Senior Federal IT Auditor

Senior Federal IT Auditor

Full-Time 51750 - 63250 £ / year (est.) Home office (partial)
T

At a Glance

  • Tasks: Support cloud compliance by developing authorization packages and monitoring controls.
  • Company: Join Tanium, a leader in Autonomous IT with a collaborative culture.
  • Benefits: Enjoy competitive salary, equity awards, health benefits, and flexible work options.
  • Other info: Diverse and inclusive environment with excellent career growth opportunities.
  • Why this job: Make a real impact on federal IT security while working with cutting-edge technology.
  • Qualifications: 5+ years in IT security and hands-on FedRAMP experience required.

The predicted salary is between 51750 - 63250 £ per year.

The ideal candidate has solid, hands-on experience with FedRAMP compliance processes and federal risk management frameworks, including exposure to FedRAMP High and DoD Impact Level (IL4/IL5) environments. This role supports the organization's cloud authorization activities by contributing to authorization package development, continuous monitoring, and control implementation efforts. Working under the direction of Senior GRC members, it partners closely with engineering, security, and product teams to ensure Tanium's cloud offerings meet and maintain federal compliance requirements across civilian and defense environments.

This is a hybrid position, which will require in-person attendance several days each week in one of the following locations: Addison, TX; Bellevue, WA; Durham, NC; Emeryville, CA; or Reston, VA.

What You'll Do

  • Contribute to authorization package documentation (SSPs, POA&Ms, SAPs), with attention to FedRAMP High baseline requirements.
  • Coordinate with 3PAOs and federal agency sponsors on scheduling, evidence collection, and artifact prep for FedRAMP and DoD IL4/IL5 assessments; respond to assessor inquiries.
  • Implement and document NIST SP 800-53 controls, validating effectiveness and gathering evidence across FedRAMP Moderate, High, and DoD IL4/IL5 boundaries.
  • Execute continuous monitoring: monthly vulnerability scanning reviews, POA&M tracking, and deliverables for sponsoring agencies and DoD stakeholders, including annual assessment support.
  • Assess system architectures with cloud/infrastructure teams to identify compliance gaps, and conduct gap analyses/readiness assessments ahead of 3PAO assessments.
  • Develop and improve FedRAMP policies, procedures, control implementation descriptions, and internal documentation standards, aligned with PMO and DoD SRG guidance.
  • Review and respond to federal customer security questionnaires and due diligence requests.
  • Prepare compliance status summaries, POA&M updates, and control assessment findings for senior leadership.
  • Monitor FedRAMP PMO, NIST, and DoD SRG updates and federal cybersecurity directives, flagging relevant changes to the GRC team.
  • Participate in cross-functional projects integrating FedRAMP High and DoD IL4/IL5 requirements into product development.
  • Working knowledge of NIST SP 800-53 (Rev 4/5) High baseline controls and their practical application in cloud environments.

You Should be Knowledgeable In:

  • Familiarity with the DoD Cloud Computing SRG and IL2/IL4/IL5 requirements and how they relate to FedRAMP.
  • Experience contributing to authorization artifacts (SSP, SAP, SAR, POA&M, ConMon deliverables).
  • Familiarity with adjacent frameworks: FedRAMP, FISMA, NIST SP 800-53, NIST SP 800-37 (RMF), NIST SP 800-171, GovRAMP, CMMC, NIST CSF.
  • Experience with cloud/SaaS environments, particularly AWS GovCloud, Azure Government, or other IL-accredited platforms.

We're Looking for Someone With Experience

  • 5+ years in information security, compliance, or risk management, with federal program exposure.
  • 5+ years of hands-on FedRAMP experience (CSP compliance, 3PAO assessment support, or federal agency ISSO activities); FedRAMP and DoD IL2 (IL4/IL5 preferred).
  • Strong written and verbal communication skills across technical and non-technical audiences; experience producing audit findings, policies, and compliance reports.
  • Certifications preferred: CISSP, CISA, CAP, Security+, or equivalent.

About Tanium

Tanium is the Autonomous IT company. Driven by AI and real-time endpoint intelligence, Tanium Autonomous IT empowers IT and security teams to make their organizations unstoppable. Many of the world's leading organizations trust Tanium’s single, unified platform for endpoint management and security to innovate faster, stay resilient and move business forward with confidence, at scale.

At Tanium, we are stewards of a culture that emphasizes the importance of collaboration, respect, and diversity. In our pursuit of revolutionizing the way some of the largest enterprises and governments in the world solve their most difficult IT challenges, we are strengthened by our unique perspectives and by our collective actions. We strive to create a diverse and inclusive environment where everyone feels they have opportunities to succeed and grow because we know that only together can we do great things.

Our commitment to excellence and innovation has earned us a place on the Forbes Cloud 100 list for ten consecutive years, and we continue to be recognized worldwide as a great place to work.

Each of our team members has 5 days set aside as volunteer time off (VTO) to contribute to the communities they live in and give back to the causes they care about most.

What you’ll get

  • The annual base salary range for this full-time position is $100,000 to $155,000. This range is an estimate for what Tanium will pay a new hire. The actual annual base salary offered may be adjusted based on a variety of factors, including but not limited to, location, education, skills, training, and experience.
  • Equity awards.
  • Medical, dental and vision plan.
  • Family planning benefits.
  • Health savings account.
  • Flexible spending account.
  • Transportation savings account.
  • 401(k) retirement savings plan with company match.
  • Life, accident and disability coverage.
  • Business travel accident insurance.
  • Employee assistance programs.
  • Disability insurance.
  • Other well-being benefits.

Tanium is an Equal Opportunity and Affiliation employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, gender identity, sexual orientation, disability, protected Veteran status, or other legally protected categories.

Senior Federal IT Auditor employer: Tanium

Tanium is an exceptional employer that fosters a collaborative and inclusive work culture, making it an ideal place for a Product Manager to thrive. With a strong commitment to employee growth, team members benefit from generous volunteer time off, competitive salaries, and a comprehensive benefits package, all while working in a dynamic hybrid environment that encourages innovation and creativity. Located in a vibrant area, Tanium not only values diversity but also empowers its employees to make a meaningful impact in the tech industry and their communities.

T

Contact Details:

Tanium Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Senior Federal IT Auditor

Join the IT Consultancy Buzz

Get involved in local or virtual IT consultancy meetups and forums. This is where we can rub shoulders with industry professionals, get insights into what Tanium values, and even spot unadvertised opportunities. Don't miss out on these chances to make a name for ourselves in the IT world!

Show Off Your Skills

Create a personal project or case study relevant to the challenges Tanium might face. Use platforms like GitHub or Medium to share your findings. This not only demonstrates our consulting skills but shows a proactive attitude, making us stand out from the crowd when applying for that full-time gig.

Leverage LinkedIn for Connections

Follow and engage with the relevant thought leaders and influencers in IT consultancy on LinkedIn. Share insightful content and join discussions to gain visibility. A well-placed comment or shared article could catch the attention of someone at Tanium!

Direct Apply to Tanium

Let's not forget to apply directly through the Tanium website! Tailor your application to showcase our understanding of their consulting style and how we can contribute to their projects. A personalised approach can make a huge difference in landing that full-time position!

We think you need these skills to ace Senior Federal IT Auditor

FedRAMP Compliance
Federal Risk Management Frameworks
NIST SP 800-53
Cloud Authorization Activities
Continuous Monitoring
Control Implementation
Documentation Skills

Some tips for your application 🫡

Showcase Your Problem-Solving Skills:In IT consulting, it's all about problem-solving, so make sure your CV highlights your analytical skills and any relevant projects you've tackled. Mention specific technologies or methodologies you've used to resolve issues or improve processes; this shows you can think critically and deliver results, which is vital for us at Tanium.

Highlight Relevant Certifications:Certifications like ITIL, PMP, or even specific tech stack qualifications can really make you stand out. Make sure to include these in your CV, as they not only demonstrate your expertise but also your commitment to staying current in the field. We love seeing candidates who are proactive about their professional development!

Tailor Your Cover Letter:Your cover letter is your chance to connect personally with us at Tanium. Share stories about your experiences in IT consulting, and how they shaped your desire to join our team. Mention why you’re excited about this particular role, and how you see yourself contributing to our projects.

Keep It Clear and Concise:We're all busy, so make sure your application is easy to read. Use bullet points for key achievements, and don’t overload us with jargon. A clean, professional layout goes a long way. Remember, the clearer your application, the more likely we are to invite you in for an interview!

How to prepare for a job interview at Tanium

Brush Up on Your Technical Skills

For an IT consulting role, be ready to demonstrate your technical prowess. You might face questions on systems integration, cloud technologies, or even troubleshooting specific software. If you have experience with tools like AWS, Azure, or even specific programming languages, make sure you can talk about them fluently.

Showcase Your Problem-Solving Approach

IT consulting is all about solving problems for clients. Think about how you can illustrate your approach to a past challenge using the STAR method (Situation, Task, Action, Result). It's a great way to show how you tackle complex issues and come up with effective solutions.

Know the Business Impact of IT Solutions

When discussing your experiences, focus not just on the tech solutions you implemented, but also on their business impact. Employers want to see that you can connect IT with organisational goals. Prep examples that highlight how your tech contributions improved efficiency or reduced costs for past clients or projects.

Prepare for Behavioural Questions

Since IT consulting often involves teamwork and client interactions, expect behavioural questions that assess your interpersonal skills. Be prepared with examples that demonstrate your adaptability, communication skills, and how you handle client feedback. Before the interview, think of situations where you worked closely with clients to create effective IT strategies or changes.