Compliance Analyst

Onebrief
2dRemote

About The Position

You will play a critical role in building and sustaining Onebrief’s governance, risk and compliance program. Leveraging your expertise with NIST RMF and FedRAMP High, you will ensure compliance evidence is created, validated, and continuously organized in various GRC platforms. You will lead efforts to automate control testing, close gaps, and prepare for audits, directly contributing to Onebrief’s ability to obtain and maintain authorizations. About You You are a seasoned cybersecurity compliance professional with hands-on experience in federal frameworks and regulatory standards. You excel at translating complex compliance obligations into practical, cloud-native solutions. You thrive in remote, collaborative environments, enjoy solving compliance challenges with both precision and creativity, and are driven by continuous learning and professional growth. Most importantly, you are motivated by building secure, compliant IT ecosystems that enable organizations to scale with confidence.

Requirements

  • Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or a related field
  • Hands-on expertise with Risk Management Framework across multiple security domains
  • U.S. Citizen
  • 8+ years in Cybersecurity Compliance and related roles
  • Experience with Enterprise Mission Assurance Support Service (eMASS) and leveraging automated evidence collection and testing capabilities
  • Familiarity with cloud security standards (e.g., FedRAMP, ISO 27001, NIST 800-171, DoD Cloud Computing Security Requirements Guide)
  • Strong background in policy development, control testing, and evidence gathering
  • Excellent communication skills for working with both technical and non-technical stakeholders
  • CISSP, CISM, CISSO, CPTE, CySA+, FITSP-A, GCSA, CISA, ISSEP, GSLC, or GSNA

Nice To Haves

  • Proven ability to prioritize, adapt, and deliver under tight timelines in dynamic, compliance-driven environments
  • Experience in DoD environments and compliance frameworks (RMF and ICD 503)
  • Familiarity with agency-specific overlays (DoD, DHS, or civilian agencies)
  • Experience working with 3PAOs, Security Control Assessors, and Federal Customers

Responsibilities

  • Lead and support the full NIST RMF lifecycle for Onebrief deployments, on-prem or cloud-native, across multiple security boundaries
  • Maintain, and review authorization packages, including SSPs, SAPs, SARs, POA&Ms, STIGs, and supporting artifacts
  • Coordinate internal assessments and readiness checks ahead of external audits
  • Partner with Engineers, Product teams, and Security leadership to integrate compliance requirements into system design and operations
  • Provide guidance on secure architecture and control implementation
  • Track regulatory changes and advise leadership on compliance implications
  • Conduct periodic risk assessments and suggest appropriate risk treatment actions
  • Develop internal cybersecurity awareness and training presentations for employees
  • Conduct supply chain risk management assessments for current and future vendors
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service