Program Architect - Governance, Risk, and Compliance
Job description
About the role
You will own the end-to-end architecture of Onebrief's compliance program, defining how regulatory demands are turned into operational reality. In this role, you will serve as the technical and procedural link between strict government requirements and the day-to-day work of engineers and product teams. You will design the frameworks, controls, and evidence structures that allow defense and government clients to trust our platform. Your work will ensure that compliance is not a periodic audit event but a continuously maintained state of readiness. You will translate complex regulations like RMF, FedRAMP, and CMMC into concrete technical architectures and process flows. You will partner with infrastructure and security teams to bake controls into the system rather than bolting them on after the fact. This position requires a hands-on leader who is comfortable both in strategic design and in the granular details of implementation. You will be the primary architect ensuring that our governance, risk, and compliance framework is robust, auditable, and scalable.
Key facts
What you'll do
Establish the foundational architecture for Onebrief's governance, risk, and compliance program, aligning strategy with frameworks such as RMF, FedRAMP, CMMC, and SOC 2.
Design and manage the enterprise control environment, creating policies, procedures, and system workflows that generate the evidence required for rigorous assessments.
Partner with Product, Engineering, Infrastructure, and Corporate IT to integrate security and compliance requirements into system designs through technical controls like access management, logging, encryption, and vulnerability management.
Embed compliance directly into the technology stack and delivery pipelines so that security and governance are inherent properties of the software, not retrospective documentation exercises.
Serve as the main authority and primary point of contact for responding to customer security questionnaires, compliance inquiries, and evidence requests.
Develop and oversee the control frameworks and evidence collection mechanisms that support continuous monitoring and audit readiness.
Collaborate with engineering and infrastructure teams to define secure architecture patterns, ensuring that identity and access management, network segmentation, logging, and encryption are implemented consistently.
Manage relationships with third-party assessors and auditors, coordinating the preparation, execution, and follow-up on audits and certification activities.
Leverage GRC platforms such as RegScale or eMASS to automate workflows, track control performance, and maintain an up-to-date state of authorization.
Implement infrastructure-as-code solutions to codify security controls and compliance artifacts, enabling scalable and repeatable deployments across federal and defense environments.
Utilize logging systems and monitoring tools to ensure that security-relevant data is captured, retained, and structured to meet compliance visibility requirements.
Optimize CI/CD pipelines to include compliance checks, policy validation, and evidence capture as standard gates in the software delivery lifecycle.
Guide the adoption of security control frameworks like NIST 800-53 and NIST 800-171, tailoring their application to the specific needs of cloud-native and defense-focused products.
Champion continuous improvement in the compliance program by analyzing audit findings, control failures, and emerging regulatory trends to drive proactive enhancements.
Requirements
Possess a minimum of 5 years of professional experience in GRC, security engineering, or a blended role that combines compliance with technical security responsibilities.
Have demonstrated, hands-on experience with federal compliance frameworks such as RMF, FedRAMP, or CMMC, including their control families and lifecycle processes.
Show practical, implementation-level experience with technical security controls, including identity and access management, logging and monitoring, network segmentation, and encryption technologies.
Demonstrate familiarity with security control frameworks and standards such as NIST 800-53 or NIST 800-171 and the ability to apply them in cloud and hybrid environments.
Have experience managing third-party audits, working directly with assessors, and following through on remediation activities to closure.
Show strong written communication skills, with the ability to interpret dense regulatory language and convert it into clear, actionable technical guidance for engineering and operations teams.
Be legally authorized to work in the United States without sponsorship, as the role requires U.S. citizenship or permanent residency to meet government client requirements.
Commit to working full-time hours aligned with U.S. business expectations, supporting collaboration across distributed engineering and security teams.
Nice to have
Bring prior experience from a startup or a rapidly growing company, where you have operated with agility and ownership in evolving compliance environments.
Have a background in military, defense, or government contracting sectors, providing contextual understanding of defense-in-depth and mission-critical requirements.
Hold professional certifications such as CISSP, CISA, CRISC, or a technical security certification like AWS Solutions Architect, demonstrating structured knowledge of security and cloud platforms.
Show experience automating GRC processes using infrastructure-as-code tools, scripting, and integration between security tooling and workflow systems.
Practical notes
Onebrief is a U.S.-based company and requires that team members be eligible to work in the United States without sponsorship.
This is a full-time position aligned with standard U.S. business hours to enable close collaboration with engineering, security, and product teams.
Onebrief does not accept unsolicited resumes from third-party recruitment agencies.