Onebrief

Program Architect - Governance, Risk, and Compliance

Full-time · +1 more
✓ Verified live on the employer's own system · added 11 days ago
Save search
Mid-level · 5+ yrs exp

Requirements

Experience: 5+ years

Skills & tools

EmbeddedSecurityManagementCommunicationsCloud PlatformsDevopsScriptingRecruiting
Apply on company site ↗ See your fit → free

Full job description

WHAT YOU'LL DO Core

responsibilities: - Own the design and implementation of Onebrief's GRC framework across RMF, FedRAMP, CMMC, SOC 2, and other applicable standards. - Build and manage the control environment, including policies, procedures, and evidence collection systems. - Design and implement technical security controls in partnership with Product, Engineering, Infrastructure and Corporate IT including access management, logging, encryption, and vulnerability management practices. - Partner with Engineering, Infrastructure, and Corporate IT to translate compliance requirements into working technical controls, not just documented ones.

MINIMUM

QUALIFICATIONS - 5+ years of experience in GRC, security engineering, or a combined compliance and technical security role - Direct experience with RMF, FedRAMP, CMMC, or equivalent federal compliance frameworks - Hands-on experience implementing technical security controls, such as IAM, logging and monitoring, network segmentation, or encryption - Working knowledge of security control frameworks such as NIST 800-53 or NIST 800-171 - Experience managing third-party audits and assessor relationships - Strong written communication skills, with the ability to translate regulatory language into clear technical and internal guidance

PREFERRED

QUALIFICATIONS - Experience in a startup or scaling company environment - Background in military, defense, or government contracting - Relevant certifications, such as CISSP, CISA, CRISC, or a technical security certification (AWS Solutions Architect) - Experience building GRC automation using infrastructure-as-code or scripting INDICATORS OF SUCCESS This role will evolve as priorities change, but the outcomes below reflect what success typically looks like in the first six months.

A successful GRC Program Architect will: - Identify and remediate at least one significant security control gap before it surfaces in an external audit - Serve as the trusted point of contact for customer security questionnaires and compliance inquiries - Be recognized by engineering and security teams as a partner who makes compliance workable and technically sound, not just another gate to pass - Win buy-in from engineering leads who previously treated compliance requests as low priority - Get through a customer or third-party security review without escalations or fire drills TOOLS, SYSTEMS & TECHNOLOGIES (OPTIONAL) Experience with GRC platforms (such as RegScale, eMASS, or similar), cloud security tooling relevant to Federal environments, logging systems, CI/CD pipelines, and infrastructure-as-code for control automation is a plus.

More jobs at Onebrief

Similar jobs near +1 more

Tell me when more Senior Director, AI Risk and Compliance jobs post near Remote, GA We re-check every listing against the employer’s own board — no résumé needed.

Search Program Architect - Governance, Risk, and Compliance jobs near +1 more → Browse all live jobs

This posting was published by Onebrief on their own careers system and is shown here with a direct link to apply there. Employers: for corrections or removal, contact jobs@veritahire.com.