GRC Analyst - Public Sector
Owns hands-on GRC operations for the public-sector business, including FedRAMP/GovRAMP continuous monitoring, POA&M management, vulnerability remediation, audit readiness, and customer-facing compliance content. Requires 4+ years of cybersecurity or compliance experience and direct FedRAMP, GovRAMP, or comparable experience.
About the job
Responsibilities
- Coordinate third-party assessment organization (3PAO) assessments and respond to auditor evidence and documentation requests.
- Maintain FedRAMP and GovRAMP controls and documentation aligned with NIST SP 800-53 Rev. 5 and related frameworks.
- Prepare certification and authorization packages, including System Security Plans (SSPs) and appendices.
- Build and maintain POA&M, compliance trackers, procedures, and status-reporting artifacts.
- Replace manual evidence collection with system-generated, API-driven, or continuously validated evidence.
- Run FedRAMP continuous monitoring and vulnerability-management activities from identification through remediation and verification.
- Coordinate remediation with Security, Engineering, and DevOps teams using tools such as Wiz, Burp Suite, and AWS services.
- Coordinate access reviews, incident-response exercises, and contingency-plan testing.
- Design automated access-validation mechanisms and deliver FedRAMP training programs.
- Conduct internal reviews of logged events and control activities; escalate gaps and report trends, risks, and remediation progress.
- Develop automation-first, AI-enabled, and machine-readable compliance workflows, including OSCAL or comparable formats.
- Partner with engineering and automation teams to integrate compliance data into risk management, vulnerability remediation, access-request, and reporting systems.
- Support public-sector sales by translating controls and system capabilities into accurate, persuasive customer-facing narratives.
- Develop security certification communications, RFP/RFx response frameworks, answer libraries, and AI-assisted tools.
- Monitor regulatory and industry changes, perform gap analyses, and contribute input to standards bodies when applicable.
Required Qualifications
- 4+ years of hands-on cybersecurity, compliance, or identity-management experience, including personal execution of FedRAMP, GovRAMP, or comparable continuous-monitoring work.
- Direct experience with FedRAMP, GovRAMP, and NIST frameworks, including NIST 800-53, 800-63, and 800-171.
- Experience running scans, maintaining a POA&M, preparing deviation requests, conducting continuous monitoring, coordinating vulnerability remediation, and producing compliance reports.
- Ability to design and improve repeatable compliance processes and create structure where none exists.
- Strong written, verbal, organizational, and cross-functional collaboration skills.
- Ability to write persuasively for customer audiences and distinguish persuasive content from compliance-accurate content.
- Ability to adapt to changing requirements and manage multiple priorities.
- Demonstrated customer-facing experience and exposure to product or sales positioning.
- Must be a U.S. Person residing in the United States and able to obtain a U.S. OPM NACI clearance.
Preferred Qualifications
- Public-sector experience.
- Experience in regulated industries such as financial services or healthcare.
- Knowledge of GDPR, CCPA, and additional NIST standards.
- CISSP, CISM, CISA, or IAPP certification.
- Experience with OSCAL, machine-readable compliance formats, AI tools such as ChatGPT, Glean, or Gemini, and automation-first workflows.
- Hands-on contribution to FedRAMP, GovRAMP, or NIST 800-63/171 certification and compliance initiatives.
- Experience with continuous monitoring, vulnerability management, policy updates, audit coordination, and proactive process-gap remediation.
Skills
FedRAMP, Govramp, Nist Sp 800-53, Nist Sp 800-63, Nist Sp 800-171, Poa&M, Vulnerability Management, Continuous Monitoring, Oscal, Wiz, Burp Suite, AWS, Identity Management, AI Workflows, Rfp Responses
Similar jobs
Security Engineering jobsThe Security Engineer will secure AWS and Google Cloud environments, monitor infrastructure, and assess AI/LLM deployments, MCP integrations, and agentic workflows. The role requires 5+ years of security engineering experience, including 2+ years in AI/ML security, plus cloud security and compliance expertise.
The Security GRC Analyst will manage security risks, policies, audits, control testing, and compliance reporting while partnering with technical and business stakeholders. The role requires 4+ years of GRC or security assurance experience and familiarity with major security frameworks.
Own network engineering and government cybersecurity compliance for on-site and field-deployed aerospace systems. The role requires 5+ years of experience, end-to-end IATT/ATO experience, strong networking skills, and familiarity with DoD security frameworks and tactical communications.
Investigates and assesses physical security threats involving personnel, executives, events, travel, and operations. The role requires at least five years of relevant intelligence or threat-assessment experience, strong analytical communication, and familiarity with OSINT, behavioral threat methodologies, and technology-enabled investigations.
Owns application security by embedding review workflows in SDLC, building SAST/DAST pipelines in CI/CD, managing vulnerability remediation, and operating bug bounty programs. Requires 5+ years experience finding/fixing vulnerabilities, strong skills in Python/TypeScript/Go, and SAST/DAST tooling.