Назад
Company hidden
3 дня назад

Analyst, GRC – Public Sector (Cybersecurity)

120 000 - 145 000$
Формат работы
hybrid
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Analyst, GRC – Public Sector (Cybersecurity): Running FedRAMP and GovRAMP continuous monitoring, vulnerability remediation, audit evidence, and compliance operations for public sector security programs with an accent on automation-first workflows, NIST controls, and machine-readable OSCAL documentation. Focus on building real-time evidence and access-validation systems, coordinating cross-functional remediation, and creating persuasive security content for public sector customers and RFP responses.

Location: Hybrid in Washington, DC; must be a U.S. Person residing in the United States and able to obtain a U.S. OPM NACI clearance.

Salary: $120K–$145K base salary, plus equity, benefits, and an annual bonus or commission plan.

Company

hirify.global builds identity trust infrastructure for the digital economy, verifying legitimate identities and preventing fraud for businesses, governments, and consumers.

What you will do

  • Run day-to-day FedRAMP and GovRAMP continuous monitoring, including vulnerability management, remediation verification, access reviews, incident response exercises, and contingency plan testing.
  • Coordinate 3PAO assessments, auditor evidence requests, certification packages, System Security Plan documentation, POA&M tracking, and compliance reporting.
  • Collaborate with Security, Engineering, IT, DevOps, Product, Legal, and other teams to resolve findings within required timelines.
  • Replace manual evidence collection with system-generated, API-driven, continuously validated evidence and automated workflows.
  • Develop machine-readable compliance documentation, including OSCAL or comparable structured formats, and integrate compliance data into risk and monitoring systems.
  • Support public sector sales with customer-facing security narratives, certification communications, RFP response frameworks, and gap analyses of evolving requirements.

Requirements

  • 4+ years of hands-on cybersecurity, compliance, or identity-management experience, including direct FedRAMP, GovRAMP, or comparable continuous-monitoring work.
  • Direct experience with FedRAMP, GovRAMP, and NIST frameworks, including NIST SP 800-53, 800-63, and 800-171.
  • Hands-on experience with continuous monitoring, vulnerability remediation, compliance reporting, audit coordination, POA&M management, and deviation requests.
  • Strong written communication, organization, collaboration, and customer-facing skills, including the ability to write persuasive public sector content.
  • Experience improving repeatable compliance processes and coordinating work across multiple teams.
  • Must be a U.S. Person residing in the United States and able to obtain a U.S. OPM NACI clearance.

Nice to have

  • Experience with AI tools such as ChatGPT, Glean, or Gemini and machine-readable formats such as OSCAL.
  • Public sector experience, regulated-industry experience, or knowledge of GDPR, CCPA, and digital identity regulations.
  • Professional certifications such as CISSP, CISM, CISA, or IAPP credentials.

Culture & Benefits

  • Hybrid work environment based in Washington, DC.
  • Equity and benefits included in the total rewards package.
  • Annual bonus or commission plan in addition to base salary.
  • High-ownership environment focused on solving complex customer and public sector security problems.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →