Full Job Description
Knox is seeking a Senior Compliance Analyst with strong technical and regulatory expertise to help ensure Knox and its customers continuously meet federal and commercial compliance requirements. This role is responsible for driving ongoing compliance across FedRAMP, FISMA, NIST 800-53, IL4, IL5, CMMC, SOC 2, StateRamp, and GovRAMP environments while partnering closely with Security, DevOps, Operations, and customer teams.
This is not a point-in-time audit support role. This position is expected to operate as a technical compliance lead who can validate controls in cloud environments, track remediation and POA&M performance, enforce compliance SLAs, support audits and assessments, and provide clear risk visibility to internal leadership and customers.
Key Responsibilities
• Own continuous compliance oversight for Knox and assigned customer environments across FedRAMP, FISMA, NIST 800-53, IL4, IL5, CMMC, SOC 2, StateRamp, GovRAMP, and related frameworks.
• Track and enforce compliance obligations, remediation deadlines, POA&M milestones, vulnerability remediation timelines, and continuous monitoring requirements.
• Review and validate technical control implementation across AWS, Azure, and GCP environments, including logging, monitoring, IAM, incident response, vulnerability management, endpoint security, network segmentation, and change management.
• Partner with Security Operations, Compliance, DevOps, Engineering, and customer teams to ensure required controls are implemented and operating effectively.
• Support FedRAMP authorization and ongoing assessment activities, including SSP updates, evidence collection, ConMon support, 3PAO coordination, audit preparation, and customer artifact reviews.
• Evaluate findings and weaknesses using both compliance requirements and operational risk, including exploitability, exposure, compensating controls, and customer responsibility boundaries.
• Maintain visibility into customer compliance posture and ensure customers meet shared-responsibility obligations and required service-level timelines.
• Manage all customer-facing compliance activities, including coordinating Continuous Monitoring (ConMon) submissions, leading POA&M reviews, managing Security Change Requests/Notifications (SCR/SCN) with customers, and acting as a primary liaison for agency communication.
• Prepare dashboards, metrics, and executive reporting for overdue findings, POA&Ms, control gaps, remediation status, audit readiness, and overall compliance posture.
• Escalate material compliance gaps, SLA misses, and recurring customer issues to Knox leadership with clear recommendations and risk context.
• Help improve Knox's compliance processes, templates, playbooks, and automation capabilities, leveraging compliance-as-code and KnoxAI, to support scalable, repeatable, and audit-ready operations.
Qualifications
• 7+ years of experience in cybersecurity compliance, GRC, cloud security, or related security assurance roles.
• Direct experience with FedRAMP and NIST SP 800-53 in cloud or SaaS environments.
• Strong working knowledge of FISMA, SOC 2, StateRamp, GovRAMP, and at least one of the following: IL4, IL5, CMMC, NIST 800-171.
• Experience supporting audits, assessments, or authorization activities in regulated cloud environments.
• Strong understanding of cloud platforms such as AWS, Azure, and/or GCP and how security controls are implemented within them.
• Experience partnering with technical teams such as DevOps, SOC, SRE, Engineering, or IT Operations to validate control implementation and drive remediation.
• Ability to manage multiple customers, priorities, deadlines, and dependencies in a fast-paced environment.
• Strong written and verbal communication skills, including the ability to explain compliance requirements, technical findings, and risk decisions clearly to both technical and non-technical stakeholders.
Preferred Qualifications
• Experience with FedRAMP High and/or DoD IL4 / IL5 environments.
• Experience working with continuous monitoring, POA&M governance, vulnerability remediation tracking, and customer audit readiness.
• Familiarity with cloud/security tooling such as CSPM, SIEM, EDR/XDR, ticketing/GRC platforms, and evidence automation workflows.
• Experience with shared responsibility models in managed cloud or regulated SaaS environments.
• Certifications such as CISSP, CISA, CAP, Security+, CCSP, or cloud security certifications.
• Experience in a high-growth cloud company, managed services provider, or regulated SaaS provider.
Success in This Role
• Knox and assigned customers maintain strong compliance posture with minimal overdue remediation items.
• Audit and assessment artifacts are complete, accurate, and ready when needed.
• Control gaps are identified early and driven to closure.
• Customers clearly understand what they own, what Knox owns, and what deadlines must be met.
• Leadership has accurate, timely visibility into compliance health, risk, and SLA performance.
Compensation Range: $135-$165k, variable annual bonus, and equity
Benefits & Perks
Knox offers a competitive employee benefits package including Medical, Dental, Vision, Life & Disability, unlimited PTO, and an employee funded 401k plan. Please note, benefits are subject to change.
Hiring Requirement: Due to the nature of our work with federal government clients and compliance with applicable regulations, this position requires U.S. citizenship. Dual citizenship is not permitted for this role. Candidates must be able to provide documentation verifying sole U.S. citizenship status as part of the background check process.