SlipstreamJobsFresh Startup & VC-Backed Jobs

GRC Analyst - Public Sector

Socure - Washington, DC, United States - In-office - posted 2026-09-11

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Socure is building identity trust infrastructure for the digital economy, verifying identities in real time and stopping fraud. The company is seeking a GRC Analyst – Public Sector to own hands-on execution of governance, risk, and compliance operations for the public sector business. Reporting to the Director of GRC – Public Sector, this role is responsible for day-to-day FedRAMP/GovRAMP continuous monitoring, building and maintaining POA&M and compliance trackers to keep the program audit-ready, and coordinating access reviews, vulnerability remediation, and evidence collection across Security, Engineering, IT, DevOps, Product, Legal, and other teams. Key responsibilities include: **Compliance & Certification Management:** Coordinate Third Party Assessment Organization (3PAO) assessments and respond to auditor requests. Maintain FedRAMP and GovRAMP controls and documentation aligned with NIST SP 800-53 rev 5 and related frameworks. Prepare certification and authorization packages including System Security Plans (SSP). Replace manual evidence collection with system-generated, API-driven, or continuously validated evidence. **Continuous Monitoring & Vulnerability Management:** Design and evolve an automation-first continuous monitoring program leveraging system integrations and real-time data pipelines. Lead day-to-day FedRAMP continuous monitoring including vulnerability management lifecycle, coordinating with teams to address issues identified through tools like Wiz, Burp Suite, and AWS native services. Coordinate recurring compliance activities such as access reviews and incident response exercises. **Access Management & Training:** Design scalable and automated access validation mechanisms. Design, implement, and deliver FedRAMP training programs. Create and manage automated workflows to improve efficiency. **Audit & Assessment Readiness:** Transform compliance evidence into dynamic, system-driven models supporting real-time audit readiness. Conduct internal reviews of logged events and control activities, escalating issues to leadership and providing status updates highlighting trends, risks, and remediation progress. **Process Improvement & Collaboration:** Collaborate to design automation-first and AI-enabled workflows. Support development of machine-readable compliance documentation (e.g., OSCAL). Partner with automation and engineering teams to integrate compliance data into broader risk management ecosystems. **Public Sector Sales & Customer Engagement:** Serve as security subject matter expert for public sector sales, translating compliance controls into compelling customer-facing narratives. Support development of external communications related to security certifications. Build and maintain scalable response frameworks for RFP and RFx responses. **Monitor Evolving Requirements:** Track updates to NIST Special Publications, government standards, contract security requirements, and FedRAMP program changes. Perform gap analyses and provide input to standards bodies when applicable. As the Analyst builds fluency in operational fundamentals, the role grows to include drafting customer-facing compliance and RFP response content and pursuing automation-first, system-driven improvements including machine-readable formats and AI-enabled workflows. **Requirements:** - 4+ years of hands-on cybersecurity, compliance, or identity-management experience, including demonstrated personal execution of FedRAMP, GovRAMP, or comparable continuous-monitoring work (running scans, building/maintaining POA&M, preparing deviation requests). Public sector experience is a plus but not required. - Direct experience with FedRAMP, GovRAMP, and NIST frameworks (800-53, 800-63, 800-171). - Proven ability to personally execute continuous monitoring, vulnerability remediation, and compliance reporting. - Proven ability to design and improve repeatable compliance processes—identifying inefficiencies, defining clear steps, and building structure where none exists. Experience using AI tools (ChatGPT, Glean, Gemini) and machine-readable formats (OSCAL) to accelerate this work is a strong plus. - Strong communication, organization, and collaboration skills with ability to manage multiple priorities, including strong written communication and ability to write persuasively for customer audiences. - Ability to adapt to changing requirements. - Demonstrated customer-facing experience and exposure to product or sales positioning to distinguish compliance-accurate writing from persuasive buyer-focused writing. Prior RFP-specific experience not required. - Must be a U.S. Person (U.S. Citizen or U.S. Permanent Resident) residing in the United States and able to obtain a U.S. OPM NACI clearance. **Preferred Qualifications:** - Experience in regulated industries (financial services, healthcare) and knowledge of privacy and compliance frameworks such as GDPR, CCPA, and key NIST standards. - Professional certifications (CISSP, CISM, CISA, IAPP). - Proven hands-on contribution to certification and compliance initiatives (FedRAMP, GovRAMP, NIST 800-63/171). - Skilled in continuous monitoring, vulnerability management, policy updates, and audit coordination across cross-functional teams. Demonstrated track record of identifying and closing process gaps proactively. - Strong understanding of evolving cybersecurity standards and digital identity regulations with ability to translate them into practical risk and compliance improvements.

Similar roles