Senior GRC Analyst
Core
Lead FedRAMP authorization, continuous monitoring, and federal compliance operations for an enterprise iPaaS platform serving government and Fortune 500 clients.
Role type
Senior GRC Analyst (Federal Compliance)
Builds
FedRAMP authorization packages, security assessment reports, and compliance artifacts for government contracts.
Domain
Cybersecurity / Federal Compliance / Cloud Infrastructure
Deliverable
client delivery
Required skills
FedRAMP authorization management, NIST 800-53 control implementation, risk assessment, audit coordination, vendor risk management, contract security review, POA&M management, vulnerability scanning oversight, access control reviews, regulatory reporting
Preferred skills
CISSP, CISA, FedRAMP PMO training, experience with AWS GovCloud/Azure Government/Google Cloud, NIST 800-171, CMMC, ISO 27001/27701, PCI-DSS, SOC 2, IRAP
Technologies
AWS GovCloud, Azure Government, Google Cloud, NIST 800-53, FedRAMP, ISO 27001, PCI-DSS, CMMC
Responsibilities
Lead FedRAMP authorization efforts including SSP development and 3PAO coordination; own continuous monitoring activities including monthly vulnerability scanning and incident reporting; maintain FedRAMP documentation and risk registers; lead internal and external audits for federal frameworks; coordinate with federal stakeholders to track and remediate findings; review contracts for security flow-down clauses; communicate compliance status to technical and non-technical stakeholders; oversee vendor security assurance processes; collaborate with engineering teams to implement NIST controls.
Seniority
Senior, hands-on IC