SlipstreamJobsFresh Startup & VC-Backed Jobs

Program Architect - Governance, Risk, and Compliance

Onebrief - Remote - Remote - posted 2026-07-29

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Onebrief builds AI-powered collaboration and workflow software for military planning and operational coordination. The company serves defense and government customers who require rigorous compliance and security posture. This role owns the architecture and implementation of Onebrief's governance, risk, and compliance (GRC) program across multiple federal frameworks including FedRAMP, CMMC, SOC 2, and RMF. You will design and implement the control environment—policies, procedures, and evidence collection systems—that translate regulatory requirements into working technical controls. This is not a documentation-only role; you'll work hands-on with Engineering, Infrastructure, and Product teams to implement technical security controls including access management, logging, encryption, and vulnerability management. You'll manage the control framework, serve as the trusted point of contact for customer security questionnaires and compliance inquiries, and partner with engineering leads to make compliance workable and technically sound rather than a gate to pass. Key responsibilities include owning the design and implementation of the GRC framework, building and managing the control environment, designing and implementing technical security controls in partnership with engineering teams, and managing third-party audits and assessor relationships. Success in the first six months means identifying and remediating significant security control gaps before external audits, earning buy-in from engineering teams, and getting through customer and third-party security reviews without escalations. You bring 5+ years of experience in GRC, security engineering, or a combined compliance and technical security role. You have direct experience with RMF, FedRAMP, CMMC, or equivalent federal compliance frameworks, hands-on experience implementing technical security controls (IAM, logging, network segmentation, encryption), and working knowledge of NIST 800-53 or NIST 800-171. You've managed third-party audits and have strong written communication skills to translate regulatory language into clear technical guidance. Preferred qualifications include startup or scaling company experience, military/defense/government contracting background, relevant certifications (CISSP, CISA, CRISC, AWS Solutions Architect), and experience with GRC automation using infrastructure-as-code or scripting.

Similar roles