SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Abnormal AI is seeking a Federal Security and Compliance Analyst to build and scale FedRAMP High/Class D security and compliance programs within a fast-moving cybersecurity company. This role sits at the intersection of security engineering, cloud operations, and federal compliance, offering meaningful ownership from day one.
Key responsibilities include owning assigned federal security and compliance workstreams from requirement interpretation through implementation and evidence collection; driving recurring continuous monitoring and evidence workflows across Security, FedOps, Engineering, IT, and other teams; supporting vulnerability detection and response by reconciling findings from tools like Wiz, Nessus, and Burp; partnering with technical teams on security impact assessments and change management; and helping build Abnormal's compliance-as-code program with structured control content and machine-readable artifacts.
You will maintain accurate control, evidence, remediation, and risk records; contribute to federal authorization and assessment artifacts including control documentation and certification packages; and support federal customer assurance through compliance guidance and artifacts for customer onboarding, POVs, DDQs, and RFPs.
Required qualifications include 2+ years in security, compliance, GRC, risk, audit, or security operations (preferably in cloud, SaaS, government, or regulated environments); working knowledge of NIST SP 800-53 and how security controls translate to technical implementation and audit evidence; experience with evidence collection, control documentation, vulnerability remediation, risk tracking, or continuous monitoring; technical curiosity to read architecture diagrams and engineering materials; ability to work effectively with Security, Engineering, Infrastructure, and IT teams; strong written communication for both assessors and non-technical stakeholders; and demonstrated ability to improve processes through automation and better workflows.
Nice-to-have skills include experience with FedRAMP High/Moderate, FISMA, CMMC, or other U.S. government security frameworks; exposure to compliance-as-code, OSCAL, JSON/YAML schemas, Git workflows, or machine-readable authorization artifacts; familiarity with AWS GovCloud, Wiz, Splunk, Okta, Jira, GitLab, Nessus, Burp, or cloud-native vulnerability management platforms; and experience with Security Impact Assessments, Significant Change Requests, POA&M/ConMon workflows, or 3PAO assessments.