Назад
Company hidden
3 дня назад

Lead GRC Subject Matter Expert for V4G (FedRAMP)

230 000 - 270 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Lead GRC Subject Matter Expert for V4G (FedRAMP) (Federal Compliance and GRC): Building automated, continuously monitored federal compliance content and product experiences for FedRAMP, NIST, CMMC, DFARS, and StateRAMP with an accent on control interpretation, machine-readable OSCAL content, and technically testable guidance. Focus on designing automated tests and failure conditions, maintaining cross-framework mappings, and shaping AI-assisted authorization workflows.

Location: Remote U.S.

Salary: $230,000–$270,000 per year, plus equity and benefits.

Company

hirify.global provides a trust management platform that helps businesses continuously monitor, improve, and prove their security and compliance.

What you will do

  • Own the creation, enhancement, and lifecycle management of federal compliance frameworks, controls, evidence requirements, and implementation guidance.
  • Interpret FedRAMP and NIST controls, assessment procedures, baselines, organization-defined parameters, inheritance models, and customer responsibility matrices.
  • Translate infrastructure contexts including AWS GovCloud, Azure Government, GCP, SaaS, endpoints, and CI/CD into automated tests and continuous monitoring detectors.
  • Shape OSCAL and FedRAMP 20x capabilities, including machine-readable SSPs, configuration-as-compliance, and continuous authorization workflows.
  • Maintain bidirectional crosswalks across 800-53, 800-171, CMMC, and StateRAMP, and advise Product and Design on federal workflows.
  • Partner with Engineering and ML on AI-assisted compliance guidance, evaluation sets, safety guardrails, and iterative content improvements.

Requirements

  • 8–10+ years of GRC and/or information security experience with hands-on federal compliance work, including FedRAMP programs, SSPs, supporting artifacts, and continuous monitoring.
  • Deep knowledge of NIST 800-53, FedRAMP, 800-53A/B, organization-defined parameters, control inheritance, customer responsibility matrices, PPSM, and STIG/CIS benchmarks.
  • Working familiarity with OSCAL or other machine-readable compliance approaches and the direction of FedRAMP 20x.
  • Ability to design functional tests with defined pass and failure conditions, evidence sufficiency criteria, and system-component coverage.
  • Experience translating compliance requirements into product capabilities and using AI-augmented workflows responsibly in GRC.
  • Strong analytical, written, verbal, collaborative, and autonomous working skills suitable for a Lead-level role.

Nice to have

  • DoD impact-level IL4/IL5, CMMC, StateRAMP, CNSSI 1253, ICD 503, GovCloud, or IL-environment architecture experience.
  • Prior product or content experience at a GRC platform.
  • CISSP-ISSEP, CISA, FedRAMP 3PAO assessor credentials, CISM, or equivalent experience.

Culture & Benefits

  • Remote workspace, internet, and cellphone stipends.
  • Medical, dental, and vision coverage, including covered employee-only premiums for most medical plans.
  • 16 weeks of paid parental leave, family planning benefits, and a health and wellness stipend.
  • Flexible PTO, 80 hours of sick time, 11 company-paid holidays, and matching 401(k) contributions with immediate vesting.
  • Virtual team-building activities, lunch-and-learns, and company-wide events.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →