
Corporate Governance, Risk and Compliance Analyst
Posted Jul 15

Posted Jul 15
This is a fully remote position, open to applicants in United States.
• Manage RMF authorizations for Department of War components and FedRAMP High, in addition to CMMC 2.0 and SOC 2 compliance for corporate systems.
• Oversee the maintenance of authorization and audit documentation, which includes SSPs, SARs, POA&Ms, STIGs, and control mappings.
• Collaborate with Engineering, Product, and Security teams to integrate compliance requirements into system design and CI/CD workflows, rather than adding them later.
• Organize internal assessments and prepare for external audits across all relevant frameworks.
• Monitor regulatory and contractual updates, providing guidance to leadership on their implications for Onebrief.
• Conduct risk assessments and evaluate vendor/supply chain risks in both federal and corporate settings.
• Must be a U.S. Citizen.
• Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related field.
• At least 8 years of experience in cybersecurity compliance.
• Practical knowledge of RMF and proficiency in at least one of CMMC 2.0 or SOC 2.
• Possess one or more of the following certifications: CISSP, CISM, CISSO, CPTE, CySA+, FITSP-A, GCSA, CISA, ISSEP, GSLC, or GSNA.
• Familiarity with GRC platforms, particularly those involving automated evidence collection and testing (experience with eMASS is a plus).
• Equity: Participate in the company's success.
• Flexible Work Environment: A remote-first organization with adaptable work hours and unlimited PTO.
• Comprehensive Health Coverage: Includes health, dental, vision, and life insurance.
• Retirement Plan: 401(k) plan with company matching to help secure your future.
• Parental Leave: 8 weeks at full pay, regardless of state.
• Company Retreats: Annual company summit trips.
• Home Office Budget: $1,000 per year allocated for home office enhancements.
ZoomInfo
Lifelancer
unybrands
Get handpicked remote jobs straight to your inbox weekly.