Corporate Governance, Risk, and Compliance Analyst
Job description
About the role
Onebrief builds collaboration and AI-powered workflow software for military planning and operational coordination. The role of the Governance, Risk, and Compliance Analyst is central to ensuring that this technology meets the highest standards required by the Department of Defense and commercial partners. You will own the integrity of our compliance posture across multiple, simultaneous regulatory programs. This position requires a high level of personal accountability for the evidence and decisions that support our authority to operate. You will be responsible for maintaining the accuracy and completeness of critical security documentation under tight timelines. The ideal candidate thrives in an environment where precision and proactive problem-solving are essential. This is a hands-on position that directly influences the security and trustworthiness of our platform.
Key facts
What you'll do
Own RMF authorizations for Department of War components while simultaneously managing FedRAMP High compliance for civilian federal customers.
Maintain authorization and audit evidence, including System Security Plans (SSPs), Security Authorization Agreements (SARs), Plans of Action and Milestones (POA&Ms), Security Technical Implementation Guides (STIGs), and detailed control mappings.
Partner with Engineering, Product, and Security leadership to embed compliance requirements into system design and CI/CD workflows, preventing issues rather than reacting to them.
Coordinate internal assessments and external audit readiness activities across all applicable frameworks, ensuring consistency and completeness.
Track evolving regulatory and contractual requirements and clearly advise leadership on potential impacts and necessary actions.
Conduct risk assessments and vendor/supply chain risk reviews across both federal and corporate environments to identify and mitigate potential threats.
Automate control testing and evidence collection to replace manual, inefficient processes and close gaps before they become formal audit findings.
Translate complex RMF, CMMC 2.0, and SOC 2 language into clear, actionable decisions for engineers and stakeholders.
Serve as the central point of coordination for compliance activities, aligning efforts across programs to avoid fragmented workflows.
Indicators of Success
This role will evolve as priorities change, but the outcomes below reflect what success typically looks like in the first six months.
A successful Governance, Risk, and Compliance Analyst will keep authorization packages current across every framework instead of reconstructing them under deadline pressure.
You will reduce manual audit prep by automating control testing and evidence collection through systematic improvements.
You will close open POA&M and corrective action items on a predictable and reliable cadence.
You will become the go-to person engineers check with before shipping changes to ensure compliance requirements are met.
You will demonstrate mastery in navigating the complex intersection of federal mandates and corporate security practices.
You will proactively identify risks in the vendor and supply chain management processes.
You will build scalable processes that allow the company to grow without a proportional increase in compliance overhead.
You will communicate effectively with diverse stakeholders, from technical teams to federal oversight entities.
You will continuously refine the evidence base to ensure it withstands scrutiny during audits and assessments.
Requirements
U.S. Citizen.
Hold a Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related field.
Possess 8+ years of professional experience in cybersecurity compliance.
Demonstrate hands-on expertise with the Risk Management Framework (RMF) and at least one of the following: CMMC 2.0 or SOC 2.
Hold one or more of the following certifications: CISSP, CISM, CISSO, CPTE, CySA+, FITSP-A, GCSA, CISA, ISSEP, GSLC, or GSNA.
Have direct experience with Governance, Risk, and Compliance (GRC) platforms, including automated evidence collection and continuous testing capabilities.
Possess practical familiarity with eMASS or similar authorization platforms.
Understand the fundamentals of secure software development lifecycle (SSDLC) practices.
Be comfortable working with technical documents, control catalogs, and audit artifacts on a regular basis.
Nice to have
Experience operating within Department of Defense environments and adhering to associated compliance frameworks such as RMF and ICD 503.
Familiarity with specific agency overlays, including policies from the Department of Defense, Department of Homeland Security, or other civilian agencies.
Background working with Third-Party Assessment Organizations (3PAOs), Security Control Assessors, federal customers, or SOC 2 auditors.
Knowledge of cloud security standards, including FedRAMP, ISO 27001, NIST 800-171, and DoD Cloud Computing Security Requirements Guide (SRG).
Practical notes
This is a full-time position based in the United States with remote flexibility.
The start date is dependent on the candidate's timeline, with a rapid onboarding process for the right individual.
Candidates must be eligible for U.S. government security clearance sponsorship, which requires U.S. citizenship.
Travel is not required for this role, though occasional virtual coordination with clients and partners may occur.
This role reports to the Director of Compliance and works closely with cross-functional leadership.