GRC Program Architect: Federal Compliance & Security Controls

Onebrief

United States

Hybrid

USD 150,000 - 230,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Onebrief is seeking a GRC Program Architect to lead the design and implementation of its GRC framework across RMF, FedRAMP, CMMC, and SOC 2, ensuring a robust control environment. You will partner with Product, Engineering, and IT to translate compliance requirements into concrete controls and evidentiary artifacts.

With 5+ years in GRC or security, you will manage third-party audits, drive integration with CI/CD pipelines, and communicate regulatory language clearly to internal teams.

Qualifications

  • 5+ years of experience in GRC, security engineering, or a combined compliance and technical security role.
  • Direct experience with RMF, FedRAMP, CMMC, or equivalent federal compliance frameworks.
  • Hands-on experience implementing technical security controls, such as IAM, logging and monitoring, network segmentation, or encryption.
  • Working knowledge of security control frameworks such as NIST 800-53 or NIST 800-171.
  • Experience managing third-party audits and assessor relationships.
  • Strong written communication skills, with the ability to translate regulatory language into clear technical and internal guidance.

Responsibilities

  • Own the design and implementation of Onebrief's GRC framework across RMF, FedRAMP, CMMC, SOC 2, and other applicable standards.
  • Build and manage the control environment, including policies, procedures, and evidence collection systems.
  • Design and implement technical security controls in partnership with Product, Engineering, Infrastructure and Corporate IT including access management, logging, encryption, and vulnerability management practices.
  • Partner with Engineering, Infrastructure, and Corporate IT to translate compliance requirements into working technical controls, not just documented ones.

Skills

GRC experience
Security engineering
Compliance & security
Audits
Regulatory frameworks
CI/CD security
NIST standards
Third-party audits
Written communication
Infrastructure as code

Tools

RegScale
eMASS

Job description

Onebrief is seeking a GRC Program Architect to lead the design and implementation of its GRC framework across RMF, FedRAMP, CMMC, and SOC 2, ensuring a robust control environment. You will partner with Product, Engineering, and IT to translate compliance requirements into concrete controls and evidentiary artifacts.

With 5+ years in GRC or security, you will manage third-party audits, drive integration with CI/CD pipelines, and communicate regulatory language clearly to internal teams.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior GRC Architect: Federal Compliance & Security
Senior GRC Architect: Federal Compliance & Security

Socket.dev • United States

On-site
USD 140,000 - 190,000
Senior Program Architect - Governance, Risk, and Compliance
Senior Program Architect - Governance, Risk, and Compliance

Socket.dev • United States

On-site
USD 140,000 - 190,000
Program Architect - Governance, Risk, and Compliance
Program Architect - Governance, Risk, and Compliance

Onebrief • United States

Hybrid
USD 150,000 - 230,000
Senior Security GRC Lead - Multi-Framework Compliance
Senior Security GRC Lead - Multi-Framework Compliance

Jobgether • United States

On-site
USD 150,000 - 210,000
High autonomy
Multi-framework exposure
Cloud environment experience
Remote GRC Engineer: CMMC & FedRAMP Expert
Remote GRC Engineer: CMMC & FedRAMP Expert

Jobgether • United States

Remote
USD 110,000 - 170,000
Remote-first culture
Mentorship & career development
Training & certification reimbursement
+4
Senior GRC Security Architect — Build Core Trust (SaaS)
Senior GRC Security Architect — Build Core Trust (SaaS)

Gong • Chicago (IL)

On-site
USD 121,000 - 185,000
Medical, dental, and vision plans
Wellbeing Fund
Mental health benefits
+6
GRC Officer
GRC Officer

penlink • Lincoln (NE)

Hybrid
USD 110,000 - 150,000
GRC Engineering Manager: Lead Secure Cloud Compliance
GRC Engineering Manager: Lead Secure Cloud Compliance

Workstreet • Northern (KY)

Hybrid
USD 150,000 - 190,000
Career Development
Role-Related Training
Competitive Compensation
+2
GRC & Security Compliance Lead
GRC & Security Compliance Lead

Neura Market • San Francisco (CA)

On-site
USD 140,000 - 190,000
Equity
Medical, dental, and vision coverage
Flexible PTO
+4
Senior GRC Architect: FedRAMP/ITAR/TISAX on AWS - Remote
Senior GRC Architect: FedRAMP/ITAR/TISAX on AWS - Remote

United States Digital Space LLC • United States

Remote
USD 150,000 - 230,000
Remote work flexibility
Health coverage and retirement plans
Paid time off and wellness programs
+1