← Все вакансии/jobgether
RemoteUS

GRC Engineer

J
jobgether
Формат
Remote
О роли

Описание вакансии

About the company

Our partner is looking for a GRC Engineer (CMMC) based in the United States. This role offers the opportunity to help organizations strengthen cybersecurity and achieve demanding federal and defense compliance standards.

Responsibilities
  • Analyze and apply NIST SP 800-53 controls and FedRAMP Moderate and High baselines to assess client architectures against federal security requirements.
  • Advise defense contractor clients on CMMC 2.0 and NIST SP 800-171 requirements, translating regulatory expectations into practical and actionable security milestones.
  • Author, maintain, and evaluate key compliance and authorization artifacts, including System Security Plans (SSPs), control implementation narratives, Plans of Action and Milestones (POA&Ms), Security Assessment Plans (SAPs), and Security Assessment Reports (SARs).
  • Conduct detailed readiness assessments and gap analyses to prepare clients for federal Authority to Operate (ATO), Joint Authorization Board (JAB), and CMMC assessment pathways.
  • Define and document technical authorization boundaries, data flows, interconnectivity, and shared-responsibility models across FedRAMP and CMMC environments.
  • Execute continuous monitoring activities, including vulnerability management tracking, incident response documentation, structural change workflows, and recurring compliance updates.
  • Coordinate external assessment activities between clients, Cloud Service Providers, 3PAOs, C3PAOs, and relevant federal stakeholders.
  • Develop structured compliance documentation and assessment-readiness materials for CMMC Level 1 and Level 2 engagements.
  • Manage multiple client compliance initiatives simultaneously while maintaining strong documentation quality, deadlines, and delivery standards.
  • Serve as a trusted client advisor, communicating complex security and compliance concepts clearly and helping stakeholders navigate evolving requirements.
  • Stay current with changes to federal cybersecurity frameworks, regulatory requirements, cloud security practices, and defense compliance standards.
Requirements
  • 2+ years of direct experience in GRC, cybersecurity compliance, or related roles with hands-on exposure to FedRAMP, NIST SP 800-53, NIST SP 800-171, or federal authorization lifecycles.
  • Practical experience authoring, evaluating, and maintaining federal compliance artifacts, particularly SSPs and POA&Ms.
  • Foundational knowledge of CMMC 2.0 and NIST SP 800-171 requirements as they apply to defense contractors and Controlled Unclassified Information (CUI).
  • Familiarity with DFARS requirements and CUI protection practices is strongly valued.
  • Experience working with government cloud environments such as AWS GovCloud, Azure Government, or Microsoft GCC High.
  • Understanding of cloud shared-responsibility models, technical security boundaries, data flows, and secure configurations.
  • Experience supporting B2B SaaS providers, federal contractors, regulated technology organizations, or comparable clients.
  • Strong project management and organizational skills, with the ability to manage several fast-moving compliance initiatives while maintaining attention to detail.
  • Excellent written and verbal English communication skills, with confidence engaging directly with technical teams, clients, assessors, and other stakeholders.
  • Ability to translate complex regulatory and technical requirements into clear, actionable guidance.
  • Comfortable operating independently in a fast-growing consulting environment where priorities can evolve quickly and ownership is expected.
  • CMMC credentials such as Registered Practitioner (RP), Certified Professional (CCP), or Certified Assessor (CCA) are advantageous.
  • Certifications such as CISSP, CISM, or CompTIA Security+ are a plus.
  • Direct experience supporting JAB or federal Agency ATO processes is highly valued.
  • Previous collaboration with 3PAO or C3PAO assessment teams is beneficial.
  • Must be authorized to work in the United States without current or future visa sponsorship.
  • Able to work a standard schedule of 8:00 AM–5:00 PM U.S. Eastern Time, with occasional flexibility as business needs require.
  • Willingness to travel locally for occasional onsite meetings, team gatherings, or business activities.
  • Reliable high-speed internet and a professional home-office environment suitable for confidential client work and virtual collaboration.
Conditions
  • Competitive base salary with regular performance reviews and merit-based appraisal opportunities.
  • Bonus opportunities based on performance.
  • Remote-first culture with the flexibility to work from anywhere in the United States.
  • Mentorship, training, and structured career development opportunities.
  • Reimbursement for approved role-related training and professional certification courses.
  • Opportunity to deepen expertise across CMMC, NIST, FedRAMP, and federal cybersecurity compliance.
  • Growth opportunities within a fast-paced, early-stage environment.
  • Collaborative culture with exposure to complex cybersecurity and compliance engagements.
Стек и навыки

С чем работаем