This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Are you interested in helping shape how cybersecurity works across the US public sector while building a strong foundation in Trust, Risk, and Compliance (TRC)? This role offers the opportunity to grow your career while contributing directly to Rapid7’s mission of making the digital world safer. As a Trust, Risk, and Compliance Analyst, you will support Rapid7’s expanding US Public Sector compliance programs, including FedRAMP, GovRAMP, TX-RAMP, and COV-RAMP. As part of the Trust, Risk, and Compliance team within the broader Information Security organization, you will help build, operate, and continuously improve scalable compliance and risk management programs that enable our Federal and SLED customers to succeed.
Job Responsibility:
Support day-to-day activities for Rapid7’s US Public Sector compliance programs, with a primary focus on FedRAMP
Assist in maintaining compliance documentation, including policies, procedures, system security plans (SSPs), authorization artifacts, and supporting evidence
Support continuous monitoring (ConMon) activities, including ongoing evidence collection and reporting
Assist in managing Plans of Action & Milestones (POA&Ms), including tracking remediation progress, timelines, and risk ownership
Track and support control implementation aligned to NIST 800-53 rev. 5 and NIST 800-171
Use ATO-focused GRC platforms such as Paramify, ServiceNow GRC, Onspring, or RegScale to manage compliance status, risks, and findings
Partner with Engineering and Security teams to understand technical control implementations, vulnerabilities, and remediation plans
Support audit and assessment readiness activities, including ATO packages and regulatory reporting
Assist with vendor reviews, including Control Implementation Summaries (CIS) and Customer Responsibility Matrices (CRM)
Help identify opportunities to improve GRC, POA&M, and ConMon processes through standardization, automation, and improved data quality
Gain hands-on exposure to evolving requirements such as CMMC, new Executive Orders, and emerging US public sector cybersecurity initiatives
Requirements:
2-5 years of experience (or equivalent academic, internship, or early-career experience) in cybersecurity, risk, compliance, governance, or cloud security
Foundational knowledge of NIST 800-53 and/or NIST 800-171
Interest in US Government and SLED cybersecurity programs (FedRAMP, GovRAMP, StateRAMP)
Experience or familiarity with ATO-focused GRC platforms such as Paramify, ServiceNow GRC, Onspring, or RegScale
Ability to understand and document both policy-based and technical security controls
Strong analytical skills, attention to detail, and comfort working with structured documentation
Clear written and verbal communication skills
A curious, collaborative mindset and eagerness to learn
Nice to have:
Exposure to AWS or cloud-based environments
Familiarity with vulnerability management, security scanning, or cloud security concepts
Experience or interest in POA&M workflows, continuous monitoring, or risk remediation
Familiarity with frameworks such as FISMA, CMMC, StateRAMP, or ISO 27001
Interest in compliance automation, OSCAL, or policy-as-code approaches
Early-career certifications or coursework in cybersecurity, cloud security, or information assurance