Please mention DailyRemote when applying
In today’s dynamic environment, business leaders face constantly shifting risks. Riveron helps organizations implement leading governance, risk and compliance practices by combining deep expertise with pragmatic partnership, using a hands-on approach to understand the specific needs of the organization and create tailored solutions to address key compliance risks.
Our Cyber Security Advisory (CSA) services include building GRC/Cybersecurity programs from the ground up, framework readiness, design and maintenance of critical security domains, managed internal controls testing and monitoring, co-sourced/outsourced internal audit, segregation of duties and access risk review, policy and procedure development, enterprise risk management, and IT and cybersecurity risk assessment.
The Manager level position for Riveron’s CSA group will work collaboratively with senior team members and provide guidance, coaching, and direction. Managers are expected to conduct the majority of day-to-day project management activities on all of their engagements, including project plan development, reviewing staff work for quality, status updates to clients and mentoring Senior Associates and Associates.
In this role, you will own complex FedRAMP and CMMC initiatives end-to-end—guiding clients from readiness through authorization by designing, implementing, and validating secure cloud architectures across AWS, Azure, and GCP. You’ll operate as a trusted technical advisor, translating federal and DoD security requirements into practical, scalable solutions. This is a hands-on consulting role for senior practitioners who want real ownership, deep technical work, and visible impact.
What You Have:
Bachelor's and/or Master’s degree in Information Technology (IT), Computer Information Systems (CIS), Management Information Systems (MIS), or a related field
5+ years of deep, demonstrable experience in FedRAMP and/or CMMC compliance efforts in real-world environments
Deep understanding of NIST 800-53 and NIST 800-171 control frameworks
Demonstrated knowledge of other compliance frameworks such as SOC 2, ISO 27001, HIPAA, PCI-DSS
Relevant certification preferred, such as CISA, CISM, CISSP or AWS Cloud Practitioner
Familiarity with GRC solutions, tools, and technologies
Who You Are:
You have a passion for developing and maintaining client relationships
You get the job done and have fun doing it
You communicate skillfully with a variety of audiences and can create compelling stories from data
You thrive in an ever-changing, dynamic work environment
You readily identify problems and instinctively look for solutions
You enjoy participating in internal and external company initiatives such as community service, training, recruiting, and firm events
What You’ll Do:
Lead FedRAMP Moderate and CMMC readiness assessments, including system boundary validation and control gap analysis
Design and implement cloud security architectures aligned to NIST 800-53 and NIST 800-171 requirements
Develop and own System Security Plans (SSPs), control narratives, and compliance documentation
Partner closely with client engineering, security, and compliance teams to remediate gaps and implement controls
Drive implementation of technical security measures such as encryption, IAM, logging, continuous monitoring, vulnerability management, and incident response
Advise clients on federal and DoD security mandates, including cryptographic requirements and vulnerability remediation timelines
Update and align security policies and procedures to support FedRAMP and CMMC compliance
Conduct preliminary control testing to validate effectiveness prior to formal assessments
Coordinate with Third-Party Assessment Organizations (3PAOs) and C3PAOs during independent assessments
Support assessment execution, evidence collection, remediation cycles, and authorization package submission
Mentor and review work from other consultants, raising the bar on technical quality and delivery
Conduct interviews with prospective team members, assessing candidate suitability while serving as a brand ambassador for the CSA practice and Riveron
Stay current on emerging risks and evolving control practices
Build and maintain strong industry relationships to support long-term business development
About Riveron:
At Riveron, we partner with clients—from global multinationals to high-growth private entities—to solve complex finance challenges, guided by our DELTA values: Drive, Excellence, Leadership, Teamwork, and Accountability. Our entrepreneurial culture thrives on collaboration, diverse perspectives, and delivering exceptional outcomes. We are committed to fostering growth, both for our clients and our people, through mentorship, integrity, and a client-centric approach. This inclusive environment offers flexibility, progressive benefits, and meaningful opportunities for impactful work that supports well-being in and out of the office.
Check us out on social media:
LinkedIn Glassdoor Instagram Facebook
Riveron Consulting is an Equal Opportunity Employer and believes that we are stronger together through our diversity. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, national origin, disability status, protected veteran status, sexual orientation, gender identity or any other characteristic protected by law.
Full time roles are eligible for a full range of benefits including medical, dental, and vision insurance, 401(k) with company match, and PTO. A complete description of all available benefits can be found at Riveron's Benefits page at https://riveron.com/riveron-life/. Contract roles are not eligible for benefits.
Please beware of fraudulent schemes or impersonations when going through the job application process. A Riveron employee will never recruit via text or extend unsolicited employment offers. Additionally, a Riveron employee will never ask you to exchange money or purchase anything as part of the recruiting process.
Stop the endless job search. Our AI finds and applies to the best jobs for you.
Discover remote opportunities in Software Development
Answer easy questions
200,000+ jobs across 15+ categories
Get your best job matches
Only hand-screened, legit jobs
Find a remote job faster
No ads, scams, or junk
“ I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!