# Program Architect

**Company:** [Onebrief](https://hotfix.jobs/companies/onebrief)
**Location:** Remote
**Role:** Security Engineering
**Salary:** $160k – $200k/yr
**Experience:** 5+ years
**Skills:** GRC, FedRAMP, cmmc, rmf, SOC 2, nist 800-53, nist 800-171, IAM, cissp, cisa, crisc, aws solutions architect, Infrastructure As Code
**Posted:** 2026-07-29

> Own the architecture and implementation of Onebrief's GRC framework for defense/government compliance (FedRAMP, CMMC, RMF, SOC 2). Translate regulatory requirements into technical security controls in close partnership with engineering teams.

## Job Description

## What You’ll Do

- Own the design and implementation of Onebrief's GRC framework across RMF, FedRAMP, CMMC, SOC 2, and other applicable standards.
- Build and manage the control environment, including policies, procedures, and evidence collection systems.
- Design and implement technical security controls in partnership with Product, Engineering, Infrastructure and Corporate IT including access management, logging, encryption, and vulnerability management practices.
- Partner with Engineering, Infrastructure, and Corporate IT to translate compliance requirements into working technical controls, not just documented ones.

## Minimum Qualifications

- 5+ years of experience in GRC, security engineering, or a combined compliance and technical security role
- Direct experience with RMF, FedRAMP, CMMC, or equivalent federal compliance frameworks
- Hands-on experience implementing technical security controls, such as IAM, logging and monitoring, network segmentation, or encryption
- Working knowledge of security control frameworks such as NIST 800-53 or NIST 800-171
- Experience managing third-party audits and assessor relationships
- Strong written communication skills, with the ability to translate regulatory language into clear technical and internal guidance

## Preferred Qualifications

- Experience in a startup or scaling company environment
- Background in military, defense, or government contracting
- Relevant certifications, such as CISSP, CISA, CRISC, or a technical security certification (AWS Solutions Architect)
- Experience building GRC automation using infrastructure-as-code or scripting

## Indicators of Success

- Identify and remediate at least one significant security control gap before it surfaces in an external audit
- Serve as the trusted point of contact for customer security questionnaires and compliance inquiries
- Be recognized by engineering and security teams as a partner who makes compliance workable and technically sound, not just another gate to pass
- Win buy-in from engineering leads who previously treated compliance requests as low priority
- Get through a customer or third-party security review without escalations or fire drills

## Tools, Systems & Technologies

- GRC platforms (such as RegScale, eMASS, or similar)
- Cloud security tooling relevant to Federal environments
- Logging systems
- CI/CD pipelines
- Infrastructure-as-code for control automation

## Similar roles

- [Security Engineer](https://hotfix.jobs/jobs/be1ae539-4e2e-462f-aedd-c2ac34023a86) - Skydio - San Mateo, CA - $160k – $210k/yr
- [Software Engineer - Secret, Cryptographic and Identity Infrastructure](https://hotfix.jobs/jobs/a918f997-7c56-44bb-9b30-9a92afad2937) - Snowflake - Bellevue, WA - $160k – $230k/yr
- [Software Engineer - Trust Center](https://hotfix.jobs/jobs/eca646e8-2ac5-42be-8887-68e227b5b842) - Snowflake - Bellevue, WA - $160k – $230k/yr
- [Security Engineer](https://hotfix.jobs/jobs/3e8573ef-e06e-4e0e-907b-299b0e307a11) - Juicebox - San Francisco, CA - $160k – $250k/yr
- [Security Infrastructure Engineer](https://hotfix.jobs/jobs/1fb7499e-0f95-40d3-bc9b-28f07610453e) - PointOne - New York, NY - $160k – $220k/yr

**Apply:** https://hotfix.jobs/jobs/5384a590-015f-4993-b8ab-c3265b23c189
**Canonical:** https://hotfix.jobs/jobs/5384a590-015f-4993-b8ab-c3265b23c189