Description
Merlin Group is hiring an Information System Security Manager to own FedRAMP authorization compliance and continuous monitoring for cloud environments. The role coordinates access authorization, vulnerability scanning, POA&M remediation, change control, compliance calendars, SBOM submissions, security training, and program updates, while communicating requirements to customers and reporting risks to leadership. Candidates need at least five years of ISSM experience with cloud service providers in FedRAMP environments, hands-on knowledge of FedRAMP Rev 5, 20x, and CR26 requirements, and experience with vulnerability management, POA&M, and change control. The position offers medical, dental, and vision insurance, a 401(k) match, unlimited PTO, and other wellness and retirement benefits.
