans, policies, procedures, evidence, inventories, and diagrams. Your daily work involves coordinating assessments with 3PAO partners, federal agencies, consultants, and internal teams to track security findings and POA&M items through remediation. You will collaborate with Engineering, IT, Product, and Legal teams to implement required controls and monitor compliance metrics for leadership. The role requires expertise in FedRAMP, NIST SP 800-53, vulnerability management, and security assessments. This position addresses the specific challenge of maintaining federal compliance standards within a cloud-based search and security platform environment while ensuring all systems meet Department of Defense Impact Level 4 requirements.

What you'll do

  • Manage the FedRAMP Moderate authorization and continuous monitoring program.
  • Maintain System Security Plans, policies, procedures, evidence, inventories, and diagrams.
  • Coordinate assessments and reviews with 3PAOs, federal agency partners, consultants, and internal teams.
  • Track security findings and POA&M items through successful remediation.
  • Collaborate with Engineering, IT, Product, and Legal teams to implement required controls.
  • Monitor program deadlines, risks, and compliance metrics for leadership reporting.
  • Review system and product changes to determine potential FedRAMP impacts.
  • Guide control owners on their responsibilities and the preparation of evidence.

What we're looking for

  • 5+ years of experience managing or supporting a FedRAMP Moderate program.
  • Strong understanding of FedRAMP, NIST SP 800-53, and continuous monitoring requirements.
  • Experience with SSPs, POA&Ms, control evidence, vulnerability management, and security assessments.
  • Strong project management and organizational skills.
  • Ability to communicate effectively with technical teams, auditors, government stakeholders, and leadership.
  • Eligible to work in Department of Defense (DoD) Impact Level 4 or above cloud service environments.
  • Export controls.

More like this

Similar roles

Federal Compliance & Security Architect

Salesforce

Remote (Chicago, IL) +2 3 days ago $218,400$365,200
FedRAMP AWS) GovCloud Microsoft Azure Government NIST SP 800-37 FIPS) 140-2/140-3 Cloud Architecture Security Architecture Continuous Monitoring System Security Plans CISSP CCSP CISM
10+ yrs exp Remote

Senior Information Security Manager

Fortinet

Sunnyvale, CA 30 days ago $166,500$203,500
ISO/IEC 27001 NIST SP800-53 FedRAMP GovRAMP PCI DSS SOC2 GDPR CCPA HIPAA AWS Azure GCP Linux Windows VMWare MySQL MSSQL SIEM Vulnerability Management Cryptography Fortinet Products
7+ yrs exp

Senior Information Security Compliance Analyst

Warner Bros. Discovery

Atlanta, GA 6 days ago $89,390$166,010
PCI QSA AWS Azure GCP GRC SSAE 18 SOX Swift Data Privacy Tableau Power BI Audit Cybersecurity Compliance Information Security Control Testing ASV Scanning
4+ yrs exp Hybrid

Information Security Analyst Principal

General Dynamics

Remote 11 days ago $97,968$132,250
NIST 800-53 FIPS 199 FIPS 200 Zero Trust SBOM SDLC Agile fire-wall Source Code Control VistA RPMS Information Security Data Security
10+ yrs exp Remote

Senior Cybersecurity Analyst, OT Compliance

Marathon Petroleum

Findlay, OH +2 8 days ago $106,900$184,300
OT Cybersecurity Risk Management SIEM Vulnerability Management Penetration Testing Identity Access Management Security Governance Threat Hunting Forensics Web Application Scanning Asset Inventory Information Technology Operational Technology
5+ yrs exp