# Senior Federal IT Auditor at Tanium

- Company: Tanium
- What the company does: Tanium is a unified endpoint management and security platform: agentic AI for real-time visibility, patching, and risk remediation across endpoints. Backed by a16z and IVP.
- Company website: https://www.tanium.com
- Type: Startups
- Level: Senior
- Location: Addison, TX (Hybrid); Bellevue, WA (Hybrid); Durham, NC (Hybrid); Emeryville, CA (Hybrid); Remote, US; Reston, VA...
- Work setup: Remote
- Pay: $131K to $201K base salary per year (USD)
- Posted: 2026-08-13
- Apply by: 2026-10-08
- Apply: https://job-boards.greenhouse.io/tanium/jobs/8126966
- Page: https://www.1752.vc/careers/jobs/tanium-senior-federal-it-auditor/

## About the role

The ideal candidate has solid, hands-on experience with FedRAMP compliance processes and federal risk management frameworks, including exposure to FedRAMP High and DoD Impact Level (IL4/IL5) environments. This role supports the organization's cloud authorization activities by contributing to authorization package development, continuous monitoring, and control implementation efforts.

## What they're looking for

- Contribute to authorization package documentation (SSPs, POA&Ms, SAPs), with attention to FedRAMP High baseline requirements
- Coordinate with 3PAOs and federal agency sponsors on scheduling, evidence collection, and artifact prep for FedRAMP and DoD IL4/IL5 assessments, respond to assessor inquiries
- Implement and document NIST SP 800-53 controls, validating effectiveness and gathering evidence across FedRAMP Moderate, High, and DoD IL4/IL5 boundaries
- Execute continuous monitoring: monthly vulnerability scanning reviews, POA&M tracking, and deliverables for sponsoring agencies and DoD stakeholders, including annual assessment support
- Assess system architectures with cloud/infrastructure teams to identify compliance gaps, and conduct gap analyses/readiness assessments ahead of 3PAO assessments
- Develop and improve FedRAMP policies, procedures, control implementation descriptions, and internal documentation standards, aligned with PMO and DoD SRG guidance

Tags: IT Security
