An application made for this job — a tailored resume and cover letter that speak straight to the posting.
Onebrief is seeking a GRC Program Architect to lead the design and implementation of its GRC framework across RMF, FedRAMP, CMMC, and SOC 2, ensuring a robust control environment. You will partner with Product, Engineering, and IT to translate compliance requirements into concrete controls and evidentiary artifacts.
With 5+ years in GRC or security, you will manage third-party audits, drive integration with CI/CD pipelines, and communicate regulatory language clearly to internal teams.
Onebrief builds collaboration and AI-powered workflow software for military planning and operational coordination.
Today, many critical planning workflows still rely on fragmented systems, static documents, and disconnected tools that make collaboration and decision-making unnecessarily difficult. Onebrief brings modern software, AI, and real-time collaboration into those environments, helping teams operate with greater clarity, coordination, and adaptability in situations where decisions carry real-world consequences.
We are a distributed team of builders from military, operational, and technology backgrounds who care deeply about improving how important work gets done. Some team members work remotely, while others work directly alongside customers in operational environments around the world.
Founded in 2019, Onebrief is backed by leading investors including General Catalyst, Battery Ventures, Insight Partners, Sapphire Ventures, and Human Capital. Valued at more than $2 billion, we continue to invest in product innovation, AI capabilities, and team growth.
Onebrief sells to defense and government customers. Those customers require proof, not promises, that our systems protect their data. We need a GRC Program Architect to inform the build that proof and keep it current as our compliance obligations grow.
This role owns the architecture behind our compliance posture. FedRAMP, CMMC, SOC 2, and international frameworks each impose different controls. Someone has to translate those requirements into systems, processes, and evidence that hold up under audit. That work falls to this person.
Compliance and security engineering can't operate as separate tracks here. Controls that exist only on paper don't protect anyone and don't survive an audit. This person will work hands‑on with engineering to implement the technical controls that back up our compliance claims, not just document them after the fact.
The stakes are direct. A gap in our compliance program can block a contract, delay an authorization, or put customer data at risk. A strong program does the opposite. It opens doors to new customers and gives existing ones confidence to expand their use of our platform.
Core responsibilities:
This role will evolve as priorities change, but the outcomes below reflect what success typically looks like in the first six months.
A successful GRC Program Architect will:
Experience with GRC platforms (such as RegScale, eMASS, or similar), cloud security tooling relevant to Federal environments, logging systems, CI/CD pipelines, and infrastructure‑as‑code for control automation is a plus.