About the company
Abnormal AI is looking for a Federal Security and Compliance Analyst who wants to help build how modern federal compliance operates inside a fast-moving cybersecurity company.
Responsibilities
- Own assigned federal security and compliance workstreams from requirement interpretation through implementation, evidence collection, remediation, and review readiness.
- Drive recurring continuous monitoring and evidence workflows, coordinating across Security, FedOps, Engineering, IT, People Operations, GRC, and other control performers to ensure evidence is current, complete, traceable, and retained correctly.
- Support vulnerability detection and response, including reconciling findings from tools such as Wiz, Nessus, and Burp; risk-based triage; Jira routing; SLA tracking; remediation follow-through; validation; and audit-ready evidence.
- Partner with technical teams on security and compliance impact, supporting Security Impact Assessments, Significant Change Requests, control implementation decisions, and other change-management activities before changes reach production.
- Help build Abnormal's compliance-as-code program, including structured control content, JSON/YAML or other machine-readable artifacts, schema validation, evidence indexing, automation, deterministic document generation, and reusable workflows.
- Maintain accurate control, evidence, remediation, risk, and ownership records, proactively identifying gaps, aging items, dependencies, and decisions requiring escalation.
- Contribute to federal authorization and assessment artifacts, including control documentation, Security Decision Records, certification-package content, assessor requests, and continuous monitoring deliverables.
- Support federal customer assurance by providing clear, accurate compliance guidance and artifacts for customer onboarding, POVs, DDQs, RFPs, and other government or regulated customer requests.
Requirements
- 2+ years of experience in security, compliance, GRC, risk, audit, security operations, or a related discipline, preferably in a cloud, SaaS, government, or highly regulated environment.
- Working knowledge of NIST SP 800-53 and an understanding of how security controls translate into technical implementation, operational processes, and audit evidence.
- Experience with one or more core compliance operations such as evidence collection, control documentation, vulnerability remediation, risk tracking, audit support, or continuous monitoring.
- Technical curiosity and the ability to read architecture diagrams, security documentation, vulnerability findings, Jira tickets, logs, or engineering materials and turn them into clear compliance actions.
- Ability to work effectively with Security, Engineering, Infrastructure/Operations, IT, and other technical teams without needing every problem or requirement to be fully defined in advance.
- Strong written communication skills and the ability to produce documentation that is precise enough for assessors and technical teams while remaining understandable to non-technical stakeholders.
- Strong operational discipline: you can manage multiple workstreams, dependencies, owners, and deadlines while identifying problems and escalating risk early.
- A demonstrated tendency to improve the way work gets done through automation, better processes, clearer documentation, reusable templates, better data, or simpler workflows.
Conditions
- Base salary range: $114,800 — $173,250 USD
- May be eligible for bonus or incentive compensation, equity, and a comprehensive benefits package.