Back to all roles

GRC Engineer – CMMC, FedRAMP

Remote-first Full-time Now hiring

Job Description:

  • Interpret and Apply FedRAMP Requirements: Analyze and apply NIST SP 800-53 controls, FedRAMP baselines, and agency-specific requirements to ensure client compliance.
  • Develop and Maintain FedRAMP Documentation: Develop and maintain System Security Plans (SSPs), control implementation narratives, POA&Ms, SAPs, SARs, and continuous monitoring artifacts.
  • Conduct FedRAMP Readiness Assessments: Perform gap analyses and readiness reviews to prepare organizations for JAB or Agency ATO pathways.
  • Support Authorization and Assessment Activities: Coordinate with Third-Party Assessment Organizations (3PAOs), cloud service providers, and government stakeholders throughout the FedRAMP lifecycle.
  • Boundary Definition & Scoping: Perform CMMC/FedRAMP authorization boundary definition and system scoping activities.
  • Support Continuous Monitoring Programs: Conduct monthly, quarterly, and annual FedRAMP continuous monitoring requirements.
  • Support FedRAMP Engagements: Assist on multiple concurrent client projects.
  • Support CMMC and NIST 800-171 Compliance Efforts: Assist defense contractors with interpreting CMMC 2.0 and NIST SP 800-171 controls and implementing compliant security programs.
  • Develop CMMC Documentation: Contribute to SSPs, POA&Ms, and supporting artifacts required for CMMC Level 1 and Level 2 readiness.

Requirements:

  • Strong organizational and project management skills with the ability to manage multiple engagements concurrently
  • 2+ years of experience in GRC, with exposure to FedRAMP, NIST SP 800-53, and federal compliance programs
  • Working knowledge of CMMC 2.0 and NIST SP 800-171 requirements
  • Experience authoring and reviewing SSPs, POA&Ms, and assessment artifacts
  • Familiarity with federal cloud environments (AWS GovCloud, Azure Government, GCC High)
  • Experience working with SaaS providers, federal contractors, or regulated technology organizations
  • Ability to thrive in a fast-paced, consulting, or startup environment.

Benefits:

  • Reliable high-speed internet connection.
  • Quiet, professional home office setup.
  • Must be amenable to work US Eastern Time zone hours.
  • Fluency in written and verbal English communication skills.

Apply tot his job Apply To this Job

More remote roles

SAP GRC Consultant

Remote-first Full-time

Industry Principal- GRC

Remote-first Full-time

Watsonx.Gov - GRC Delivery Consultant

Remote-first Full-time

Product Sales Executive - GRC

Remote-first Full-time

SAP GRC Access Control Specialist consultant (EAM, ARA, ARM, BRM)

Remote-first Full-time

Manager, IT Service Management & GRC Support

Remote-first Full-time

Information Security & GRC Intern

Remote-first Full-time

: SAP Security Analyst / Lead - GRC, S/4HANA & BTP (Experience: 10+ Years)

Remote-first Full-time

ServiceNow Technical Lead- IRM & GRC

Remote-first Full-time

Cybersecurity Risk Analyst (GRC / IT Risk & Compliance)

Remote-first Full-time

Experienced Part-time Remote Data Entry Specialist – Organizing and Maintaining Essential Data for arenaflex Operations

Remote-first Full-time

Experienced Full Stack Product Manager – Customer Service Innovation and Experience

Remote-first Full-time

Entry-Level Remote Data Entry Specialist – No Experience Required – Flexible Schedule, Training & Growth Opportunities at arenaflex

Remote-first Full-time

Life Insurance Sales Representative - Up to $150k+ Yearly

Remote-first Full-time

PCS Vendor Management Professional

Remote-first Full-time

Experienced Proofreader & Customer Representative Specialist – Remote – (DAY OR NIGHT SHIFT) in arenaflex

Remote-first Full-time

[Remote] Veeva CRM Business Analyst - Remote, US

Remote-first Full-time

Experienced Data Entry Associate – Remote Opportunity at arenaflex

Remote-first Full-time

[Remote] Infrastructure Operations Engineer

Remote-first Full-time

Remote Data Entry Specialist – Entry‑Level Work‑From‑Home Opportunity with arenaflex – Full‑Time & Part‑Time

Remote-first Full-time