
FedRamp Compliance Analyst
Posted Sep 1

Posted Sep 1
This is a fully remote position, open to applicants in United States.
β’ Take ownership of designated federal security and compliance workstreams, overseeing everything from requirement interpretation to implementation, evidence collection, remediation, and readiness for review.
β’ Facilitate ongoing continuous monitoring and evidence workflows in collaboration with Security, FedOps, Engineering, IT, People Operations, GRC, and other control performers.
β’ Assist in vulnerability detection and response by utilizing insights from tools such as Wiz, Nessus, and Burp; carry out triage, route tasks in Jira, track SLAs, follow through on remediation, validate results, and prepare evidence.
β’ Collaborate with technical teams on Security Impact Assessments, Significant Change Requests, decisions regarding control implementations, and activities related to change management.
β’ Contribute to the development of a compliance-as-code program through structured control content, JSON/YAML artifacts, schema validation, evidence indexing, automation, document generation, and reusable workflows.
β’ Maintain records related to control, evidence, remediation, risk, and ownership, while escalating issues such as gaps, aging items, dependencies, and decision points.
β’ Participate in the creation of federal authorization and assessment artifacts, which include control documentation, Security Decision Records, certification-package content, assessor requests, and continuous monitoring deliverables.
β’ Provide support for federal customer assurance activities such as onboarding, POVs, DDQs, RFPs, and requests from government or regulated customers.
β’ A minimum of 2 years of experience in security, compliance, GRC, risk management, audit, security operations, or a related field.
β’ Proficient understanding of NIST SP 800-53.
β’ Ability to translate security controls into technical implementations, operational processes, and audit evidence.
β’ Experience with evidence collection, control documentation, vulnerability remediation, risk tracking, audit support, or continuous monitoring.
β’ Capability to interpret architecture diagrams, security documentation, vulnerability findings, Jira tickets, logs, or engineering materials and convert them into compliance actions.
β’ Experience collaborating with Security, Engineering, Infrastructure/Operations, IT, and other technical teams.
β’ Excellent written communication and documentation skills.
β’ Ability to manage multiple workstreams, dependencies, owners, and deadlines while escalating risks proactively.
β’ Proven track record of enhancing processes through automation, effective documentation, reusable templates, data management, or streamlined workflows.
β’ Bonus or incentive compensation may be available.
β’ Equity options may be offered.
β’ A comprehensive benefits package is provided.
β’ Pre-employment checks will be conducted in accordance with relevant legislation and security/privacy policies.
biBerk Business Insurance
Doppel
PingWind Inc. (SDVOSB)
The Standard
Get handpicked remote jobs straight to your inbox weekly.