Cyber Security - Manager (FedRAMP)
Riveron
$117,500–$166,250
Jul 20, 2026
—
Jul 22, 2026
What this job asks for AI summary
A consulting manager role focused on federal cloud security compliance, primarily FedRAMP and CMMC engagements. Day-to-day work involves leading readiness assessments, designing cloud security architectures across major platforms, authoring System Security Plans, coordinating with third-party assessors, and remediating control gaps for clients. The role also carries project management and mentoring responsibilities across a team of junior consultants. Best suited to experienced practitioners with hands-on NIST framework and cloud compliance backgrounds.
Senior level · 5+ years · Bachelor's required · Full-time
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Rare in this occupation — lead with these, and say what you built with them.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $132,021 (middle half $99,961–$167,095).
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (8)
No work location is specified in the posting; the role appears to be a consulting position that may involve client-site travel. Remote status is marked false as no remote option is stated.
The title is 'Manager' in Riveron's internal hierarchy, but the role is a hands-on individual-contributor consulting engagement (no people-management budget/headcount ownership described); seniority is assessed as Senior based on 5+ years of required experience and end-to-end project ownership.
AWS, Azure, and GCP are all named together as the cloud platforms the role works across; they are listed as separate required skills rather than alternatives, since the JD implies working across all three.
SOC 2, ISO 27001, HIPAA, and PCI-DSS appear under the 'What You Have' (requirements) section as 'demonstrated knowledge of other compliance frameworks' — treated as hard gates despite the 'such as' qualifier, which signals interchangeability of specific frameworks rather than optionality of the requirement itself.
Certifications (CISA, CISM, CISSP, AWS Cloud Practitioner) are explicitly listed as 'preferred' and are marked accordingly.
GRC tools/solutions are listed under 'What You Have' but framed as 'familiarity with' — a softer qualifier — so marked as preferred.
The degree requirement states 'Bachelor's and/or Master's' with no 'or equivalent experience' escape clause; minimum is set to Bachelor's.
No compensation figures are provided in the posting.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.