GRC Officer

penlink

$75K — $95K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 3+ years in GRC or cybersecurity compliance in SaaS/cloud environments
  • Solid knowledge of FedRAMP and NIST 800-53 controls
  • Experience with FedRAMP authorizations and audit prep
  • Familiarity with SOC 2, ISO 27001, TX-RAMP, CMMC or CJIS
  • Strong project management skills; able to juggle multiple projects
  • Effective communicator with both technical and non-technical audiences
  • U.S. Citizenship required

Responsibilities

  • Support FedRAMP program from readiness to Agency ATO
  • Develop and maintain compliance documentation like SSPs and policies
  • Coordinate with auditors and assessors during compliance checks
  • Implement and validate NIST 800-53 controls in cloud and engineering
  • Track remediation and ongoing compliance activities
  • Conduct internal reviews and risk assessments
  • Assist in vendor risk reviews and continuous monitoring efforts

Benefits

  • Hybrid work schedule with in-office requirements
  • Opportunities for professional certification
  • Supportive team atmosphere focused on compliance and security improvement
  • Work with cross-functional teams across departments
  • Engage in diverse compliance initiatives in a growing organization
Full Job Description
Description

With our get it done attitude and focused mission we are growing at an unprecedented rate and are therefore seeking a GRC Officer - Federal Compliance to support and expand our federal security compliance program. This role will help lead FedRAMP readiness and authorization efforts while partnering closely with Security, Engineering, Infrastructure, and Product teams to ensure compliance with government cybersecurity standards and regulatory frameworks.

YOUR RESPONSIBILITIES

  • Supporting the FedRAMP program from readiness through Agency ATO, including documentation, coordination, and audit preparation
  • Developing and maintaining key compliance documentation including SSPs, POA&Ms, policies, and security artifacts
  • Coordinating with internal teams, external auditors, consultants, and 3PAO assessors during compliance assessments
  • Supporting implementation and validation of NIST 800-53 security controls across cloud, engineering, and infrastructure environments
  • Tracking remediation efforts, control gaps, and ongoing compliance activities
  • Conducting internal compliance reviews, risk assessments, and gap analyses
  • Supporting additional compliance initiatives including SOC 2, ISO 27001, TX-RAMP, CMMC, and CJIS requirements
  • Assisting with vendor risk reviews, access reviews, policy governance, and continuous monitoring activities
  • Supporting external audits, certification programs, and regulatory assessments
  • Assisting with customer security questionnaires, RFPs/RFIs, and compliance-related inquiries
  • Partnering cross-functionally with Security, Engineering, Product, and Infrastructure teams to improve security and compliance processes

Requirements

YOUR COMPETENCIES & EXPERIENCE

  • 3+ years of experience in GRC, cybersecurity compliance, or regulatory compliance within SaaS, cloud, or regulated environments
  • Strong understanding of FedRAMP requirements and NIST 800-53 security controls
  • Hands-on experience supporting or managing FedRAMP authorizations, SSP development, POA&M management, and audit preparation
  • Experience supporting compliance frameworks such as SOC 2, ISO 27001, TX-RAMP, CMMC, or CJIS
  • Strong project management and organizational skills with the ability to manage multiple initiatives simultaneously
  • Experience coordinating with external auditors, assessors, consultants, or compliance partners
  • Strong written communication, documentation, and cross-functional collaboration skills
  • Ability to communicate effectively with both technical and non-technical stakeholders
  • Familiarity with AWS or Azure cloud environments preferred
  • Experience with GRC tools, compliance automation platforms, or continuous monitoring programs preferred
  • Professional certifications such as CISSP, CISM, CISA, CRISC, CCSP, CCSK, or PMP are a plus
  • U.S. Citizenship required

This position currently follows a hybrid schedule requiring two days per week in our Lincoln, Nebraska office. Onsite requirements may be adjusted based on business needs and company or departmental policy.

Similar Jobs

More Jobs at penlink

More Information Technology Jobs

Find similar GRC Officer jobs: