yoinka

GRC Analyst - Public Sector

Socure

RemoteHub - Washington DCFull TimeMidH-1B sponsor company
Sign in to applyVerified 2h ago
Location
Hub - Washington DC
Employment
Full Time
Work model
Remote
Level
Mid
H-1B history
5 approvals (FY2023)
Posted
2h ago

Skills

AWSCybersecurity

About this role

Why Socure? Socure is building the identity trust infrastructure for the digital economy — verifying 100% of good identities in real time and stopping fraud before it starts. The mission is big, the problems are complex, and the impact is felt by businesses, governments, and millions of people every day. We hire people who want that level of responsibility. People who move fast, think critically, act like owners, and care deeply about solving customer problems with precision. If you want predictability or narrow scope, this won’t be your place. If you want to help build the future of identity with a team that holds a high bar for itself — keep reading.

Overview

Socure is seeking an Analyst, GRC – Public Sector to own the hands-on execution of the company’s governance, risk, and compliance operations for its public sector business. Reporting to the Director of GRC – Public Sector, this role is responsible day-to-day for running FedRAMP/GovRAMP continuous monitoring, building and maintaining the POA&M and compliance trackers that keep the program audit-ready, and coordinating access reviews, vulnerability remediation, and evidence collection with Security, Engineering, IT, DevOps, Product, Legal, and other teams. As the Analyst builds fluency in these operational fundamentals, the role grows to include drafting customer-facing compliance and RFP response content that makes Socure’s security posture compelling to public sector buyers, and pursuing automation-first, system-driven improvements, including machine-readable formats like OSCAL and AI-enabled workflows, that reduce manual effort and challenge how the team has traditionally done this work. Role and Responsibilities Compliance & Certification Management Day-to-day coordination and execution of externalThird Party Assessment Organization (3PAO) assessments and responding to auditor requests for evidence and documentation. Maintain and update FedRAMP and GovRAMP controls and documentation in alignment with organizational and regulatory requirements, including controls aligned with NIST SP 800-53 rev 5 and other related frameworks. Prepare certification and authorization packages and maintain related documentation such as the System Security Plan (SSP) and associated appendices. Replace manual evidence collection with system-generated, API-driven, or continuously validated evidence where possible. Build and maintain the trackers, procedures, and status-reporting artifacts that operationalize this work, structured so other stakeholders can use them directly. Continuous Monitoring & Vulnerability Management Design and evolve an automation-first continuous monitoring program leveraging system integrations, telemetry, and real-time data pipelines Lead the day-to-day FedRAMP continuous monitoring process including vulnerability management lifecycle, from identification through remediation and verification, coordinating with Security, Engineering, and DevOps teams to address issues identified with tools such as Wiz, Burp Suite, AWS native services, and other platforms and resolve issues within FedRAMP and GovRAMP timelines. Coordinate recurring continuous monitoring compliance activities such as access reviews, incident response exercises, and contingency plan testing. Access Management & Training Design scalable and automated access validation mechanisms integrated with identity and infrastructure systems Design, implement and deliver FedRAMP training programs to promote compliance awareness Create and manage automated workflows to improve efficiency. Audit & Assessment Readiness Transform compliance evidence from static repositories into dynamic, system-driven evidence models supporting real-time audit readiness Conduct internal reviews of logged events and control activities, escalating issues or gaps to the Director of GRC and provide status updates and reports highlighting trends, risks, and remediation progress. Process Improvement & Collaboration Collaborate

Listing verified 2h ago. Applications go through the company's official careers site.

← Back to Yoinka

GRC Analyst - Public Sector at Socure, Hub - Washington DC | Yoinka