The board
- Pay
- $120,000–$145,000/yr
- Where
- Hub - Washington DC
- Posted
- Sep 11
Socure is seeking an Analyst, GRC – Public Sector to own the hands-on execution of the company’s governance, risk, and compliance operations for its public sector business. Reporting to the Director of GRC – Public Sector, this role is responsible day-to-day for running FedRAMP/GovRAMP continuous monitoring, building and maintaining the POA&M and compliance trackers that keep the program audit-ready, and coordinating access reviews, vulnerability remediation, and evidence collection with Security, Engineering, IT, DevOps, Product, Legal, and other teams.
What you'd do
- Day-to-day coordination and execution of externalThird Party Assessment Organization (3PAO) assessments and responding to auditor requests for evidence and documentation.
- Maintain and update FedRAMP and GovRAMP controls and documentation in alignment with organizational and regulatory requirements, including controls aligned with NIST SP 800-53 rev 5 and other related frameworks.
- Prepare certification and authorization packages and maintain related documentation such as the System Security Plan (SSP) and associated appendices.
- Replace manual evidence collection with system-generated, API-driven, or continuously validated evidence where possible.
- Build and maintain the trackers, procedures, and status-reporting artifacts that operationalize this work, structured so other stakeholders can use them directly.
- Design and evolve an automation-first continuous monitoring program leveraging system integrations, telemetry, and real-time data pipelines
- Lead the day-to-day FedRAMP continuous monitoring process including vulnerability management lifecycle, from identification through remediation and verification, coordinating with Security, Engineering, and DevOps teams to address issues identified with tools such as Wiz, Burp Suite, AWS native services, and other platforms and resolve issues within FedRAMP and GovRAMP timelines.
- Coordinate recurring continuous monitoring compliance activities such as access reviews, incident response exercises, and contingency plan testing.
- Design scalable and automated access validation mechanisms integrated with identity and infrastructure systems
- Design, implement and deliver FedRAMP training programs to promote compliance awareness
- Create and manage automated workflows to improve efficiency.
What they want
- Monitor new and evolving requirements and perform gap analyses including
- Updates to applicable NIST Special Publications and other government standards
- Contract security requirements from new customers
- Updates to the FedRAMP Program requirements and processes as the program evolves
- Provide input to standards bodies on evolving standards when applicable
- 4+ years of hands-on cybersecurity, compliance, or identity-management experience, including demonstrated personal execution of FedRAMP, GovRAMP, or comparable continuous-monitoring work — running scans, building or maintaining a POA&M, and preparing deviation requests.
- Public sector experience is a plus but not required.
- Direct experience with FedRAMP, GovRAMP, and NIST frameworks (800-53, 800-63, 800-171).
- Proven ability to personally execute continuous monitoring, vulnerability remediation, and compliance reporting.
- Proven ability to design and improve repeatable compliance processes - identifying inefficiencies, defining clear steps, and building structure where none exists; experience using AI tools (e.g., ChatGPT, Glean, Gemini) and machine-readable formats (e.g., OSCAL) to accelerate that work is a strong plus.
- Strong communication, organization, and collaboration skills with the ability to manage multiple priorities, including strong written communication and the ability to write persuasively for a customer audience — distinct from writing that is merely compliance-accurate.