Назад
Company hidden
3 часа назад

Governance, Risk, and Compliance Analyst (Cybersecurity)

160 000 - 200 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Governance, Risk, and Compliance Analyst (Cybersecurity): Owning RMF authorizations, FedRAMP High, CMMC 2.0, and SOC 2 compliance for federal and corporate environments with an accent on authorization evidence, control mapping, and audit readiness. Focus on automating control testing and evidence collection, managing POA&Ms and risk reviews, and translating regulatory requirements into actionable engineering and CI/CD decisions.

Location: United States, remote. U.S. citizenship required.

Salary: $160,000–$200,000 per year, plus equity.

Company

hirify.global builds collaboration and AI-powered workflow software for military planning and operational coordination, combining modern software, AI, and real-time collaboration.

What you will do

  • Own RMF authorizations across Department of War components and FedRAMP High, alongside CMMC 2.0 and SOC 2 compliance.
  • Maintain SSPs, SARs, POA&Ms, STIGs, control mappings, and other authorization and audit evidence.
  • Partner with Engineering, Product, and Security to embed compliance requirements into system design and CI/CD workflows.
  • Coordinate internal assessments and external audit readiness across federal and commercial frameworks.
  • Track regulatory and contractual changes, advise leadership, and run risk and vendor/supply chain assessments.
  • Automate control testing and evidence collection to reduce audit preparation and close corrective actions predictably.

Requirements

  • U.S. citizenship required.
  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related field.
  • 8+ years of experience in cybersecurity compliance.
  • Hands-on RMF expertise and experience with at least one of CMMC 2.0 or SOC 2.
  • One or more certifications: CISSP, CISM, CISSO, CPTE, CySA+, FITSP-A, GCSA, CISA, ISSEP, GSLC, or GSNA.
  • Experience with GRC platforms, automated evidence collection, and automated testing.

Nice to have

  • eMASS experience and experience in DoD environments.
  • Familiarity with ICD 503 and agency-specific DoD, DHS, or civilian overlays.
  • Experience with 3PAOs, Security Control Assessors, federal customers, or SOC 2 auditors.
  • Familiarity with FedRAMP, ISO 27001, NIST 800-171, and the DoD Cloud Computing SRG.

Culture & Benefits

  • Remote-first organization with flexible work hours and unlimited PTO.
  • Health, dental, vision, and life insurance.
  • 401(k) plan with company match and eight weeks of fully paid parental leave.
  • Annual company summit trips and a $1,000 yearly home office budget.
  • Equity participation in the company's success.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →