Senior GRC Analyst - Remote, GovRAMP & SOC 2 Expert

Career Team Enterprises

Philippines

On-site

PHP 1,800,000 - 2,400,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Fully remote work

Job summary

Career TEAM seeks a Senior GRC Analyst to own core elements of our GRC program for Career EDGE. You will manage SSPs, POA&Ms, policy work, and evidence collection, while coordinating with US security and 3PAOs to support GovRAMP and FedRAMP authorizations.

You are a self-starter with 7+ years in GRC, deep knowledge of NIST 800-53, SOC 2, and risk management, and you will work fully remotely with night shifts to align with the US team.

Qualifications

  • 7+ years of hands-on GRC experience with focus on FedRAMP, GovRAMP, StateRAMP, TX-RAMP, or CMMC.
  • Experience authoring SSPs, POA&Ms, and continuous monitoring deliverables.
  • Deep knowledge of NIST 800-53, 800-171, FIPS 199/200, and SOC 2 Type II.

Responsibilities

  • Maintain and improve SSPs, policies, procedures, and standards aligned to NIST 800-53 and SOC 2.
  • Own POA&M lifecycle: tracking, aging, remediation evidence, and monitoring deliverables.
  • Manage control evidence catalog: where it lives, last refreshed, renewal timelines.
  • Coordinate with US security team and 3PAOs to support GovRAMP, FedRAMP, and state authorization.

Skills

GovRAMP
FedRAMP
NIST 800-53
SOC 2
SSPs
POA&M
Risk management
Vendor risk
Policy development
Security training
Tabletop exercises
Onboarding security
NIST 800-171
FIPS 199/200
SOC 2 Type II
CISSP
CISA
CRISC
CGRC/CAP
ISO 27001 Lead Implementer
Drata
Vanta
Hyperproof
ServiceNow GRC

Education

Bachelor's degree in Cybersecurity

Job description

Career TEAM seeks a Senior GRC Analyst to own core elements of our GRC program for Career EDGE. You will manage SSPs, POA&Ms, policy work, and evidence collection, while coordinating with US security and 3PAOs to support GovRAMP and FedRAMP authorizations.

You are a self-starter with 7+ years in GRC, deep knowledge of NIST 800-53, SOC 2, and risk management, and you will work fully remotely with night shifts to align with the US team.

Get your free, confidential resume review.
or drag and drop your file here.