Overview
Own federal security and compliance workstreams for Abnormal Gov’s FedRAMP High/Class D program, from requirement interpretation through evidence, remediation, and assessment readiness. Help technical teams improve risk management and build compliance-as-code capabilities aligned with FedRAMP 20x.
What you'll do
- Own security and compliance workstreams through implementation, evidence collection, remediation, and review readiness.
- Coordinate continuous monitoring and evidence workflows across technical and business teams.
- Reconcile vulnerability findings, triage risk, route Jira tickets, track SLAs, and validate remediation.
- Support Security Impact Assessments, Significant Change Requests, and control implementation decisions.
- Build machine-readable compliance artifacts, validation, evidence indexing, and automated workflows.
- Maintain control, evidence, remediation, risk, and ownership records.
- Support authorization artifacts and federal customer compliance requests.
What you'll need
- 2+ years of experience in security, compliance, GRC, risk, audit, security operations, or a related discipline.
- Working knowledge of NIST SP 800-53.
- Experience with evidence collection, control documentation, vulnerability remediation, risk tracking, audit support, or continuous monitoring.
- Ability to interpret architecture diagrams, security documentation, vulnerability findings, Jira tickets, logs, or engineering materials.
- Strong written communication for technical and non-technical stakeholders.
- Ability to manage multiple workstreams, dependencies, owners, and deadlines.
- Demonstrated improvement of processes through automation, documentation, templates, data, or workflows.
Nice to have
- Experience with FedRAMP, FISMA, CMMC, GovRAMP, or other U.S. government security frameworks.
- Exposure to compliance-as-code, OSCAL, JSON/YAML schemas, Git workflows, or automated validation.
- Familiarity with AWS GovCloud, Wiz, Splunk, Okta, Jira, GitLab, Nessus, Burp, or cloud vulnerability platforms.
- Experience with federal authorization packages, POA&M/ConMon workflows, or 3PAO assessments.
- Basic scripting or automation experience with Python, APIs, CI/CD, or data transformation.
Details
- Remote in the United States.
- Base salary: $114,800–$173,250 USD yearly.
Read the full description and apply on the company’s own careers page.