This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
You will play a critical role in building and sustaining Onebrief’s governance, risk and compliance program. Leveraging your expertise with NIST RMF and FedRAMP High, you will ensure compliance evidence is created, validated, and continuously organized in various GRC platforms. You will lead efforts to automate control testing, close gaps, and prepare for audits, directly contributing to Onebrief’s ability to obtain and maintain authorizations.
Job Responsibility:
Lead and support the full NIST RMF lifecycle for Onebrief deployments, on-prem or cloud-native, across multiple security boundaries
Maintain, and review authorization packages, including SSPs, SAPs, SARs, POA&Ms, STIGs, and supporting artifacts
Coordinate internal assessments and readiness checks ahead of external audits
Partner with Engineers, Product teams, and Security leadership to integrate compliance requirements into system design and operations
Provide guidance on secure architecture and control implementation
Track regulatory changes and advise leadership on compliance implications
Conduct periodic risk assessments and suggest appropriate risk treatment actions
Develop internal cybersecurity awareness and training presentations for employees
Conduct supply chain risk management assessments for current and future vendors
Requirements:
Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or a related field
Hands-on expertise with Risk Management Framework across multiple security domains
Active Secret Clearance required
8+ years in Cybersecurity Compliance and related roles
Experience with Enterprise Mission Assurance Support Service (eMASS) and leveraging automated evidence collection and testing capabilities
Familiarity with cloud security standards (e.g., FedRAMP, ISO 27001, NIST 800-171, DoD Cloud Computing Security Requirements Guide)
Strong background in policy development, control testing, and evidence gathering
Excellent communication skills for working with both technical and non-technical stakeholders
Certifications (one or more required): CISSP, CISM, CISSO, CPTE, CySA+, FITSP-A, GCSA, CISA, ISSEP, GSLC, or GSNA
Nice to have:
Proven ability to prioritize, adapt, and deliver under tight timelines in dynamic, compliance-driven environments
Experience in DoD environments and compliance frameworks (RMF and ICD 503)
Familiarity with agency-specific overlays (DoD, DHS, or civilian agencies)
Experience working with 3PAOs, Security Control Assessors, and Federal Customers
Active Top Secret / SCI eligibility
Top Secret / SCI eligibility is a plus
What we offer:
Equity: Share in the company's success
Flexible Work Environment: Remote work with flexible hours and unlimited PTO
Comprehensive Health Coverage: Health, dental, vision, and life insurance
Retirement Plan: 401(k) plan to secure your future
Parental Leave: 8 weeks at 100% regardless of state
Company Retreats: Annual company summit trips
Home Office Budget: $1,000 per year for home office improvements