Compliance Analyst (GRC/RMF Focused)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Compliance Analyst (GRC/RMF Focused): Supports governance, risk, and compliance initiatives by developing, maintaining, and managing security documentation and artifacts aligned with federal standards like NIST SP 800-53 and FISMA, with an accent on RMF activities, continuous monitoring, and authorization efforts. Focus on translating technical system configurations into audit-ready documentation and supporting FedRAMP/CMMC compliance.
Location: Hybrid USA - Must work EST (8:30AM - 5:30PM), U.S. Citizen required and eligible for federal contracting.
Company
supports federal and regulated environments with GRC, RMF, and cybersecurity compliance services.
What you will do
- Author and maintain security documentation including System Security Plans (SSPs), control implementation statements, policies, and procedures.
- Develop documentation per agency-specific requirements and manage POA&Ms.
- Support continuous monitoring, RMF activities, and authorization efforts.
- Translate technical configurations into audit-ready documentation using GRC tools.
- Engage with technical and non-technical stakeholders, lead discussions, and communicate requirements clearly.
Requirements
- Bachelor’s degree in Cybersecurity, IT, Information Systems, or related field.
- Minimum 3–6+ years in GRC, RMF, or cybersecurity compliance in federal/regulated environments.
- Strong knowledge of NIST SP 800-53, FISMA, and related guidance (800-37, 800-60, 800-171, 800-137).
- Experience with FedRAMP, CMMC, SOC 2, and GRC platforms.
- Technical understanding of on-premises and cloud environments.
- Strong communication, organizational skills, and ability to manage multiple priorities.
Culture & Benefits
- Fast-paced environment with focus on detail-oriented compliance work.
- Proficiency with Microsoft tools (Word, Excel, SharePoint, Teams).
- Opportunity to leverage AI tools for documentation.
- Work independently while coordinating across teams.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →