- Own hands-on execution of governance, risk, and compliance operations for Socure’s public sector business
- Coordinate third-party assessment organization assessments and respond to auditor evidence and documentation requests
- Maintain FedRAMP and GovRAMP controls and documentation aligned with NIST SP 800-53 rev. 5 and related frameworks
- Prepare certification and authorization packages, including the System Security Plan and appendices
- Build and maintain POA&M, compliance trackers, procedures, and status-reporting artifacts
- Replace manual evidence collection with system-generated, API-driven, and continuously validated evidence
- Design and evolve automation-first continuous monitoring using integrations, telemetry, and real-time data pipelines
- Coordinate vulnerability management from identification through remediation and verification using tools such as Wiz, Burp Suite, and AWS native services
- Coordinate access reviews, incident response exercises, and contingency plan testing
- Design automated access validation mechanisms and deliver FedRAMP training programs
- Conduct internal reviews of logged events and control activities; escal gaps and report trends, risks, and remediation progress
- Develop automation-first, AI-enabled workflows and machine-readable compliance documentation such as OSCAL
- Partner with automation and engineering teams to integrate structured compliance data into risk management and monitoring systems
- Monitor regulatory and industry trends and perform gap analyses
- Support public sector sales as a security subject matter expert and create customer-facing compliance and RFP/RFx content
- Support external communications related to security certifications and authorizations
Requirements
- 4+ years of hands-on cybersecurity, compliance, or identity-management experience
- Demonstrated personal execution of FedRAMP, GovRAMP, or comparable continuous-monitoring work, including running scans, building or maintaining a POA&M, and preparing deviation requests
- Direct experience with FedRAMP, GovRAMP, and NIST frameworks (800-53, 800-63, 800-171)
- Ability to execute continuous monitoring, vulnerability remediation, and compliance reporting
- Ability to design and improve repeatable compliance processes
- Strong written communication and ability to write persuasively for a customer audience
- Ability to manage multiple priorities and adapt to changing requirements
- Demonstrated customer-facing experience and exposure to product or sales positioning
- Must be a U.S. Person (U.S. Citizen or U.S. Permanent Resident)
- Must reside in the United States
- Able to obtain a U.S. OPM NACI clearance
- Preferred: experience in regulated industries and knowledge of GDPR, CCPA, and NIST standards
- Preferred: professional certifications such as CISSP, CISM, CISA, or IAPP
- Preferred: hands-on contribution to FedRAMP, GovRAMP, and NIST 800-63/171 initiatives
- Preferred: continuous monitoring, vulnerability management, policy updates, and audit coordination experience
Core Competencies
Demonstrates expertise in governance, risk, and compliance operations, with a strong focus on FedRAMP, GovRAMP, and NIST frameworks. Capable of executing continuous monitoring, vulnerability management, and compliance reporting while effectively communicating with stakeholders.
Highest-signal resume keywords
- FedRAMP Compliance
- NIST SP 800-53
- Continuous Monitoring
- Vulnerability Management
- Cybersecurity Experience
Hard Skills
- Governance Operations
- Risk Management
- Compliance Reporting
- Automation-First Monitoring
- API-Driven Evidence Collection
- System Security Plan Preparation
- POA&M Maintenance
- Internal Review Execution
- Gap Analysis
- Incident Response Coordination
Soft Skills
- Strong Written Communication
- Persuasive Writing
- Adaptability
- Customer-Facing Experience
- Multi-Priority Management
Certifications & Qualifications
Industry Keywords
- Governance Risk Compliance
- Public Sector
- Regulated Industries
- GDPR
- CCPA
Tools & Technologies
- Wiz
- Burp Suite
- AWS Native Services
- Telemetry Integrations
- Real-Time Data Pipelines