GRC Analyst - Public Sector
Core
Execute hands-on governance, risk, and compliance operations for the public sector business, focusing on FedRAMP/GovRAMP continuous monitoring, vulnerability remediation, and audit readiness.
Role type
Senior IC GRC Analyst (Public Sector)
Builds
FedRAMP/GovRAMP compliance programs, automated evidence collection pipelines, and machine-readable documentation (OSCAL).
Domain
Cybersecurity compliance, Public Sector, Identity Trust
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure
Required skills
FedRAMP/GovRAMP execution, NIST 800-53/800-63/800-171 framework knowledge, continuous monitoring lifecycle management, vulnerability remediation coordination, POA&M management, 3PAO assessment coordination, access review design, RFP response drafting, OSCAL format proficiency, AI tool integration for compliance workflows
Preferred skills
Regulated industry experience (financial services, healthcare), GDPR/CCPA knowledge, CISSP/CISM/CISA/IAPP certifications, prior public sector experience
Technologies
Wiz, Burp Suite, AWS native services, OSCAL, ChatGPT, Glean, Gemini
Responsibilities
Coordinate 3PAO assessments and respond to auditor evidence requests; maintain FedRAMP/GovRAMP controls and documentation aligned with NIST frameworks; design automation-first continuous monitoring programs; lead vulnerability management lifecycle from identification to remediation; draft customer-facing compliance narratives and RFP responses; monitor evolving regulatory requirements and perform gap analyses.
Seniority
Mid-Senior, hands-on IC