• Receive and evaluate deviation and risk acceptance requests; confirm CVSS scores, affected assets, and proposed compensating controls.
• Meet with engineers and developers to understand technical constraints, agree on remediation timelines, and document alternative solutions that satisfy FedRAMP Moderate or High requirements.
• Draft or refine risk acceptance forms and POA&M entries; shepherd each request through security, compliance, and Authorizing Official approval.
• Maintain an up to date exception register with owners, due dates, and re validation checkpoints; remind stakeholders as deadlines approach.
• Update vulnerability management runbooks, service level agreements, and playbooks to reflect the approved deviation handling process and any new tooling integrations.
• Help integrate scanners or ticketing systems such as Prisma Cloud, Tenable, Qualys, and Jira so deviation status is captured and tracked automatically.
• Advise engineering teams on FedRAMP control requirements, acceptable compensating controls, and best practices for patching or mitigating findings.
• Support audits by supplying requested evidence and context prepared by the compliance team.