Source Job

US 24w maternity 24w paternity

  • Own FedRAMP and GovRAMP certifications and roadmaps, including package management and compliance timelines.
  • Manage 3PAO relationships and assessments, coordinating scoping, evidence, and results validation.
  • Lead continuous monitoring, POA&M processes, and drive compliance automation and efficiency.

FedRAMP NIST 800-53 Cloud Security Compliance

20 jobs similar to Senior Security Engineer I – GRC FedRAMP (Remote Eligible)

Jobs ranked by similarity.

$190,000–$210,000/yr
Global

  • Own Filevine's FedRAMP 20x strategy and execution, including evidence automation, continuous monitoring, and certification readiness.
  • Drive the security compliance and trust program across FedRAMP, SOC 2, ISO, HIPAA, and PCI-DSS, converting obligations into engineering work.
  • Lead cross-functional alignment and executive reporting to ensure compliance, privacy, and security priorities are shipped on time.

Filevine is a Legal AI company delivering Legal Operating Intelligence for the future of legal work. Fueled by a team of exceptional collaborators and innovators, Filevine’s rapid growth has earned AI awards and recognition from Deloitte and Inc. as one of the most innovative and fastest-growing technology companies in the country.

India Unlimited PTO

  • Lead delivery of FedRAMP, CMMC, HITRUST, and NIST compliance engagements where federal authorization is on the line.
  • Build reusable IP like control-mapping libraries, SSP templates, and evidence-collection playbooks for complex frameworks.
  • Own pricing, margin, and utilization for specialized federal engagements, plus leverage AI to standardize deliverables.

Sprinto is an Autonomous Trust Platform that centralizes trust requirements across security frameworks, vendors, and customers. Backed by top-tier investors like Accel, Elevation, and Blume Ventures, we've raised $31.8M and are trusted by over 3,000 organizations across 75 countries, with a remote culture built on ownership and progress over perfection.

$100,000–$160,000/yr
US

  • Support the day-to-day security posture of systems across cloud and on-prem environments, including vulnerability management and remediation tracking.
  • Partner with infrastructure, platform, and engineering teams on secure configuration, access control, logging, and incident readiness.
  • Support compliance activities related to GovRAMP, FedRAMP, PCI DSS, and internal reviews using AWS security tooling.

Grant Street Group is a growing company that provides SaaS products for electronic payments, auctions, and tax collection. The company fosters a culture of teamwork, professional excellence, and individual responsibility in a technology-rich remote environment.

US

  • Maintain Risk Management Framework artifacts for DevSecOps pipeline inheritance of NIST SP 800-53 controls.
  • Complete and validate STIG/SRG checklists quarterly and provide monthly application STIG status reports.
  • Evaluate program risks, document mitigation strategies, and recommend courses of action to ensure continuous ATO compliance.

DecisionPoint is a company providing cloud services and DevSecOps solutions, supporting ARTRANS AWS environments. It is a regular full-time employer fostering a culture of security and compliance, with an active Secret clearance required for this role.

US

  • Lead end-to-end service delivery operations for cybersecurity and cloud security professional services engagements.
  • Own the delivery lifecycle for FedRAMP advisory, implementation, continuous monitoring, and related security programs.
  • Develop operational strategies and governance models ensuring compliance with NIST 800-53, FedRAMP, and DoD frameworks.

This company specializes in cybersecurity and cloud service delivery for federal agencies, managing mission-critical environments with strict compliance requirements. They are a mid-sized organization focused on scalable operations and measurable outcomes.

US 24w maternity 24w paternity

  • Own the end-to-end GRC strategy and roadmap, driving compliance maturity and reducing audit risk.
  • Design and implement policy-as-code systems, translating compliance frameworks into enforceable code.
  • Lead full audit cycles, manage evidence collection, and architect GRC platform strategy for continuous compliance.

Smartsheet empowers teams to manage work and scale solutions, now uniting human teams with AI agents to automate tasks and uncover insights. With a history of over 20 years, the company fosters a culture of inclusion, creativity, and big thinking, offering professional growth and a supportive environment.

$130,000–$145,000/yr
US Unlimited PTO 20w maternity 12w paternity

  • Support and scale the Assurance & Compliance function through an engineering-driven, automation-first approach.
  • Partner with Engineering, Security, Legal, and other teams to support compliance programs and audit readiness.
  • Help transform compliance into a continuous, measurable capability embedded into operations.

Flock builds technology that reduces crime and protects privacy, partnering with cities, businesses, schools, and neighborhoods. With over $1B in funding and an $8.3B valuation, the company is a high-performance team united by urgency, ownership, and a shared commitment to meaningful impact.

Global

  • Own RMF authorizations across Department of War components and FedRAMP High, alongside CMMC 2.0 and SOC 2 compliance for corporate systems.
  • Maintain authorization and audit evidence, including SSPs, SARs, POA&Ms, STIGs, and control mappings.
  • Partner with Engineering, Product, and Security to embed compliance requirements into system design and CI/CD workflows.

Onebrief builds collaboration and AI-powered workflow software for military planning and operational coordination. Founded in 2019, valued at over $2 billion, they are a distributed team of builders from military, operational, and technology backgrounds.

US Unlimited PTO 24w maternity 24w paternity

  • Own US customer trust operations, managing questionnaire triage and completion for enterprise customers.
  • Respond to customer security inquiries with technical depth, building trusted relationships.
  • Drive process improvements and collaborate with sales and security teams to accelerate deals.

Smartsheet empowers teams to manage work and scale solutions with AI. It is a publicly traded company with a culture of innovation and collaboration.

$125,000–$150,000/yr
US

  • Own and manage POA&M lifecycle activities, including tracking findings, coordinating remediation, and maintaining audit-ready documentation.
  • Support FISMA compliance programs with evidence collection, continuous monitoring, and coordination with system owners and ISSOs/ISSMs.
  • Develop operational reporting for leadership and government stakeholders, translating compliance and operational data into actionable insights.

Aquia is a Veteran-founded digital services firm that helps the government modernize and secure its systems and processes. Named the “#1 Best Remote Startup to Work For in 2025” by Built In and a certified “Great Place to Work” for five years in a row, we prioritize outcomes over outputs.

US Unlimited PTO

  • Lead the technical work to achieve and maintain compliance certifications (SOC 2, ISO 27001, and the upcoming FedRAMP process)
  • Design and implement security controls across AWS infrastructure, CI/CD pipelines, Kubernetes, and application deployments
  • Build the automation, logging, and evidence collection required for continuous compliance

Zafran's mission is to stop the exploitation of vulnerabilities everywhere, using an Exposure Graph that maps and neutralizes real attack paths. Backed by Menlo Ventures, Sequoia Capital, and Cyberstarts, they are one of the fastest-growing companies in cybersecurity, with a culture of meaningful work and challenging teammates.

US 5w PTO

  • Take ownership of building and scaling comprehensive security, privacy, and compliance programs that protect customer data.
  • Lead compliance initiatives such as SOC 2 Type 2 audits and evaluate additional frameworks like ISO 27001 and HIPAA.
  • Build scalable automated security processes by replacing manual tasks with scripts, APIs, and AI-powered solutions.

Our partner is a technology company focused on building secure, scalable systems. They operate with a remote, collaborative culture emphasizing ownership, transparency, and continuous improvement, with around 50–300 employees.

$145,000–$175,000/yr
United States

  • Strengthen company-wide security posture through hands-on engineering, collaboration, and pragmatic standards, focusing on application security, cloud and infrastructure security, and secure development practices.
  • Define and implement scalable security standards supporting SOC 2 readiness through practical, automated, and auditable solutions, partnering with Engineering, Infrastructure, IT, Product, Legal, and other teams.
  • Build and maintain internal security tools, automation, and services that support secure development, compliance workflows, vulnerability management, and operational visibility.

Later is the world’s most intelligent influencer marketing company, built to give brands the confidence to create unforgettable campaigns by combining real creator relationships, trusted intelligence, and expert guidance. Trusted by leading enterprise brands including Nike, Wayfair, Unilever, and Southwest Airlines, Later bridges creativity and performance so campaigns deliver results.

US

  • Lead RMF authorization activities, including SSP, SAP, SAR, and POA&M development.
  • Conduct vulnerability assessments and enforce secure configurations using CIS Benchmarks and DISA STIGs.
  • Support cloud security initiatives in AWS GovCloud and advise on AI-enabled system security.

This company provides cybersecurity solutions for federal government systems. They are a mid-sized organization with a collaborative culture focused on security and compliance.

$105,000–$130,000/yr
US

  • Consult onsite and remotely with customers to collect and analyze data related to policies, infrastructure, and compliance requirements.
  • Perform gap analyses of current environments and recommend remediation steps.
  • Assist with sales and marketing activities as a subject matter expert and prepare industry presentations.

CampusGuard provides information security and privacy consulting and compliance services for campus-based organizations. It is a full-service firm leveraging industry standards to deliver world-class security and compliance services.

$111,427–$200,000/yr
US

  • Lead Risk Management Framework activities for a federal AI platform deployment in AWS GovCloud.
  • Own authorization artifacts and coordinate with ISSOs and Authorizing Officials for ATO.
  • Partner with platform engineers on cloud and container security, vulnerability management, and hardening.

LMI is a digital solutions provider dedicated to accelerating government impact with innovation and speed, bringing commercial-grade platforms and mission-ready AI to federal agencies. Headquartered in Tysons, Virginia, it serves the defense, space, healthcare, and energy sectors, with a culture more startup than traditional government contractor.

$170,000–$218,000/yr
US

  • Design, deploy, and operate secure cloud infrastructure across AWS and AWS GovCloud to support regulated deployments.
  • Drive platform reliability, release operations, and incident response for production and customer-facing systems.
  • Translate compliance obligations into practical engineering work, including access controls, monitoring, and documentation.

Arch Systems empowers discrete manufacturing facilities with deep data insights for optimal efficiency and proactive decision-making. As a remote-first company with a passionate, multidisciplinary team, they foster innovation and collaboration among employees.

$150,000–$170,000/yr
US Unlimited PTO

  • Lead the governance, risk, and compliance function across security policies, standards, risk management, audits, and third-party risk.
  • Own audit readiness and ongoing compliance programs across frameworks such as SOC 2, ISO 27001, GovRAMP, PCI DSS, HIPAA, NIST CSF, and more.
  • Manage third-party and supply chain risk management, including vendor security reviews, due diligence, and remediation tracking.

Accela provides government software solutions to improve efficiency, increase citizen engagement, and enable thriving communities. They have been an industry leader for nearly 20 years and are committed to diversity, equity, and inclusion.

US

  • Design, deploy, and manage cloud infrastructure on FedRAMP-authorized platforms (AWS GovCloud, Azure Government, Google Cloud for Government) supporting Army workloads.
  • Lead technical execution of cloud migration efforts including workload assessment, lift-and-shift, re-platforming, and cloud-native refactoring.
  • Implement Infrastructure as Code (IaC) using Terraform, AWS CloudFormation, Azure Bicep, or equivalent tools to automate provisioning and configuration management.

Empower AI provides AI solutions for government agencies, helping federal leaders enhance workforce potential through practical transformation. Headquartered in Reston, VA, the company leverages over 30 years of experience in Health, Defense, and Civilian missions, and is recognized as a 2024 Military Friendly Employer.

United States Unlimited PTO

  • Partner with the CISO to drive security strategy, roadmap, and execution across application security, GRC, and operations.
  • Support compliance initiatives including PCI, SOC 2, ISO 27001, DORA, and FedRAMP readiness.
  • Serve as a trusted security leader in customer-facing settings, translating technical risks into business language.

Sardine is the leading agentic risk platform for fighting financial crime, integrating data across risk teams to stop fraud and automate AML operations. With over 6 billion profiled devices and 800 million consumers, we maintain a remote-first culture that values performance over hours worked.