Onebrief

Onebrief

Corporate Governance, Risk, and Compliance Analyst

United States | Remote

Sponsorship not specified$171k-$800kDetected 14 days ago
CI/CDCybersecurityComplianceAuditingSupply ChainCorporate LawCadenceLeadershipCollaborationAdaptabilityInternal Audit

About the role

  • Onebrief brings modern software, AI, and real-time collaboration into those environments, helping teams operate with greater clarity, coordination, and adaptability in situations where decisions carry real-world consequences.
  • Valued at more than $2 billion, we continue to invest in product innovation, AI capabilities, and team growth.
  • This role needs someone who works closely with Engineering, Product, and Security leadership to keep every program aligned instead of managing each one in isolation.

Responsibilities

  • Own RMF authorizations across Department of War components and FedRAMP High, alongside CMMC 2.0 and SOC 2 compliance for corporate systems
  • Maintain authorization and audit evidence, including SSPs, SARs, POA&Ms, STIGs, and control mappings
  • Partner with Engineering, Product, and Security to embed compliance requirements into system design and CI/CD workflows, not bolt them on afterward

Requirements

  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or related field
  • 8+ years in cybersecurity compliance
  • Hands-on expertise with RMF and at least one of CMMC 2.0 or SOC 2

Nice to have

  • Experience in DoD environments and compliance frameworks (RMF, ICD 503)
  • Familiarity with agency-specific overlays (DoD, DHS, or civilian agencies)
  • Familiarity with cloud security standards (FedRAMP, ISO 27001, NIST 800-171, DoD Cloud Computing SRG)
  • Indicators of Success
  • This role will evolve as priorities change, but the outcomes below reflect what success typically looks like in the first six months.
  • A successful Governance, Risk, and Compliance Analyst will:

Skills

  • Why This Role Exists
  • SSPs, SARs, POA&Ms, control mappings, and testing that holds up under audit.
  • Manual compliance work doesn't scale across this many frameworks.
  • The work sits between engineering and a wide set of regulatory requirements.
  • Keep authorization packages current across every framework instead of reconstructing them under deadline pressure
  • Reduce manual audit prep by automating control testing and evidence collection
  • Close open POA&M and corrective action items on a predictable cadence
  • Become the go-to person engineers check with before shipping changes that touch compliance boundaries, federal or corporate
  • eMASS, GRC platforms, NIST RMF documentation (SSPs, SARs, POA&Ms, STIGs), CMMC 2.0 and SOC 2 control frameworks

Compensation

  • In the absence of an executed Recruitment Services Agreement, there will be no obligation to any referral compensation or recruiter fee.

Company info

  • Experience working with 3PAOs, Security Control Assessors, federal customers, or SOC 2 auditors

Visa & Work Authorization

  • Citizen

This listing is sourced directly from Onebrief's careers page and normalized into a canonical job model.