Onebrief
Corporate Governance, Risk, and Compliance Analyst
United States | Remote
Sponsorship not specified$171k-$800kDetected 14 days ago
CI/CDCybersecurityComplianceAuditingSupply ChainCorporate LawCadenceLeadershipCollaborationAdaptabilityInternal Audit
About the role
- Onebrief brings modern software, AI, and real-time collaboration into those environments, helping teams operate with greater clarity, coordination, and adaptability in situations where decisions carry real-world consequences.
- Valued at more than $2 billion, we continue to invest in product innovation, AI capabilities, and team growth.
- This role needs someone who works closely with Engineering, Product, and Security leadership to keep every program aligned instead of managing each one in isolation.
Responsibilities
- Own RMF authorizations across Department of War components and FedRAMP High, alongside CMMC 2.0 and SOC 2 compliance for corporate systems
- Maintain authorization and audit evidence, including SSPs, SARs, POA&Ms, STIGs, and control mappings
- Partner with Engineering, Product, and Security to embed compliance requirements into system design and CI/CD workflows, not bolt them on afterward
Requirements
- Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or related field
- 8+ years in cybersecurity compliance
- Hands-on expertise with RMF and at least one of CMMC 2.0 or SOC 2
Nice to have
- Experience in DoD environments and compliance frameworks (RMF, ICD 503)
- Familiarity with agency-specific overlays (DoD, DHS, or civilian agencies)
- Familiarity with cloud security standards (FedRAMP, ISO 27001, NIST 800-171, DoD Cloud Computing SRG)
- Indicators of Success
- This role will evolve as priorities change, but the outcomes below reflect what success typically looks like in the first six months.
- A successful Governance, Risk, and Compliance Analyst will:
Skills
- Why This Role Exists
- SSPs, SARs, POA&Ms, control mappings, and testing that holds up under audit.
- Manual compliance work doesn't scale across this many frameworks.
- The work sits between engineering and a wide set of regulatory requirements.
- Keep authorization packages current across every framework instead of reconstructing them under deadline pressure
- Reduce manual audit prep by automating control testing and evidence collection
- Close open POA&M and corrective action items on a predictable cadence
- Become the go-to person engineers check with before shipping changes that touch compliance boundaries, federal or corporate
- eMASS, GRC platforms, NIST RMF documentation (SSPs, SARs, POA&Ms, STIGs), CMMC 2.0 and SOC 2 control frameworks
Compensation
- In the absence of an executed Recruitment Services Agreement, there will be no obligation to any referral compensation or recruiter fee.
Company info
- Experience working with 3PAOs, Security Control Assessors, federal customers, or SOC 2 auditors
Visa & Work Authorization
- Citizen
Apply directly at Onebrief →Create a free account for alerts like thisView Onebrief immigration profile
This listing is sourced directly from Onebrief's careers page and normalized into a canonical job model.