Onsite GRC Analyst: FedRAMP & Federal Compliance

NextgenID

Fairfax, Northern (VA, KY)

Hybrid

USD 75,000 - 95,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

NextgenID is hiring a GRC Analyst to manage compliance documentation, evidence, and audit support for FedRAMP, Kantara, and UK identity programs. The role is onsite at Fairfax, VA, with a strong focus on evidence, questionnaire responses, and remediation tracking.

You will own control documentation, run the operational side of certifications, and coordinate with DevSecOps and vendors to keep POA&M and vulnerability logs current. The position reports to the GRC Lead and requires U.S. citizenship.

Qualifications

  • Two or more years in GRC, security compliance, audit support, or a closely related role.
  • Working knowledge of NIST SP 800-53 and/or NIST SP 800-63, ISO 27001, or SOC 2.
  • Experience gathering evidence and maintaining compliance documentation.
  • Experience with vulnerability or POA&M tracking and remediation coordination.
  • Familiarity with vulnerability tooling (Qualys or Nessus) and evidence / GRC platforms (Vanta or similar).
  • Strong writing and documentation skills for policies, procedures, and questionnaire responses.
  • Highly organized and detail‑oriented, able to manage many concurrent items.
  • Discreet and reliable with sensitive security and compliance information.
  • Must be able to work onsite in Fairfax, VA; U.S. citizen (FedRAMP / federal customer).

Responsibilities

  • Compliance Documentation & Evidence — keep the record current and audit‑ready.
  • Maintain control documentation, policies, and procedures, and migrate evidence into Vanta.
  • Gather and organize evidence from engineering, DevSecOps, and operations leads.
  • Convert implemented controls into machine‑readable (OSCAL / JSON) format for FedRAMP submission.
  • Authorization & Assessment Support — run the operational side of our certifications.
  • Refine and maintain the UK DVS / DIATF documentation package and scoping forms.
  • Prepare Kantara assessment materials (SoCA, S3A, KAR) and the Rev 4 gap working draft.
  • Coordinate assessment and pentest logistics, scheduling, and evidence with assessors and leads.
  • Vulnerability & POA&M Tracking — keep the remediation record honest.
  • Produce the monthly POA&M from Qualys findings using the FedRAMP template.
  • Track vulnerability remediation and compensating controls with the RedTeam / DevSecOps leads.
  • Maintain vulnerability and vendor‑risk evidence logs (for example, the BeyondTrust remediation log).
  • Customer & Vendor Assurance Support — answer the questionnaires and support vendor risk.
  • Complete security questionnaires (for example, CCRA and customer InfoSec assessments) consistent with prior responses.
  • Support third‑party and vendor risk assessments and evidence requests.
  • Route completed responses to the GRC Lead and management for review before submission.
  • Research & Program Support — support the wider compliance effort.
  • Provide compliance and privacy research to the document and product teams.
  • Support ADA / Section 508 assessments and international import certification documentation (BIS, WPC, ATA Carnet).
  • Help configure and maintain GRC tooling (Vanta) and keep the compliance calendar updated.

Skills

GRC experience
Security compliance
Audit support
Evidence gathering
POA&M tracking
Vulnerability tooling
Vanta experience
Documentation writing
Discretion with sensitive info

Tools

Qualys
Nessus
Vanta
OSCAL/JSON

Job description

NextgenID is hiring a GRC Analyst to manage compliance documentation, evidence, and audit support for FedRAMP, Kantara, and UK identity programs. The role is onsite at Fairfax, VA, with a strong focus on evidence, questionnaire responses, and remediation tracking.

You will own control documentation, run the operational side of certifications, and coordinate with DevSecOps and vendors to keep POA&M and vulnerability logs current. The position reports to the GRC Lead and requires U.S. citizenship.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

GRC Lead: Federal Compliance & Risk (Onsite)
GRC Lead: Federal Compliance & Risk (Onsite)

NextgenID • Fairfax (VA), Northern (KY)

Hybrid
USD 95,000 - 120,000
GRC Analyst
GRC Analyst

NextgenID • Fairfax (VA), Northern (KY)

On-site
USD 75,000 - 95,000
GRC Lead
GRC Lead

NextgenID • Fairfax (VA), Northern (KY)

On-site
USD 95,000 - 120,000
Senior GRC Analyst - GovRAMP/FedRAMP, Remote
Senior GRC Analyst - GovRAMP/FedRAMP, Remote

Career Team • United States

Remote
USD 120,000 - 180,000
Remote work environment
Public Sector GRC Analyst - FedRAMP and Compliance
Public Sector GRC Analyst - FedRAMP and Compliance

Apply • Washington, Northern (KY)

Hybrid
USD 110,000 - 140,000
Public Sector GRC Analyst – FedRAMP & Compliance
Public Sector GRC Analyst – FedRAMP & Compliance

United States Digital Space LLC • United States

Remote
USD 90,000 - 130,000
Remote Senior Security GRC Engineer: FedRAMP/ISO 27001
Remote Senior Security GRC Engineer: FedRAMP/ISO 27001

GitLab Inc. • Northern (KY)

Hybrid
USD 140,000 - 190,000
GRC Specialist (US Citizen)
GRC Specialist (US Citizen)

Oligo Cyber Security Ltd. • Illinois

On-site
USD 120,000 - 180,000
Remote GRC Analyst: Cloud Security & Risk
Remote GRC Analyst: Cloud Security & Risk

Upwind Security, Inc. • Northern (KY)

Hybrid
USD 70,000 - 110,000
GRC Security Analyst: Compliance, Risk & Controls Lead
GRC Security Analyst: Compliance, Risk & Controls Lead

Virtru • United States

Hybrid
USD 130,000 - 170,000
Flexible PTO
Learning stipend
Team events
+4