Full-Time

Sr. Manager

Information Security Public Compliance

Posted on 4/21/2025

Crowdstrike

Crowdstrike

10,001+ employees

Cloud-native endpoint security solutions provider

Compensation Overview

$135k - $225k/yr

+ Variable Compensation + Equity

Expert

Company Historically Provides H1B Sponsorship

Remote in USA

US Top Secret Clearance Required

Category
Cybersecurity
IT & Security
Required Skills
Microsoft Azure
Operating Systems
AWS
Google Cloud Platform
Requirements
  • 12+ years of experience in information security, governance, risk, and compliance (GRC) with a focus on cloud security and public-sector regulatory frameworks.
  • Deep expertise in government compliance programs, including FedRAMP Moderate & High, StateRAMP, CMMC (Levels 2 & 3), DoD SRG IL4/IL5, ISMAP (Japan), IRAP (Australia), and other international security frameworks.
  • Strong knowledge of NIST 800-53, RMF, DFARS, FISMA, ISO 27001, SOC 2, and cloud security best practices.
  • Experience leading compliance assessments, managing third-party audits, and achieving security certifications for cloud environments.
  • Ability to effectively engage with U.S. government agencies, AOs, and compliance assessors to drive compliance approvals.
  • Hands-on experience with security documentation, including SSPs, POA&Ms, control matrices, and compliance automation tools.
  • Strong leadership and collaboration skills, with the ability to work across teams, regions, and organizational levels.
  • Excellent communication and stakeholder management skills, including experience briefing executives and government entities on compliance status and security risks.
  • Technical understanding of cloud security architectures, operating systems, networks, and application security in cloud environments (AWS, Azure, GCP).
  • Project management experience, including scoping, risk assessment, resource planning, and compliance reporting.
Responsibilities
  • Lead and manage compliance initiatives for CrowdStrike GovCloud environments, ensuring adherence to FedRAMP, DoD SRG IL4/IL5, StateRAMP, CMMC, and international frameworks (ISMAP, IRAP, etc.).
  • Drive certification efforts by managing internal and external audits, risk assessments, and security documentation submissions.
  • Develop and maintain compliance strategies that align with federal and international security mandates, working closely with engineering, security, and legal teams.
  • Oversee the implementation of controls based on NIST 800-53, RMF, CMMC, and DoD SRG standards, ensuring continuous monitoring and compliance readiness.
  • Serve as a subject matter expert (SME) on public-sector security compliance, providing guidance to internal teams and engaging with government agencies, assessors, and third-party auditors.
  • Manage relationships with regulatory bodies and compliance assessors, advocating for compliance best practices while ensuring business agility.
  • Maintain and enhance security compliance documentation, including System Security Plans (SSPs), policies, procedures, and risk assessments.
  • Support customers and Authorizing Officials (AO) by providing necessary compliance documentation and guidance for their security evaluations.
  • Stay ahead of evolving regulatory landscapes, interpreting new policies and their impact on cloud security compliance.
  • Drive continuous improvement by identifying areas for automation, efficiency, and optimization in security compliance processes.
  • Other responsibilities as requested by leadership.
Desired Qualifications
  • Experience in system engineering or security operations supporting government compliance programs.
  • Familiarity with CrowdStrike’s products and cloud security services.
  • Security certifications such as CISSP, CISM, CISA, CCSP, or relevant compliance certifications (e.g., Certified CMMC Assessor, FedRAMP Certified Assessor).

CrowdStrike specializes in cybersecurity, focusing on protecting businesses from cyber threats through cloud-native endpoint security solutions. Their main product, the Falcon platform, includes services like Falcon Pro, which replaces traditional antivirus with next-generation antivirus that integrates threat intelligence for immediate threat responses; Falcon Insight, which offers endpoint detection and response to help detect and investigate security incidents; and Falcon Device Control, which manages devices connected to the network to prevent unauthorized access. CrowdStrike serves a diverse clientele, including many Fortune 100 companies, and operates on a subscription-based model, allowing clients to choose different service levels based on their needs. The company is recognized as a leader in the cybersecurity industry, noted for its effectiveness in endpoint security and threat detection.

Company Size

10,001+

Company Stage

IPO

Headquarters

Austin, Texas

Founded

2011

Simplify Jobs

Simplify's Take

What believers are saying

  • CrowdStrike's recognition in Gartner's 2025 report enhances its market reputation and customer trust.
  • The cybersecurity market's projected 12.9% CAGR until 2030 favors CrowdStrike's growth potential.
  • AI-driven solutions like agentic AI reduce security operation times, boosting CrowdStrike's appeal.

What critics are saying

  • Rapid AI adoption increases attack surfaces, challenging CrowdStrike to keep up with evolving threats.
  • Recent layoffs of 5% of workforce may impact CrowdStrike's operational capacity.
  • Intense competition from firms like Palo Alto Networks could affect CrowdStrike's market share.

What makes Crowdstrike unique

  • CrowdStrike's Falcon platform offers cloud-native endpoint security solutions, setting it apart from competitors.
  • The company serves 44 of the Fortune 100, showcasing its strong market presence.
  • CrowdStrike's proactive threat hunting differentiates it by actively searching for potential threats.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Competitive Employee Stock Purchase Plan

Remote-friendly culture

Market leader in compensation and equity awards

Competitive vacation and flexible working arrangements

Comprehensive health benefits + 401k plan

Paid Parental Leave, including adoption

Wellness programs

Professional development and mentorship opportunities

Open offices have stocked kitchens, coffee, soda and treats

Growth & Insights and Company News

Headcount

6 month growth

1%

1 year growth

3%

2 year growth

0%
VentureBeat
Jun 11th, 2025
‘Generative Ai Helps Us Bend Time’: Crowdstrike, Nvidia Embed Real-Time Llm Defense, Changing How Enterprises Secure Ai

Join the event trusted by enterprise leaders for nearly two decades. VB Transform brings together the people building real enterprise AI strategy. Learn more. Generative AI adoption has surged by 187% over the past two years. But at the same time, enterprise security investments focused specifically on AI risks have grown by only 43%, creating a significant gap in preparedness as AI attack surfaces rapidly expand.More than 70% of enterprises experienced at least one AI-related breach in the past year alone, with generative models now the primary target, according to recent SANS Institute findings. State-sponsored attacks on AI infrastructure have spiked a staggering 218% year-over-year, as CrowdStrike’s 2025 Global Threat Report reveals.For CISOs, security and SOC leaders, the harsh reality is apparent. Deploying new AI models at scale exponentially expands their enterprises’ attack surfaces, and CISOs speaking on condition of anonymity have told VentureBeat traditional security tactics, strategies and technologies are challenged to keep pace

Massive News
Jun 5th, 2025
CrowdStrike Named a Customers' Choice in 2025 Gartner(R) Peer Insights(TM) Voice of the Customer for User Authentication Report

CrowdStrike named a Customers' Choice in 2025 gartner(r) Peer Insights(TM) Voice of the Customer for User Authentication report.

Financial Modeling Prep
Jun 2nd, 2025
CrowdStrike (NASDAQ: CRWD) Maintains "Buy" Rating Amidst Cybersecurity Enhancements

CrowdStrike competes with other cybersecurity firms like Palo Alto Networks and FireEye.

Massive News
May 31st, 2025
CrowdStrike Named a Frost Radar(TM) Leader in Cloud and Application Runtime Security

CrowdStrike named a Frost Radar(TM) leader in Cloud and Application Runtime Security.

VentureBeat
May 29th, 2025
Danabot Takedown Shows How Agentic Ai Cut Months Of Soc Analysis To Weeks

Join our daily and weekly newsletters for the latest updates and exclusive content on industry-leading AI coverage. Learn More. The recent takedown of DanaBot, a Russian malware platform responsible for infecting over 300,000 systems and causing more than $50 million in damage, highlights how agentic AI is redefining cybersecurity operations. According to a recent Lumen Technologies post, DanaBot actively maintained an average of 150 active C2 servers per day, with roughly 1,000 daily victims across more than 40 countries. Last week, the U.S. Department of Justice unsealed a federal indictment in Los Angeles against 16 defendants of DanaBot, a Russia-based malware-as-a-service (MaaS) operation responsible for orchestrating massive fraud schemes, enabling ransomware attacks and inflicting tens of millions of dollars in financial losses to victims

INACTIVE