INTL
WWR
전문가
외주
원격 가능
Amwell: Manager, Government Compliance & Authorization
예상 기간
정규직 (장기)
난이도
전문가
기술 스택
NIST SP 800-53
FedRAMP
CMMC
NIST SP 800-171
MARS-E
StateRAMP
AI 분석 요약 기회점수 20/100
이 공고는 개발 외주 프로젝트가 아니라 Amwell(헬스케어 기업)의 정규직 채용 공고로, 정부 규제 준수 및 인증(Government Compliance & Authorization) 프로그램을 총괄하는 관리자(Manager) 역할을 뽑는 자리입니다. FedRAMP High 인증 획득 및 유지가 핵심이며 CMMC, CMS MARS-E, StateRAMP 등 미국 연방/주정부 컴플라이언스 프레임워크 정렬, 지속적 모니터링, 3PAO 협업, 인증 패키지(SSP, POA&M) 작성을 담당합니다. 소프트웨어 개발보다는 보안 거버넌스·컴플라이언스 전문성과 프로젝트 관리 역량을 갖춘 정보보안 관리자에게 적합합니다.
핵심 요구사항
- FedRAMP High 요구사항에 대한 깊은 전문성
- CMMC Level 2/3, CMS MARS-E 2.2, StateRAMP 컴플라이언스 정렬 경험
- NIST SP 800-53 Rev 5 통제항목 매핑 및 'comply once' 전략 수립
- 3PAO 협업 및 보안 평가·인증(SA&A) 관리
- 인증 패키지(SSP, POA&M, 지속 모니터링) 작성 및 유지
- 강력한 프로젝트 관리 및 부서 간 협업 능력
산출물
- FedRAMP 인증 패키지 (System Security Plan, POA&M)
- 지속적 모니터링 월간 산출물 및 취약점 관리 보고서
- 연방기관 대상 인시던트 리포팅 및 컴플라이언스 대응 문서
- 규제 프레임워크 통제 매핑 문서
매력 포인트
- 완전 원격 근무 (Remote US)
- 대형 헬스케어 기업의 안정적 정규직
주의사항
- 개발 외주가 아닌 정규직 채용 공고 (프리랜서 프로젝트 부적합)
- 카테고리가 'Full-Stack Programming'으로 잘못 분류됨
- 예산·기간·구체적 기술스택 정보 부재
프로젝트 유형장기계약
적합 개발자FedRAMP/NIST 전문성을 갖춘 정보보안 컴플라이언스 관리자 (개발자 아님)
프로젝트 원문 설명
Headquarters: Remote US
Company Description
At Amwell, we’re transforming healthcare for all—powered by technology and inspired by people. Here, your ideas don’t just matter—they drive real change, improving lives on a global scale.
We marry technology and innovation with clinical excellence to provide trusted solutions that solve the healthcare industry’s biggest pain points and are on a mission to enable greater access to more convenient, affordable, and effective care.
We do this through our technology-enabled care platform that is designed to help our clients achieve their digital care ambitions – today and in the future. We offer programs spanning the full care continuum, including urgent, acute and specialty care, behavioral health, and services for the treatment of chronic conditions such as heart and cardiometabolic diseases. Programs are powered by Amwell as well as our growing partner network.
For almost two decades, Amwell has proudly served some of the largest and most sophisticated healthcare organizations in the U.S. and worldwide. Our team is passionate about technology’s role in transforming care delivery and making it more equitable, accessible, efficient, cost-effective and navigable for all.
Brief Overview
The Manager of Government Compliance & Authorization will lead the strategy, implementation, and maintenance of Amwell’s federal and state authorization programs. While a primary focus remains achieving and sustaining FedRAMP High authorization, this leader will also architect the internal systems necessary to align with CMMC (Level 2/3), CMS MARS-E, and StateRAMP requirements. The Manager will mature Amwell’s government compliance program, oversee the authorization process, lead efforts to define resources and hire staff to support the program, manage continuous monitoring activities, and serve as the primary liaison with federal stakeholders and third-party assessment organizations (3PAOs). The ideal candidate will have deep expertise in FedRAMP High requirements, strong project management skills, and the ability to work cross-functionally to implement and maintain complex compliance frameworks.
Core Responsibilities
· Lead the end-to-end authorization process for FedRAMP High, while concurrently driving alignment with CMMC Level 2/3 for DoD contracts and MARS-E 2.2 for CMS/Medicaid engagements
· Manage ongoing FedRAMP continuous monitoring requirements, including monthly deliverables, vulnerability management, and incident reporting to federal agencies
· Collaborate with engineering, security, and operations teams to develop a "comply once, satisfy many" strategy by mapping NIST SP 800-53 Rev 5 controls to CMMC (NIST SP 800-171) and MARS-E requirements to minimize redundant engineering efforts
· Own risk management of services provided to federal agencies, ensuring compliance with High-impact baseline
· Coordinate with 3PAOs to manage security assessment and authorization (SA&A) activities, including annual assessments and significant change requests
· Develop and maintain FedRAMP authorization packages, including System Security Plans (SSP), Plans of Action and Milestones (POA&M), and Continuous Monitoring deliverables
· Serve as primary point of contact for federal agency customers regarding FedRAMP compliance questions and authorization boundary matters
· Monitor and interpret FedRAMP policy updates and guidance from the FedRAMP PMO, implementing necessary changes to maintain compliance
· Build and lead a team of compliance analysts and security specialists focused on federal authorization requirements
· Create and deliver training programs to ensure organizational awareness of FedRAMP requirements and responsibilities
· Manage relationships with federal authorizing officials, cloud service providers, and other stakeholders in the authorization process
Qualifications
· 7+ years of experience in information security, compliance, or risk management with at least 3 years specifically working with FedRAMP authorizations
· Demonstrated experience successfully achieving FedRAMP High authorization for a cloud service offering (CSO)
· Deep knowledge of NIST SP 800-53 Rev 5 security controls, FISMA, FedRAMP baselines, and federal security authorization processes
· Experience managing continuous monitoring activities and maintaining active FedRAMP ATOs
· 3+ years of people management experience, including hiring, developing, and leading compliance or security teams
· Strong understanding of cloud infrastructure security (AWS, Azure, or GCP) in FedRAMP environments
· Familiarity with healthcare compliance frameworks (HIPAA, HITRUST) and their intersection with federal requirements
· Proven project management skills with ability to coordinate complex, multi-stakeholder authorization efforts
· Experience working with 3PAOs and understanding of security assessment methodologies
· Excellent written and verbal communication skills with ability to translate technical security concepts for various audiences
· Relevant certifications such as CISSP, CISM, CAP, or FedRAMP-specific certifications preferred
· Bachelor's degree in Information Security, Computer Science, or related field required; Master's degree preferred
· Ability to obtain and maintain security clearance if required
Do Well. Live Well. At Amwell.
Driven by our mission and values, we foster a workplace where Delivering Awesome, being Customer First and operating as One Team aren’t just aspirations – they are how we work, every day.
Our people are our greatest asset. We strive to empower their growth and development not only as Amwellians but as individuals, through generous total rewards packages, a virtual-first work environment, work-life flexibility, including Summer Fridays and designated Mental Health Days, as well as opportunities to stretch and learn – to name a few. It’s our people who truly differentiate us. Ask anyone and they’ll tell you – you’ll never work with more passionate, more driven and more caring team members.
We champion a culture of respect and inclusion, accountability and integrity, innovation and collaboration. At Amwell, you’ll do the most meaningful work of your career—improving healthcare for millions, growing alongside incredible teammates, and being valued for who you are.
Benefits
- Flexible Personal Time Off (Vacation time)
- 401K match
- Competitive healthcare, dental and vision insurance plans
- Paid Parental Leave (Maternity and Paternity leave)
- Employee Stock Purchase Program
- Free access to Amwell’s Telehealth Services, SilverCloud and The Clinic by Cleveland Clinic’s second opinion program
- Free Subscription to the Calm App
- Tuition Assistance Program
- Pet Insurance
Salaried, Exempt Roles
The typical base salary range for this position is $126,180 - $154,220. The actual salary offer will ultimately depend on multiple factors including, but not limited to, knowledge, skills, relevant education, experience, complexity or specialization of talent, and other objective factors. In addition to base salary, this role may be eligible for an annual bonus based on a combination of company performance and employee performance. Long-term incentive and short-term variable compensation may be offered as part of the compensation package dependent on the role. Some roles may be commission based, in which case the total compensation will be based on a commission, and the above range may not be an accurate representation of total compensation.
Further, the above range is subject to change based on market demands and operational needs and does not constitute a promise of a particular wage or a guarantee of employment. Your recruiter can share more during the hiring process about the specific salary range based on the above factors listed.
https://business.amwell.com/company/privacy-notice-applicants
Privacy Notice
To apply: https://weworkremotely.com/remote-jobs/amwell-manager-g
Company Description
At Amwell, we’re transforming healthcare for all—powered by technology and inspired by people. Here, your ideas don’t just matter—they drive real change, improving lives on a global scale.
We marry technology and innovation with clinical excellence to provide trusted solutions that solve the healthcare industry’s biggest pain points and are on a mission to enable greater access to more convenient, affordable, and effective care.
We do this through our technology-enabled care platform that is designed to help our clients achieve their digital care ambitions – today and in the future. We offer programs spanning the full care continuum, including urgent, acute and specialty care, behavioral health, and services for the treatment of chronic conditions such as heart and cardiometabolic diseases. Programs are powered by Amwell as well as our growing partner network.
For almost two decades, Amwell has proudly served some of the largest and most sophisticated healthcare organizations in the U.S. and worldwide. Our team is passionate about technology’s role in transforming care delivery and making it more equitable, accessible, efficient, cost-effective and navigable for all.
Brief Overview
The Manager of Government Compliance & Authorization will lead the strategy, implementation, and maintenance of Amwell’s federal and state authorization programs. While a primary focus remains achieving and sustaining FedRAMP High authorization, this leader will also architect the internal systems necessary to align with CMMC (Level 2/3), CMS MARS-E, and StateRAMP requirements. The Manager will mature Amwell’s government compliance program, oversee the authorization process, lead efforts to define resources and hire staff to support the program, manage continuous monitoring activities, and serve as the primary liaison with federal stakeholders and third-party assessment organizations (3PAOs). The ideal candidate will have deep expertise in FedRAMP High requirements, strong project management skills, and the ability to work cross-functionally to implement and maintain complex compliance frameworks.
Core Responsibilities
· Lead the end-to-end authorization process for FedRAMP High, while concurrently driving alignment with CMMC Level 2/3 for DoD contracts and MARS-E 2.2 for CMS/Medicaid engagements
· Manage ongoing FedRAMP continuous monitoring requirements, including monthly deliverables, vulnerability management, and incident reporting to federal agencies
· Collaborate with engineering, security, and operations teams to develop a "comply once, satisfy many" strategy by mapping NIST SP 800-53 Rev 5 controls to CMMC (NIST SP 800-171) and MARS-E requirements to minimize redundant engineering efforts
· Own risk management of services provided to federal agencies, ensuring compliance with High-impact baseline
· Coordinate with 3PAOs to manage security assessment and authorization (SA&A) activities, including annual assessments and significant change requests
· Develop and maintain FedRAMP authorization packages, including System Security Plans (SSP), Plans of Action and Milestones (POA&M), and Continuous Monitoring deliverables
· Serve as primary point of contact for federal agency customers regarding FedRAMP compliance questions and authorization boundary matters
· Monitor and interpret FedRAMP policy updates and guidance from the FedRAMP PMO, implementing necessary changes to maintain compliance
· Build and lead a team of compliance analysts and security specialists focused on federal authorization requirements
· Create and deliver training programs to ensure organizational awareness of FedRAMP requirements and responsibilities
· Manage relationships with federal authorizing officials, cloud service providers, and other stakeholders in the authorization process
Qualifications
· 7+ years of experience in information security, compliance, or risk management with at least 3 years specifically working with FedRAMP authorizations
· Demonstrated experience successfully achieving FedRAMP High authorization for a cloud service offering (CSO)
· Deep knowledge of NIST SP 800-53 Rev 5 security controls, FISMA, FedRAMP baselines, and federal security authorization processes
· Experience managing continuous monitoring activities and maintaining active FedRAMP ATOs
· 3+ years of people management experience, including hiring, developing, and leading compliance or security teams
· Strong understanding of cloud infrastructure security (AWS, Azure, or GCP) in FedRAMP environments
· Familiarity with healthcare compliance frameworks (HIPAA, HITRUST) and their intersection with federal requirements
· Proven project management skills with ability to coordinate complex, multi-stakeholder authorization efforts
· Experience working with 3PAOs and understanding of security assessment methodologies
· Excellent written and verbal communication skills with ability to translate technical security concepts for various audiences
· Relevant certifications such as CISSP, CISM, CAP, or FedRAMP-specific certifications preferred
· Bachelor's degree in Information Security, Computer Science, or related field required; Master's degree preferred
· Ability to obtain and maintain security clearance if required
Do Well. Live Well. At Amwell.
Driven by our mission and values, we foster a workplace where Delivering Awesome, being Customer First and operating as One Team aren’t just aspirations – they are how we work, every day.
Our people are our greatest asset. We strive to empower their growth and development not only as Amwellians but as individuals, through generous total rewards packages, a virtual-first work environment, work-life flexibility, including Summer Fridays and designated Mental Health Days, as well as opportunities to stretch and learn – to name a few. It’s our people who truly differentiate us. Ask anyone and they’ll tell you – you’ll never work with more passionate, more driven and more caring team members.
We champion a culture of respect and inclusion, accountability and integrity, innovation and collaboration. At Amwell, you’ll do the most meaningful work of your career—improving healthcare for millions, growing alongside incredible teammates, and being valued for who you are.
Benefits
- Flexible Personal Time Off (Vacation time)
- 401K match
- Competitive healthcare, dental and vision insurance plans
- Paid Parental Leave (Maternity and Paternity leave)
- Employee Stock Purchase Program
- Free access to Amwell’s Telehealth Services, SilverCloud and The Clinic by Cleveland Clinic’s second opinion program
- Free Subscription to the Calm App
- Tuition Assistance Program
- Pet Insurance
Salaried, Exempt Roles
The typical base salary range for this position is $126,180 - $154,220. The actual salary offer will ultimately depend on multiple factors including, but not limited to, knowledge, skills, relevant education, experience, complexity or specialization of talent, and other objective factors. In addition to base salary, this role may be eligible for an annual bonus based on a combination of company performance and employee performance. Long-term incentive and short-term variable compensation may be offered as part of the compensation package dependent on the role. Some roles may be commission based, in which case the total compensation will be based on a commission, and the above range may not be an accurate representation of total compensation.
Further, the above range is subject to change based on market demands and operational needs and does not constitute a promise of a particular wage or a guarantee of employment. Your recruiter can share more during the hiring process about the specific salary range based on the above factors listed.
https://business.amwell.com/company/privacy-notice-applicants
Privacy Notice
To apply: https://weworkremotely.com/remote-jobs/amwell-manager-g
WWR에서 원본 확인
원본 보기