GRC Analyst - FedRAMP & RMF Compliance Expert

C2 Labs, Inc.

Knoxville (TN)

On-site

USD 65,000 - 90,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

C2 Labs, Inc. is seeking a Governance Risk and Compliance (GRC) Analyst to join our security team in Knoxville. You will implement regulatory frameworks (FISMA, FedRAMP, StateRAMP), develop security documentation (SSP, SAP, SAR), and maintain RMF artifacts for FedRAMP cloud environments.

Strong writing and client-facing skills are essential. The role emphasizes creating clear security control statements, coordinating with engineers, and delivering risk assessments and training.

Qualifications

  • 1–3 years in IT consulting focusing on RMF.
  • US Citizenship and ability to pass a Public Trust background check.
  • Strong communication and technical writing skills.
  • Familiarity with NIST 800-53, FedRAMP, and StateRAMP.

Responsibilities

  • Develop, review, and update security authorization package documentation (SSP, SAP, SAR, POA&M).
  • Develop, review, and update Contingency Plan (CP), Incident Response Plan (IRP), and Configuration Management Plan (CMP).
  • Conduct Security Impact Assessments (SIAs) on information systems changes.
  • Create the Control Implementation Summary and CRM workbook outlining CSP and customer responsibilities.
  • Develop and update policies aligning with NIST 800-53 controls.
  • Leverage GRC tools to automate SSP creation.
  • Review current RMF processes and provide improvement recommendations.
  • Develop and deliver Risk Assessment Reports (RAR).
  • Provide guidance on FedRAMP and StateRAMP control requirements.
  • Deliver training on RMF tasks to stakeholders.

Skills

RMF familiarity
FedRAMP knowledge
GRC documentation
Technical writing
Client communication

Education

Security certifications (CISSP/CISM/CAP)

Tools

GRC tools
NIST templates

Job description

C2 Labs, Inc. is seeking a Governance Risk and Compliance (GRC) Analyst to join our security team in Knoxville. You will implement regulatory frameworks (FISMA, FedRAMP, StateRAMP), develop security documentation (SSP, SAP, SAR), and maintain RMF artifacts for FedRAMP cloud environments.

Strong writing and client-facing skills are essential. The role emphasizes creating clear security control statements, coordinating with engineers, and delivering risk assessments and training.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Remote GRC Engineer: CMMC & FedRAMP Expert
Remote GRC Engineer: CMMC & FedRAMP Expert

Jobgether • United States

Remote
USD 110,000 - 170,000
Remote-first culture
Mentorship & career development
Training & certification reimbursement
+4
GRC Analyst
GRC Analyst

C2 Labs, Inc. • Knoxville (TN)

On-site
USD 65,000 - 90,000
Federal GRC Engineer - FedRAMP & NIST 800-53
Federal GRC Engineer - FedRAMP & NIST 800-53

Workstreet • Northern (KY)

Hybrid
USD 90,000 - 130,000
Remote-first culture
Federal GRC Engineer — CMMC & FedRAMP Specialist
Federal GRC Engineer — CMMC & FedRAMP Specialist

Workstreet • Northern (KY)

Hybrid
USD 120,000 - 180,000
Remote-first culture
Career development
Training reimbursement
GRC Program Architect: Federal Compliance & Security Controls
GRC Program Architect: Federal Compliance & Security Controls

Onebrief • United States

Hybrid
USD 150,000 - 230,000
GRC Analyst: FedRAMP, SOC 2 & CMMC Compliance Lead
GRC Analyst: FedRAMP, SOC 2 & CMMC Compliance Lead

Virtru • United States

On-site
USD 130,000 - 170,000
Flexible PTO
$1,500 learning & development stipend
Team celebrations
+4
GRC Engineer: CMMC & FedRAMP Specialist (Remote)
GRC Engineer: CMMC & FedRAMP Specialist (Remote)

Workstreet • United States

On-site
USD 90,000 - 130,000
Career Development
Training reimbursement
Competitive compensation
+2
Security GRC Lead
Security GRC Lead

Jobtailor • Washington

On-site
USD 150,000 - 190,000
Onsite GRC Analyst: FedRAMP & Federal Compliance
Onsite GRC Analyst: FedRAMP & Federal Compliance

NextgenID • Fairfax (VA), Northern (KY)

Hybrid
USD 75,000 - 95,000
Senior GRC Architect: Federal Compliance & Security
Senior GRC Architect: Federal Compliance & Security

Socket.dev • United States

On-site
USD 140,000 - 190,000