2 часа назад
Principal Security GRC Analyst (FedRAMP)
150 000 - 200 000$
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Principal Security GRC Analyst (FedRAMP): Driving control implementation, audit readiness, and cross-framework harmonization for a cloud-based HPC and simulation platform with an accent on FedRAMP, SOC 2, ISO 27001, NIST, and CMMC compliance. Focus on designing controls, collecting audit evidence, engaging auditors and government officials, and automating security, compliance, and privacy processes.
Location: Remote (United States); US Citizenship required
Salary: $150,000–$200,000 estimated base salary, plus equity
Company
develops a cloud-based digital engineering, HPC, and simulation platform using intelligent automation, applied AI, data management, and engineering applications.
What you will do
- Mature a multi-framework security governance, risk, and compliance program under the guidance of the Director of Compliance.
- Drive control implementation, audit readiness, evidence collection, and cross-framework harmonization.
- Work directly with auditors and government officials across NIST SP 800, FedRAMP, SOC 2, ISO 27001, Cyber Essentials, CSA, and related frameworks.
- Partner with security, IT, engineering, product, platform, and other teams to translate compliance requirements into practical controls.
- Represent the compliance program in customer discussions, security questionnaires, and due diligence reviews.
- Draft policies and procedures and create automated processes for distributing security, compliance, and privacy knowledge.
Requirements
- 8+ years of experience with multiple compliance frameworks, audits, and complex implementation projects.
- Deep expertise in at least one framework such as SOC 2 Type II, ISO 27001, FedRAMP, or the NIST SP 800 series.
- Experience adapting compliance programs to changes and solving novel compliance challenges in a scaling technology environment.
- US Citizenship required due to the nature of the work.
Nice to have
- Exposure to GDPR, ITAR, EAR, NISPOM, CMMC, or other regulations and frameworks.
- Certifications such as CISM, GSLC, Security+ CE, or CISSP.
- Flexibility to expand responsibilities beyond security compliance.
Culture & Benefits
- Remote work in the United States.
- Equity offered in addition to the estimated base salary.
- Collaborative, mission-driven environment focused on engineering and scientific innovation.
- Employment is contingent upon successful completion of a comprehensive background check.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
5 дней назад
Lead GRC Subject Matter Expert for V4G (FedRAMP)
230 000 - 270 000$
4 дня назад
InfoSec Analyst II, Trust (AI Governance)
96 000 - 160 000$
7 дней назад
Senior GRC Manager (Cybersecurity)
3 дня назад
GRC/IT Compliance Analyst
108 000 - 130 000$
4 дня назад
Director, Cybersecurity (GRC)
148 000 - 267 840$
6 часов назад
Security Governance Risk & Compliance Analyst I (Cybersecurity)
49 729 - 73 130$