This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Socure is seeking an Analyst, GRC – Public Sector to execute and enhance the company’s governance, risk, and compliance operations for its public sector business. This role drives measurable improvements in compliance efficiency and audit readiness by managing vulnerability remediation, continuous monitoring, access oversight, and evidence preparation that allow Socure to meet the rigorous standards of FedRAMP, GovRAMP, and related frameworks.
Job Responsibility:
Day-to-day coordination and execution of external Third Party Assessment Organization (3PAO) assessments and responding to auditor requests for evidence and documentation
Maintain and update FedRAMP and GovRAMP controls and documentation in alignment with organizational and regulatory requirements
Prepare certification and authorization packages and maintain related documentation such as the System Security Plan (SSP) and associated appendices
Lead the day-to-day FedRAMP continuous monitoring process including vulnerability management lifecycle
Coordinate recurring continuous monitoring compliance activities such as access reviews, incident response exercises, and contingency plan testing
Oversee access controls for FedRAMP environments
Design, implement and deliver FedRAMP training programs
Create and manage automated workflows to improve efficiency
Maintain compliance evidence repositories
Conduct internal reviews of logged events and control activities
Collaborate to design and implement AI-enabled compliance workflows
Support the development, rollout, and maintenance of machine-readable compliance documentation
Partner with automation and engineering teams to integrate structured compliance data
Monitor regulatory and industry trends for potential impacts to compliance strategy
Serve as a security subject matter expert for public sector sales activities
Support development of external communications related to security certifications and authorizations
Monitor new and evolving requirements and perform gap analyses
Provide input to standards bodies on evolving standards when applicable
Requirements:
5+ years of cybersecurity or identity management experience, including 1+ year in the public sector
Direct experience with FedRAMP, GovRAMP, and NIST frameworks (800-53, 800-63, 800-171)
Proven ability to manage continuous monitoring, vulnerability remediation, and compliance reporting
Experience using AI tools (e.g., ChatGPT, Glean, Gemini) and machine-readable formats (e.g., OSCAL) to automate and streamline compliance processes
Strong communication, organization, and collaboration skills with the ability to manage multiple priorities
Ability to adapt to changing requirements
Must be a U.S. Person (U.S. Citizens or U.S. Permanent Residents) residing in the United States and be able to obtain a U.S. OPM NACI clearance
Nice to have:
Experience in regulated industries (e.g., financial services, healthcare) and knowledge of privacy and compliance frameworks such as GDPR, CCPA, and key NIST standards
Professional certifications preferred (CISSP, CISM, CISA, IAPP)
Proven success leading certification and compliance initiatives (FedRAMP, GovRAMP, NIST 800-63/171)
Skilled in continuous monitoring, vulnerability management, policy updates, and audit coordination across cross-functional teams
Strong understanding of evolving cybersecurity standards and digital identity regulations, with the ability to translate them into practical risk and compliance improvements
What we offer:
Equity
Comprehensive benefits
Annual discretionary performance bonus or commissions plans