Also available on
Job Description
📋 Description Own design and implementation of Onebrief's GRC framework (RMF, FedRAMP, CMMC, SOC 2). Build and manage the control environment: policies, procedures, and evidence. Design and implement security controls with Product, Eng, Infra, IT (IAM, encryption). Collaborate with Engineering and IT to turn requirements into working controls. 🎯 Requirements 5+ years in GRC, security engineering, or a combined compliance/technical security role. Direct experience with RMF, FedRAMP, CMMC, or equivalent. Hands-on security controls: IAM, logging/monitoring, encryption. Knowledge of NIST 800-53 and/or NIST 800-171. Experience managing third-party audits and assessor relationships. Strong written comms translating regulatory language into guidance. 🎁 Benefits Remote work options; distributed team. Work on defense and government projects.