Назад
Company hidden
2 часа назад

Principal Security GRC Analyst (FedRAMP)

150 000 - 200 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Principal Security GRC Analyst (FedRAMP): Driving control implementation, audit readiness, and cross-framework harmonization for a cloud-based HPC and simulation platform with an accent on FedRAMP, SOC 2, ISO 27001, NIST, and CMMC compliance. Focus on designing controls, collecting audit evidence, engaging auditors and government officials, and automating security, compliance, and privacy processes.

Location: Remote (United States); US Citizenship required

Salary: $150,000–$200,000 estimated base salary, plus equity

Company

hirify.global develops a cloud-based digital engineering, HPC, and simulation platform using intelligent automation, applied AI, data management, and engineering applications.

What you will do

  • Mature a multi-framework security governance, risk, and compliance program under the guidance of the Director of Compliance.
  • Drive control implementation, audit readiness, evidence collection, and cross-framework harmonization.
  • Work directly with auditors and government officials across NIST SP 800, FedRAMP, SOC 2, ISO 27001, Cyber Essentials, CSA, and related frameworks.
  • Partner with security, IT, engineering, product, platform, and other teams to translate compliance requirements into practical controls.
  • Represent the compliance program in customer discussions, security questionnaires, and due diligence reviews.
  • Draft policies and procedures and create automated processes for distributing security, compliance, and privacy knowledge.

Requirements

  • 8+ years of experience with multiple compliance frameworks, audits, and complex implementation projects.
  • Deep expertise in at least one framework such as SOC 2 Type II, ISO 27001, FedRAMP, or the NIST SP 800 series.
  • Experience adapting compliance programs to changes and solving novel compliance challenges in a scaling technology environment.
  • US Citizenship required due to the nature of the work.

Nice to have

  • Exposure to GDPR, ITAR, EAR, NISPOM, CMMC, or other regulations and frameworks.
  • Certifications such as CISM, GSLC, Security+ CE, or CISSP.
  • Flexibility to expand responsibilities beyond security compliance.

Culture & Benefits

  • Remote work in the United States.
  • Equity offered in addition to the estimated base salary.
  • Collaborative, mission-driven environment focused on engineering and scientific innovation.
  • Employment is contingent upon successful completion of a comprehensive background check.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →