
GRC Engineer – NIST
Posted Aug 19

Posted Aug 19
This is a fully remote position, open to applicants in United States.
• Implement NIST 800-53 control mappings while applying security and privacy controls and baselines to software architectures.
• Develop, revise, and sustain System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), along with supporting authorization documents.
• Perform technical gap analyses and readiness evaluations for federal agency ATO or FedRAMP authorization processes.
• Assist in continuous monitoring cycles by managing monthly vulnerability logs, updating POA&Ms, and handling structural change requests.
• Guide clients throughout the Assessment and Authorization (A&A) process.
• Coordinate operational logistics with 3PAOs and independent evaluators.
• Collaborate with internal and client technical teams to address control deficiencies across Low, Moderate, and High baselines.
• Record technical security boundaries, interconnectivity agreements, and shared responsibility profiles across cloud environments.
• Monitor changes in NIST SP 800-53 revisions, FedRAMP requirements, and updates to federal policy.
• Work directly with organizations seeking federal authorizations.
• Oversee multiple compliance projects simultaneously under senior supervision.
• Work with global teams during U.S. Eastern Time business hours.
• A minimum of 2 years of hands-on experience delivering GRC outputs across NIST SP 800-53, FedRAMP, or NIST Risk Management Framework (RMF) lifecycles.
• Practical experience in creating, reviewing, and maintaining System Security Plans (SSPs), POA&Ms, and technical security documentation.
• Capability to handle multiple federal compliance project tasks at once while ensuring meticulous attention to detail.
• Knowledge of cloud service providers and secure configurations in government cloud environments such as AWS GovCloud or Azure Government.
• Strong written and verbal communication skills in English.
• Basic understanding of NIST SP 800-53 and FedRAMP Moderate and High baseline requirements.
• Recognized professional certifications such as CGRC, CAP, CISSP, or CompTIA Security+ (preferred).
• Relevant experience supporting live agency Authority to Operate (ATO) certifications or collaborating with 3PAO assessment teams (preferred).
• Familiarity with automated or manual FedRAMP Continuous Monitoring (ConMon) workflows (preferred).
• Exposure to CMMC 2.0 or NIST SP 800-171 baselines (preferred).
• Access to a reliable, high-speed internet connection.
• Professional home office setup conducive to confidential discussions and seamless collaboration.
• Availability to work a standard schedule of 8:00 AM–5:00 PM US Eastern Time.
• Willingness and capability to travel locally for occasional onsite meetings, team gatherings, or business activities.
• Must engage in live video interviews with the camera on and verify identity during the recruitment and onboarding process.
• Employment is contingent upon identity verification and background checks, where permitted by law.
• Must have authorization to work in the U.S. without current or future visa sponsorship.
• Opportunities for career development through mentorship and training programs.
• Reimbursement for approved training and certification courses related to the role.
• Competitive base salary.
• Regular performance evaluations tied to merit-based assessments.
• Eligibility for bonus opportunities.
• Ample opportunities for career progression.
• Remote-first culture offering flexibility to work from anywhere.
• Collaboration with a global team.
IGS Energy
RMI
Rightpoint
VikingCloud
Get handpicked remote jobs straight to your inbox weekly.