
Senior Security Compliance Engineer, Public Sector
Posted 16 hours ago

Posted 16 hours ago
This is a fully remote position, open to applicants in United States.
β’ Design, execute, and oversee GRC strategies and processes that align with FedRAMP, IRAP, and other regulatory and industry standards.
β’ Collaborate with highly regulated clients to comprehend compliance needs and deliver customized solutions.
β’ Lead and coordinate security evaluations, audits, and certification procedures.
β’ Assist GitLab Dedicated for Government in fulfilling FedRAMP continuous monitoring obligations.
β’ Work in conjunction with IT, Product, Engineering, Security, and Legal teams to embed GRC requirements into operations and technology frameworks.
β’ Create and uphold policies, procedures, controls, and other compliance-related documentation.
β’ Automate GRC processes and implement compliance-as-code or policy-as-code solutions utilizing scripting and coding expertise.
β’ Track regulatory modifications and industry developments to enhance the GRC program and ensure compliance.
β’ Provide GRC training and support to internal teams and clients.
β’ Act as a GRC subject matter expert, advising senior management and stakeholders.
β’ Valid proof of U.S. citizenship and residency.
β’ Bachelorβs degree in Computer Science, Information Technology, Cybersecurity, or equivalent experience in a relevant field.
β’ At least 5 years of experience in GRC, cybersecurity, or a related domain, particularly in highly regulated industries.
β’ Demonstrated experience in achieving and maintaining security certifications such as FedRAMP, CMMC, SOC 2, IRAP, ISO 27001, among others.
β’ Strong comprehension of regulatory and compliance obligations for the public sector and highly regulated sectors.
β’ Knowledge of implementing compliance-as-code or policy-as-code, as well as automating control testing and evidence gathering.
β’ Fundamental understanding of FedRAMP requirements, processes, and documentation.
β’ Familiarity with cloud hyperscaler services like AWS and GCP.
β’ Exceptional analytical, problem-solving, and project management abilities.
β’ Strong communication and interpersonal skills, capable of collaborating with internal teams, auditors, clients, and regulatory entities.
β’ Ability to work autonomously and manage multiple projects concurrently in a fast-paced setting.
β’ Relevant certifications such as CISSP, CISM, CISA, or similar are highly advantageous.
β’ Benefits designed to support your health, financial needs, and overall well-being.
β’ Flexible Paid Time Off.
β’ Team Member Resource Groups.
β’ Equity Compensation & Employee Stock Purchase Plan.
β’ Growth and Development Fund.
β’ Parental Leave.
Eli Lilly and Company
Cisco
Planet Technologies
McKesson
Get handpicked remote jobs straight to your inbox weekly.