Socure Logo

Socure

GRC Analyst – Public Sector

Reposted 23 Days Ago
Remote
Hiring Remotely in United States
110K-130K Annually
Senior level
Remote
Hiring Remotely in United States
110K-130K Annually
Senior level
The Analyst, GRC - Public Sector will manage compliance operations, oversee vulnerability remediation, and streamline processes for FedRAMP and GovRAMP standards.
The summary above was generated by AI
Why Socure?

Socure is building the identity trust infrastructure for the digital economy — verifying 100% of good identities in real time and stopping fraud before it starts. The mission is big, the problems are complex, and the impact is felt by businesses, governments, and millions of people every day.

We hire people who want that level of responsibility. People who move fast, think critically, act like owners, and care deeply about solving customer problems with precision. If you want predictability or narrow scope, this won’t be your place. If you want to help build the future of identity with a team that holds a high bar for itself — keep reading.

About the role

Socure is seeking an Analyst, GRC – Public Sector to execute and enhance the company’s governance, risk, and compliance operations for its public sector business. Reporting to the Director of GRC – Public Sector, this role drives measurable improvements in compliance efficiency and audit readiness by managing vulnerability remediation, continuous monitoring, access oversight, and evidence preparation that allow Socure to meet the rigorous standards of FedRAMP, GovRAMP, and related frameworks.

The Analyst collaborates across Security, Engineering, IT, DevOps, Product, Legal, and other teams to operationalize regulatory requirements, automate workflows, and offers the opportunity to shape the GRC strategy for Socure’s fast-growing public sector business. This role is expected to challenge traditional GRC approaches and build automation-first, system-driven solutions that reduce manual effort and enable continuous compliance. The role also translates internal compliance systems into scalable, customer-facing outputs including RFP responses, audit artifacts, and public sector communications.

What you'll doCompliance & Certification Management
  • Day-to-day coordination and execution of externalThird Party Assessment Organization (3PAO) assessments and responding to auditor requests for evidence and documentation.

  • Maintain and update FedRAMP and GovRAMP controls and documentation in alignment with organizational and regulatory requirements, including controls aligned with NIST SP 800-53 rev 5 and other related frameworks.

  • Prepare certification and authorization packages and maintain related documentation such as the System Security Plan (SSP) and associated appendices.

  • Replace manual evidence collection with system-generated, API-driven, or continuously validated evidence where possible.

Continuous Monitoring & Vulnerability Management
  • Design and evolve an automation-first continuous monitoring program leveraging system integrations, telemetry, and real-time data pipelines

  • Lead the day-to-day FedRAMP continuous monitoring process including vulnerability management lifecycle, from identification through remediation and verification, coordinating with Security, Engineering, and DevOps teams to address issues identified with tools such as Wiz, Burp Suite, AWS native services, and other platforms and resolve issues within FedRAMP and GovRAMP timelines.

  • Coordinate recurring continuous monitoring compliance activities such as access reviews, incident response exercises, and contingency plan testing.

Access Management & Training
  • Design scalable and automated access validation mechanisms integrated with identity and infrastructure systems

  • Design, implement and deliver FedRAMP training programs to promote compliance awareness

  • Create and manage automated workflows to improve efficiency.

Audit & Assessment Readiness
  • Transform compliance evidence from static repositories into dynamic, system-driven evidence models supporting real-time audit readiness

  • Conduct internal reviews of logged events and control activities, escalating issues or gaps to the Director of GRC and provide status updates and reports highlighting trends, risks, and remediation progress.

Process Improvement & Collaboration
  • Collaborate with the Director of GRC to design automation-first and AI-enabled workflows that reduce manual effort and enable scalable compliance operations

  • Support the development, rollout, and maintenance of machine-readable compliance documentation (e.g., OSCAL or comparable structured formats) to facilitate interoperability

  • Partner with automation and engineering teams to integrate structured compliance data into Socure’s broader risk management and monitoring ecosystem including vulnerability remediation, access requests, and compliance reporting.

  • Monitor regulatory and industry trends for potential impacts to compliance strategy.

Public Sector Sales & Customer Engagement
  • Serve as a security subject matter expert for public sector sales activities, translating compliance controls and system capabilities into clear, accurate, and compelling customer-facing narratives.

  • Support development of external communications such as press releases and customer-facing materials related to security certifications and authorizations.

  • Build and maintain scalable response frameworks (e.g., answer libraries, structured content, or AI-assisted tools) to provide consistency, accuracy, and speed across RFP and RFx responses

Monitor Evolving Requirements
  • Monitor new and evolving requirements and perform gap analyses including

    • Updates to applicable NIST Special Publications and other government standards

    • Contract security requirements from new customers

    • Updates to the FedRAMP Program requirements and processes as the program evolves

  • Provide input to standards bodies on evolving standards when applicable

What you bring
  • 5+ years of cybersecurity or identity management experience, including 1+ year in the public sector.

  • Direct experience with FedRAMP, GovRAMP, and NIST frameworks (800-53, 800-63, 800-171).

  • Proven ability to manage continuous monitoring, vulnerability remediation, and compliance reporting.

  • Experience using AI tools (e.g., ChatGPT, Glean, Gemini) and machine-readable formats (e.g., OSCAL) to automate and streamline compliance processes.

  • Strong communication, organization, and collaboration skills with the ability to manage multiple priorities.

  • Ability to adapt to changing requirements

  • Experience supporting or leading responses to security questionnaires, RFPs, or public sector RFx processes

  • Must be a U.S. Person (U.S. Citizens or U.S. Permanent Residents) residing in the United States and be able to obtain a U.S. OPM NACI clearance.

Preferred Qualifications
  • Experience in regulated industries (e.g., financial services, healthcare) and knowledge of privacy and compliance frameworks such as GDPR, CCPA, and key NIST standards.

  • Professional certifications preferred (CISSP, CISM, CISA, IAPP).

  • Proven success leading certification and compliance initiatives (FedRAMP, GovRAMP, NIST 800-63/171)

  • Skilled in continuous monitoring, vulnerability management, policy updates, and audit coordination across cross-functional teams.

  • Strong understanding of evolving cybersecurity standards and digital identity regulations, with the ability to translate them into practical risk and compliance improvements.

Socure is an equal opportunity employer that values diversity in all its forms within our company. We do not discriminate based on race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.
If you need an accommodation during any stage of the application or hiring process—including interview or onboarding support—please reach out to your Socure recruiting partner directly.

Follow Us!

YouTube | LinkedIn | X (Twitter) | Facebook

Similar Jobs

52 Minutes Ago
Easy Apply
Remote
United States
Easy Apply
60K-70K Annually
Mid level
60K-70K Annually
Mid level
Artificial Intelligence • Cloud • Information Technology • Machine Learning • Natural Language Processing • Software
The Localization Project Manager will manage end-to-end localization processes for enterprise clients, ensuring workflow optimization, problem-solving, and client relationship management in a remote environment.
Top Skills: AIAsanaCat ToolsGoogle SheetsJIRALookerSmartlingTms
53 Minutes Ago
Remote or Hybrid
2 Locations
120K-190K Annually
Mid level
120K-190K Annually
Mid level
Artificial Intelligence • Big Data • Healthtech • Machine Learning • Analytics • Biotech • Generative AI
The role involves supporting research collaborations in oncology, engaging KOLs, managing study proposals, and contributing to medical writing and strategy development.
Top Skills: AIGenomic Testing
53 Minutes Ago
Remote
United States
140K-155K Annually
Senior level
140K-155K Annually
Senior level
Artificial Intelligence • Consumer Web • Edtech • HR Tech • Information Technology • Software • Conversational AI
The Senior Internal & Executive Communications Manager will lead internal and executive communications, developing strategies and messages that connect employees with company goals and drive action. Responsibilities include managing communication channels, executing town halls, and working directly with senior leaders to craft clear narratives and presentations.
Top Skills: AsanaAxios HqMs SuiteZoom

What you need to know about the Austin Tech Scene

Austin has a diverse and thriving tech ecosystem thanks to home-grown companies like Dell and major campuses for IBM, AMD and Apple. The state’s flagship university, the University of Texas at Austin, is known for its engineering school, and the city is known for its annual South by Southwest tech and media conference. Austin’s tech scene spans many verticals, but it’s particularly known for hardware, including semiconductors, as well as AI, biotechnology and cloud computing. And its food and music scene, low taxes and favorable climate has made the city a destination for tech workers from across the country.

Key Facts About Austin Tech

  • Number of Tech Workers: 180,500; 13.7% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Dell, IBM, AMD, Apple, Alphabet
  • Key Industries: Artificial intelligence, hardware, cloud computing, software, healthtech
  • Funding Landscape: $4.5 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Live Oak Ventures, Austin Ventures, Hinge Capital, Gigafund, KdT Ventures, Next Coast Ventures, Silverton Partners
  • Research Centers and Universities: University of Texas, Southwestern University, Texas State University, Center for Complex Quantum Systems, Oden Institute for Computational Engineering and Sciences, Texas Advanced Computing Center

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account