Similar Jobs
See allSenior GRC Consultant — Federal & Complex Frameworks
Sprinto
India
GRC
FedRAMP
CMMC
Security Governance Risk & Compliance (GRC) Analyst
Virtru
US
CMMC
NIST 800-53
FedRAMP
Governance, Risk, and Compliance Analyst
Onebrief
Global
RMF
CMMC
SOC 2
Cyber Security - Manager (FedRAMP)
Riveron
US
FedRAMP
CMMC
NIST 800-53
Principal Security Engineer – GRC Team Lead
Smartsheet
US
GRC
Cloud Architecture
Audit Management
WHY THIS ROLE EXISTS:
- Onebrief sells to defense and government customers requiring proof of data protection.
- This role owns the architecture behind our compliance posture across FedRAMP, CMMC, SOC 2, and international frameworks.
- Compliance and security engineering must be integrated to implement technical controls.
WHAT YOU’LL DO:
- Own the design and implementation of Onebrief's GRC framework across RMF, FedRAMP, CMMC, SOC 2, and other applicable standards.
- Build and manage the control environment, including policies, procedures, and evidence collection systems.
- Design and implement technical security controls in partnership with Product, Engineering, Infrastructure and Corporate IT.
MINIMUM QUALIFICATIONS:
- 5+ years of experience in GRC, security engineering, or a combined compliance and technical security role.
- Direct experience with RMF, FedRAMP, CMMC, or equivalent federal compliance frameworks.
- Hands-on experience implementing technical security controls, such as IAM, logging and monitoring, network segmentation, or encryption.
Onebrief
Onebrief builds collaboration and AI-powered workflow software for military planning and operational coordination. Founded in 2019 and valued at over $2 billion, the company is a distributed team of builders from military, operational, and technology backgrounds.