We're looking for a GRC Specialist to own and drive our compliance and authorization programs, with a strong emphasis on FedRAMP and NIST 800-53. This is a hands-on governance, risk, and compliance role for someone who can build and run a federal-grade compliance program from the ground up and manage it through continuous monitoring and reauthorization cycles.
U.S. citizenship is required for this role due to FedRAMP and federal customer requirements.
Key Responsibilities
Own the FedRAMP process end-to-end: System Security Plan (SSP) development and maintenance, POA&M tracking and remediation, control implementation statements, and continuous monitoring (ConMon) deliverables
Serve as primary point of contact for 3PAO assessments, coordinating testing, evidence collection, and finding resolution
Maintain compliance programs across SOC 2 Type II and ISO 27001
Respond to customers security questionnaires, and support sales enablement with SSPs, control narratives, and other security documentation
Partner with engineering, GTM, and leadership to ensure controls are implemented, evidenced, and operating effectively
Monitor changes to FedRAMP requirements, NIST guidance, and federal compliance obligations, and translate them into actionable program updates
Requirements: U.S. citizenship (required for FedRAMP program access and federal customer engagements)
3-5 years of hands-on GRC experience, with direct, demonstrable work on NIST control implementation and assessment
Direct experience supporting or owning a FedRAMP authorization (Moderate or High baseline) - SSP authorship, POA&M management, or ConMon deliverables
Solid understanding of the FedRAMP process, including 3PAO coordination
Working knowledge of SOC 2 and ISO 27001 frameworks
Excellent written English - you will be authoring SSPs, policies, and customer- and agency-facing documentation
Strong cross-team communication skills and comfort working directly with auditors and assessors
Ability to work independently and manage multiple compliance workstreams in a fast-paced environment
Experience with GRC platforms (e.g., Vanta, Drata, Scytale, or similar)
This position is open to all candidates.