Onebrief Logo

Onebrief

Corporate Governance, Risk, and Compliance Analyst

Reposted 3 Days Ago
Remote
Hiring Remotely in United States
160K-200K Annually
Senior level
Remote
Hiring Remotely in United States
160K-200K Annually
Senior level
Manage and maintain RMF authorizations and audit evidence (SSPs, SARs, POA&Ms, STIGs), embed compliance into engineering and CI/CD, coordinate internal assessments and external audits (FedRAMP High, CMMC 2.0, SOC 2), run risk and vendor reviews, and automate continuous control testing across federal and commercial environments.
The summary above was generated by AI
Consequential Work. Dedicated People.
About Onebrief

Onebrief builds collaboration and AI-powered workflow software for military planning and operational coordination.

Military planning is complex by nature, requiring teams to coordinate information, people, and decisions across systems and locations. Onebrief brings planning, collaboration, simulation, and AI into one connected environment, helping teams test strategies, adapt to changing conditions, and make decisions with greater clarity when the stakes are real.

We are a distributed team of builders from military, operational, and technology backgrounds who care deeply about improving how important work gets done. Some team members work remotely, while others work directly alongside customers in operational environments around the world.

Founded in 2019, Onebrief is backed by leading investors including General Catalyst, Battery Ventures, Insight Partners, Sapphire Ventures, and Human Capital. Valued at more than $2 billion, we continue to invest in product innovation, AI capabilities, and team growth.

Why This Role Exists

Onebrief pursues and maintains RMF authorizations across multiple Department of War components and FedRAMP High for civilian federal customers, alongside CMMC 2.0 and SOC 2 compliance for the corporate side of the business. Each program runs its own review cycle, its own overlays, and its own evidence requirements. That spread creates real coordination risk, and no single person carries it alone. This role needs someone who works closely with Engineering, Product, and Security leadership to keep every program aligned instead of managing each one in isolation.

Every one of these programs depends on evidence: SSPs, SARs, POA&Ms, control mappings, and testing that holds up under audit. Onebrief needs someone who builds that evidence chain, validates it, and keeps it current across federal and commercial frameworks alike, working alongside the teams that generate the underlying artifacts, instead of scrambling before each assessment.

Manual compliance work doesn't scale across this many frameworks. This role exists to automate control testing and close gaps before they become findings, replacing reactive audit prep with a system that runs continuously across every environment Onebrief operates in, government and commercial.

The work sits between engineering and a wide set of regulatory requirements. Every control decision affects how Onebrief's product gets built and deployed for both federal and corporate customers, so this role requires someone who can translate RMF, CMMC, and SOC 2 language into decisions engineers can act on, and coordinate closely with stakeholders across multiple agencies and internal teams at once.

What You'll Do

Core responsibilities:

  • Own RMF authorizations across Department of War components and FedRAMP High, alongside CMMC 2.0 and SOC 2 compliance for corporate systems

  • Maintain authorization and audit evidence, including SSPs, SARs, POA&Ms, STIGs, and control mappings

  • Partner with Engineering, Product, and Security to embed compliance requirements into system design and CI/CD workflows, not bolt them on afterward

  • Coordinate internal assessments and external audit readiness across all applicable frameworks

  • Track regulatory and contractual changes and advise leadership on what they mean for Onebrief

  • Run risk assessments and vendor/supply chain risk reviews across both federal and corporate environments

Minimum Qualifications

  • U.S. Citizen

  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or related field

  • 8+ years in cybersecurity compliance

  • Hands-on expertise with RMF and at least one of CMMC 2.0 or SOC 2

  • One or more of the following certifications: CISSP, CISM, CISSO, CPTE, CySA+, FITSP-A, GCSA, CISA, ISSEP, GSLC, or GSNA

  • Experience with GRC platforms, including automated evidence collection and testing (eMASS experience a plus)

Preferred Qualifications

  • Experience in DoD environments and compliance frameworks (RMF, ICD 503)

  • Familiarity with agency-specific overlays (DoD, DHS, or civilian agencies)

  • Experience working with 3PAOs, Security Control Assessors, federal customers, or SOC 2 auditors

  • Familiarity with cloud security standards (FedRAMP, ISO 27001, NIST 800-171, DoD Cloud Computing SRG)

Indicators of Success

This role will evolve as priorities change, but the outcomes below reflect what success typically looks like in the first six months.

A successful Governance, Risk, and Compliance Analyst will:

  • Keep authorization packages current across every framework instead of reconstructing them under deadline pressure

  • Reduce manual audit prep by automating control testing and evidence collection

  • Close open POA&M and corrective action items on a predictable cadence

  • Become the go-to person engineers check with before shipping changes that touch compliance boundaries, federal or corporate

Tools, Systems & Technologies

  • eMASS, GRC platforms, NIST RMF documentation (SSPs, SARs, POA&Ms, STIGs), CMMC 2.0 and SOC 2 control frameworks


Notice to Third Party Recruitment Agencies

Please note that Onebrief does not accept unsolicited resumes from recruiters or employment agencies. In the absence of an executed Recruitment Services Agreement, there will be no obligation to any referral compensation or recruiter fee. In the event a recruiter or agency submits a resume or candidate without an agreement Onebrief explicitly reserves the right to pursue and hire those candidate(s) without any financial obligation to the recruiter or agency. Any unsolicited resumes, including those submitted to hiring managers, shall be deemed the property of Onebrief.

Similar Jobs at Onebrief

6 Hours Ago
Remote
United States
160K-200K Annually
Senior level
160K-200K Annually
Senior level
Software • Defense
Design and operate Onebrief's GRC program across RMF, FedRAMP, CMMC and SOC 2. Build control environments, partner with engineering to implement technical controls (IAM, logging, encryption, segmentation), manage audits and evidence collection, and serve as the compliance lead for customer security reviews.
Top Skills: AWSCi/Cd PipelinesCloud Security ToolingCmmcEmassEncryptionFedrampGrc AutomationIamInfrastructure-As-CodeLogging And MonitoringLogging SystemsNetwork SegmentationNist 800-171Nist 800-53RegscaleRmfSoc 2Vulnerability Management
Yesterday
Remote
United States
180K-220K Annually
Senior level
180K-220K Annually
Senior level
Software • Defense
Work as an SRE embedded with product teams to improve reliability by fixing application code (primarily TypeScript), building observability (Prometheus, Loki, Grafana, Alloy), defining SLIs/SLOs, leading incident response and postmortems, automating toil, and supporting deployments across on‑prem DoD and AWS environments.
Top Skills: AlloyAWSBashContainersDockerGithub ActionsGitlab Ci/CdGoGrafanaJenkinsKubectlKubernetesLokiNode.jsPrometheusPythonTypescript
2 Days Ago
Remote
United States
181K-220K Annually
Senior level
181K-220K Annually
Senior level
Software • Defense
Lead contract execution for Onebrief's highest-priority government initiatives: align contractual obligations with program delivery, identify and mitigate risks, advise stakeholders, build contract management processes, and hire and mentor a team of Contract Managers to ensure successful post-award performance.
Top Skills: Contract Lifecycle ManagementFederal Acquisition Regulation (Far)Other Transaction Authorities (Otas)SaaS

What you need to know about the Austin Tech Scene

Austin has a diverse and thriving tech ecosystem thanks to home-grown companies like Dell and major campuses for IBM, AMD and Apple. The state’s flagship university, the University of Texas at Austin, is known for its engineering school, and the city is known for its annual South by Southwest tech and media conference. Austin’s tech scene spans many verticals, but it’s particularly known for hardware, including semiconductors, as well as AI, biotechnology and cloud computing. And its food and music scene, low taxes and favorable climate has made the city a destination for tech workers from across the country.

Key Facts About Austin Tech

  • Number of Tech Workers: 180,500; 13.7% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Dell, IBM, AMD, Apple, Alphabet
  • Key Industries: Artificial intelligence, hardware, cloud computing, software, healthtech
  • Funding Landscape: $4.5 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Live Oak Ventures, Austin Ventures, Hinge Capital, Gigafund, KdT Ventures, Next Coast Ventures, Silverton Partners
  • Research Centers and Universities: University of Texas, Southwestern University, Texas State University, Center for Complex Quantum Systems, Oden Institute for Computational Engineering and Sciences, Texas Advanced Computing Center

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account