Remotery

Public Sector Compliance Analyst

atRapid7Full-timeComplianceJuniorMid-level$86.7k – $117.3k/year

Posted May 7

πŸ“‹ Description

β€’ Assist in the daily operations of Rapid7’s US Public Sector compliance programs, primarily focusing on FedRAMP.

β€’ Help maintain compliance documentation, including policies, procedures, system security plans (SSPs), authorization artifacts, and supporting evidence.

β€’ Support continuous monitoring (ConMon) efforts, including the collection of ongoing evidence and reporting.

β€’ Aid in managing Plans of Action & Milestones (POA&Ms), including tracking remediation progress, timelines, and risk ownership.

β€’ Monitor and facilitate control implementation in accordance with NIST 800-53 rev. 5 and NIST 800-171.

β€’ Utilize ATO-focused GRC platforms such as Paramify, ServiceNow GRC, Onspring, or RegScale to oversee compliance status, risks, and findings.

β€’ Collaborate with Engineering and Security teams to comprehend technical control implementations, vulnerabilities, and remediation strategies.

β€’ Assist in audit and assessment preparedness activities, including ATO packages and regulatory reporting.

β€’ Support vendor evaluations, including Control Implementation Summaries (CIS) and Customer Responsibility Matrices (CRM).

β€’ Help identify opportunities to enhance GRC, POA&M, and ConMon processes through standardization, automation, and improved data quality.

β€’ Gain practical exposure to evolving requirements such as CMMC, recent Executive Orders, and emerging cybersecurity initiatives in the US public sector.


⛳️ Requirements

β€’ 2-5 years of experience (or equivalent academic, internship, or early-career experience) in cybersecurity, risk management, compliance, governance, or cloud security.

β€’ Foundational understanding of NIST 800-53 and/or NIST 800-171.

β€’ Interest in US Government and SLED cybersecurity programs (FedRAMP, GovRAMP, StateRAMP).

β€’ Experience or familiarity with ATO-focused GRC platforms such as Paramify, ServiceNow GRC, Onspring, or RegScale.

β€’ Ability to comprehend and document both policy-based and technical security controls.

β€’ Strong analytical skills, attention to detail, and comfort with structured documentation.

β€’ Excellent written and verbal communication skills.

β€’ A curious, collaborative mindset and a willingness to learn.


🏝️ Benefits

β€’ Health insurance

β€’ 401(k) matching

β€’ Paid time off

β€’ Flexible work hours

β€’ Professional development opportunities

People also viewed

Parexel18 hours ago

Regulatory Affairs Consultant – Regulatory Partner

IN flagIndia OnlyFull-timeCompliance
ApplyView job
GE Vernova18 hours ago

Senior Regulatory Affairs Licensing Engineer

US flagNorth Carolina OnlyFull-timeCompliance$111.2k – $213.2k/year
ApplyView job
Miratech18 hours ago

Compliance & Regulatory Analyst

US flagNew York OnlyFull-timeCompliance
ApplyView job
IMH18 hours ago

Senior Partner, PBM Compliance

US flagUtah OnlyFull-timeCompliance$58 – $90/hour
ApplyView job
Switzerland Global Enterprise18 hours ago

Senior Regulatory Affairs Licensing Engineer

US flagNorth Carolina OnlyFull-timeCompliance$111.2k – $213.2k/year
ApplyView job
Affirm18 hours ago

Compliance Analyst II

US flagCalifornia, +4 more statesFull-timeCompliance$88k – $140k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers