# GRC Analyst - Public Sector

**Company:** [Socure](https://hotfix.jobs/companies/socure)
**Location:** Washington, DC
**Role:** Security Engineering
**Salary:** $120k – $145k/yr
**Experience:** 4+ years
**Skills:** FedRAMP, Govramp, Nist Sp 800-53, Nist Sp 800-63, Nist Sp 800-171, Poa&M, Vulnerability Management, Continuous Monitoring, Oscal, Wiz, Burp Suite, AWS, Identity Management, AI Workflows, Rfp Responses
**Posted:** 2026-09-11

> Owns hands-on GRC operations for the public-sector business, including FedRAMP/GovRAMP continuous monitoring, POA&M management, vulnerability remediation, audit readiness, and customer-facing compliance content. Requires 4+ years of cybersecurity or compliance experience and direct FedRAMP, GovRAMP, or comparable experience.

## Job Description

## Responsibilities
- Coordinate third-party assessment organization (3PAO) assessments and respond to auditor evidence and documentation requests.
- Maintain FedRAMP and GovRAMP controls and documentation aligned with NIST SP 800-53 Rev. 5 and related frameworks.
- Prepare certification and authorization packages, including System Security Plans (SSPs) and appendices.
- Build and maintain POA&M, compliance trackers, procedures, and status-reporting artifacts.
- Replace manual evidence collection with system-generated, API-driven, or continuously validated evidence.
- Run FedRAMP continuous monitoring and vulnerability-management activities from identification through remediation and verification.
- Coordinate remediation with Security, Engineering, and DevOps teams using tools such as Wiz, Burp Suite, and AWS services.
- Coordinate access reviews, incident-response exercises, and contingency-plan testing.
- Design automated access-validation mechanisms and deliver FedRAMP training programs.
- Conduct internal reviews of logged events and control activities; escalate gaps and report trends, risks, and remediation progress.
- Develop automation-first, AI-enabled, and machine-readable compliance workflows, including OSCAL or comparable formats.
- Partner with engineering and automation teams to integrate compliance data into risk management, vulnerability remediation, access-request, and reporting systems.
- Support public-sector sales by translating controls and system capabilities into accurate, persuasive customer-facing narratives.
- Develop security certification communications, RFP/RFx response frameworks, answer libraries, and AI-assisted tools.
- Monitor regulatory and industry changes, perform gap analyses, and contribute input to standards bodies when applicable.

## Required Qualifications
- 4+ years of hands-on cybersecurity, compliance, or identity-management experience, including personal execution of FedRAMP, GovRAMP, or comparable continuous-monitoring work.
- Direct experience with FedRAMP, GovRAMP, and NIST frameworks, including NIST 800-53, 800-63, and 800-171.
- Experience running scans, maintaining a POA&M, preparing deviation requests, conducting continuous monitoring, coordinating vulnerability remediation, and producing compliance reports.
- Ability to design and improve repeatable compliance processes and create structure where none exists.
- Strong written, verbal, organizational, and cross-functional collaboration skills.
- Ability to write persuasively for customer audiences and distinguish persuasive content from compliance-accurate content.
- Ability to adapt to changing requirements and manage multiple priorities.
- Demonstrated customer-facing experience and exposure to product or sales positioning.
- Must be a U.S. Person residing in the United States and able to obtain a U.S. OPM NACI clearance.

## Preferred Qualifications
- Public-sector experience.
- Experience in regulated industries such as financial services or healthcare.
- Knowledge of GDPR, CCPA, and additional NIST standards.
- CISSP, CISM, CISA, or IAPP certification.
- Experience with OSCAL, machine-readable compliance formats, AI tools such as ChatGPT, Glean, or Gemini, and automation-first workflows.
- Hands-on contribution to FedRAMP, GovRAMP, or NIST 800-63/171 certification and compliance initiatives.
- Experience with continuous monitoring, vulnerability management, policy updates, audit coordination, and proactive process-gap remediation.

## Similar jobs

- [Security Engineer](https://hotfix.jobs/jobs/b2d0b5eb-6441-418b-8992-e40ef5db3518) - DataVisor - Mountain View, CA - $120k – $150k/yr
- [Security GRC Analyst](https://hotfix.jobs/jobs/e2503f84-7d16-49f3-9f64-65e03e688c69) - Pinterest - Remote - $124k – $255k/yr
- [Network Engineer](https://hotfix.jobs/jobs/43cf4905-eaf1-4ef4-b803-2668738d34a8) - Icarus - El Segundo, CA - $115k – $165k/yr
- [Protective Intelligence & Threat Analyst](https://hotfix.jobs/jobs/19e4e635-ad0e-474f-85ee-147d674f6395) - OpenAI - San Francisco, CA - $126k – $225k/yr
- [Security Engineer, Application Security](https://hotfix.jobs/jobs/f2d0e34d-91a7-4864-8672-e4a6901e3ca0) - Mercor - San Francisco, CA - $130k – $500k/yr

**Apply:** https://hotfix.jobs/jobs/5d73adaf-d124-4e28-8493-34bc2fc418bc
**Canonical:** https://hotfix.jobs/jobs/5d73adaf-d124-4e28-8493-34bc2fc418bc