GRC Analyst - Public Sector
Socure Inc
Why Socure? Socure is building the identity trust infrastructure for the digital economy - verifying 100% of good identities in real time and stopping fraud before it starts. The mission is big, the problems are complex, and the impact is felt by businesses, governments, and millions of people every day. We hire people who want that level of responsibility. People who move fast, think critically, act like owners, and care deeply about solving customer problems with precision. If you want predictability or narrow scope, this won't be your place. If you want to help build the future of identity with a team that holds a high bar for itself - keep reading. About the role Socure is seeking an Analyst, GRC - Public Sector to execute and enhance the company's governance, risk, and compliance operations for its public sector business. Reporting to the Director of GRC - Public Sector, this role drives measurable improvements in compliance efficiency and audit readiness by managing vulnerability remediation, continuous monitoring, access oversight, and evidence preparation that allow Socure to meet the rigorous standards of FedRAMP, GovRAMP, and related frameworks.
The Analyst collaborates across Security, Engineering, IT, DevOps, Product, Legal, and other teams to operationalize regulatory requirements, automate workflows, and offers the opportunity to shape the GRC strategy for Socure's fast-growing public sector business. This role is expected to challenge traditional GRC approaches and build automation-first, system-driven solutions that reduce manual effort and enable continuous compliance. The role also translates internal compliance systems into scalable, customer-facing outputs including RFP responses, audit artifacts, and public sector communications. What you'll do
Compliance & Certification Management
Socure is an equal opportunity employer that values diversity in all its forms within our company. We do not discriminate based on race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.
If you need an accommodation during any stage of the application or hiring process-including interview or onboarding support-please reach out to your Socure recruiting partner directly. Follow Us! YouTube | LinkedIn | X (Twitter) | Facebook
The Analyst collaborates across Security, Engineering, IT, DevOps, Product, Legal, and other teams to operationalize regulatory requirements, automate workflows, and offers the opportunity to shape the GRC strategy for Socure's fast-growing public sector business. This role is expected to challenge traditional GRC approaches and build automation-first, system-driven solutions that reduce manual effort and enable continuous compliance. The role also translates internal compliance systems into scalable, customer-facing outputs including RFP responses, audit artifacts, and public sector communications. What you'll do
Compliance & Certification Management
- Day-to-day coordination and execution of externalThird Party Assessment Organization (3PAO) assessments and responding to auditor requests for evidence and documentation.
- Maintain and update FedRAMP and GovRAMP controls and documentation in alignment with organizational and regulatory requirements, including controls aligned with NIST SP 800-53 rev 5 and other related frameworks.
- Prepare certification and authorization packages and maintain related documentation such as the System Security Plan (SSP) and associated appendices.
- Replace manual evidence collection with system-generated, API-driven, or continuously validated evidence where possible.
- Design and evolve an automation-first continuous monitoring program leveraging system integrations, telemetry, and real-time data pipelines
- Lead the day-to-day FedRAMP continuous monitoring process including vulnerability management lifecycle, from identification through remediation and verification, coordinating with Security, Engineering, and DevOps teams to address issues identified with tools such as Wiz, Burp Suite, AWS native services, and other platforms and resolve issues within FedRAMP and GovRAMP timelines.
- Coordinate recurring continuous monitoring compliance activities such as access reviews, incident response exercises, and contingency plan testing.
- Design scalable and automated access validation mechanisms integrated with identity and infrastructure systems
- Design, implement and deliver FedRAMP training programs to promote compliance awareness
- Create and manage automated workflows to improve efficiency.
- Transform compliance evidence from static repositories into dynamic, system-driven evidence models supporting real-time audit readiness
- Conduct internal reviews of logged events and control activities, escalating issues or gaps to the Director of GRC and provide status updates and reports highlighting trends, risks, and remediation progress.
- Collaborate with the Director of GRC to design automation-first and AI-enabled workflows that reduce manual effort and enable scalable compliance operations
- Support the development, rollout, and maintenance of machine-readable compliance documentation (e.g., OSCAL or comparable structured formats) to facilitate interoperability
- Partner with automation and engineering teams to integrate structured compliance data into Socure's broader risk management and monitoring ecosystem including vulnerability remediation, access requests, and compliance reporting.
- Monitor regulatory and industry trends for potential impacts to compliance strategy.
- Serve as a security subject matter expert for public sector sales activities, translating compliance controls and system capabilities into clear, accurate, and compelling customer-facing narratives.
- Support development of external communications such as press releases and customer-facing materials related to security certifications and authorizations.
- Build and maintain scalable response frameworks (e.g., answer libraries, structured content, or AI-assisted tools) to provide consistency, accuracy, and speed across RFP and RFx responses
- Monitor new and evolving requirements and perform gap analyses including
- Updates to applicable NIST Special Publications and other government standards
- Contract security requirements from new customers
- Updates to the FedRAMP Program requirements and processes as the program evolves
- Provide input to standards bodies on evolving standards when applicable
- 5+ years of cybersecurity or identity management experience, including 1+ year in the public sector.
- Direct experience with FedRAMP, GovRAMP, and NIST frameworks (800-53, 800-63, 800-171).
- Proven ability to manage continuous monitoring, vulnerability remediation, and compliance reporting.
- Experience using AI tools (e.g., ChatGPT, Glean, Gemini) and machine-readable formats (e.g., OSCAL) to automate and streamline compliance processes.
- Strong communication, organization, and collaboration skills with the ability to manage multiple priorities.
- Ability to adapt to changing requirements
- Experience supporting or leading responses to security questionnaires, RFPs, or public sector RFx processes
- Must be a U.S. Person (U.S. Citizens or U.S. Permanent Residents) residing in the United States and be able to obtain a U.S. OPM NACI clearance.
- Experience in regulated industries (e.g., financial services, healthcare) and knowledge of privacy and compliance frameworks such as GDPR, CCPA, and key NIST standards.
- Professional certifications preferred (CISSP, CISM, CISA, IAPP).
- Proven success leading certification and compliance initiatives (FedRAMP, GovRAMP, NIST 800-63/171)
- Skilled in continuous monitoring, vulnerability management, policy updates, and audit coordination across cross-functional teams.
- Strong understanding of evolving cybersecurity standards and digital identity regulations, with the ability to translate them into practical risk and compliance improvements.
Socure is an equal opportunity employer that values diversity in all its forms within our company. We do not discriminate based on race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.
If you need an accommodation during any stage of the application or hiring process-including interview or onboarding support-please reach out to your Socure recruiting partner directly. Follow Us! YouTube | LinkedIn | X (Twitter) | Facebook
Vacancy posted 5 days ago
Similar jobs that could be interesting for youBased on the GRC Analyst - Public Sector in New York, NY vacancy
$161.6k - $202k
...- and that responsibility demands a security and compliance program that scales with the business. We're building out our dedicated GRC team to improve and mature our program! You'll join the Security team and work across four pillars: security certifications (HITRUST...SuggestedWork from homeFlexible hours- ...Hotman Group is seeking an Entry Level GRC Analyst to work remotely in the USA. The role involves assessing client security, developing risk frameworks, and translating technical requirements into actionable steps. Candidates should possess a relevant degree and 1-2 years...SuggestedRemote work
$130k - $160k
...Alumni Ventures is seeking a Senior GRC Analyst to operate and mature governance, risk, compliance, and audit readiness programs. This role involves collaboration across departments to ensure effective compliance practices. Ideal candidates have 5+ years in GRC and experience...SuggestedRemote workFlexible hours- ...A dynamic cybersecurity firm is looking for a detail-oriented Entry-Level GRC Analyst to join their remote team. In this role, you'll work closely with senior members to strengthen client cybersecurity and compliance programs. You'll be involved in assessing controls,...SuggestedRemote work
- ...Role- GRC Analyst Duration: Contract to Perm Location: Norwalk CT, New York, Houston, TX Must Haves: GRC Nice to Haves: SOC2, IT Controls ~3 days on site. ~ Open to recent college grads with IT or accounting/finance degrees. ~ Values...SuggestedPermanent employmentContract work
- ...environment, demand excellence, and want to help build the future of finance, we invite you to join us. The Role Rogo is hiring a GRC Analyst to support our customer trust, security assurance, and compliance programs as we scale globally. This role plays a critical part...
$125k - $135k
...GRC Analyst job at Suzy. Remote. Suzy puts the voice of the consumer at your fingertips. Whether youre a novice or an expert researcher, our platform brings advanced tools together with the highest quality audience to deliver insights in minutes. Some of the biggest brands...Work experience placementImmediate startRemote work- ...DataRobot, Inc. is seeking a GRC Analyst to join their Information Security Team. The successful candidate will collaborate with stakeholders to manage ISO27001, SOC 2, and HIPAA compliance programs. Key responsibilities include responding to customer security inquiries...Flexible hours
$95k - $105k
...Subsplash is looking for a GRC Analyst to join its Remote team in the United States. In this role, you'll be a strategic lead in advancing security and risk operations by identifying gaps and implementing best practices. With a salary range of $95,000-$105,000/yr, you'...Remote work- ...Despite our growth and scale, we're still just getting started. That's where you come in. About the role We’re hiring a Senior GRC Analyst to help scale Radar’s security and compliance programs, with a focus on third-party risk and modern SaaS governance. You’ll partner...Work at officeRemote work
- ...is looking for driven, detail-obsessed team members to join our rapidly growing boutique firm as a full-time, remote Entry-Level GRC Analyst. This is a contract-to-hire position with top performers moving to permanent roles within 6 months — and trust us, we want you to...Permanent employmentFull timeContract workRemote work
- ...About the Role: As aGRC Analyst II on our Governance Team, you’ll play a critical role in helping our customers establish and implement robust security governance programs. You’ll work directly with clients to support customer onboarding, policy development, gap reviews...
- ...Job Description We are seeking a detail oriented and analytically driven GRC Analyst to support the organization's information security governance, risk management, and compliance program. This role is critical to ensuring alignment with regulatory requirements, industry...
- ...A cutting-edge technology firm in the United States is seeking a Senior GRC Analyst. The role requires 5+ years of experience in risk management, compliance, and governance. You will support the organization's GRC program, maintain security compliance frameworks, and conduct...Remote work
- ...Neier Inc. is looking for a Remote GRC Analyst to lead the transition from a single tenant to a multi‑tenant access control environment. This role involves enhancing SOX compliance and developing governance processes to ensure secure growth. The ideal candidate should...Remote work
$130k - $160k
...Location U.S Remote Employment Type Full time Department Engineering Team & Role As a Senior GRC Analyst at Benepass, you will help operate and mature the governance, risk, compliance, audit readiness, and customer assurance programs that support our business, customers...Full timeWork at officeRemote workWork from homeFlexible hours$135k - $190k
...York City, Mumbai and Bangalore for employees who prefer to work in an office some or all of the time. About your role As a Senior GRC Analyst, you are responsible for supporting the organization's governance, risk management, and compliance (GRC) program. The ideal...Full timeWork at officeLocal areaRemote workWork from homeFlexible hours- ...their AI assets. Organizations worldwide rely on DataRobot for AI that makes sense for their business — today and in the future.The GRC Analyst will collaborate with process owners, auditors, and other stakeholders to support the DataRobot Information Security Team in...Local areaWorldwideFlexible hours
- ...Neier Inc. is seeking an Experienced or Senior GRC Analyst to lead cybersecurity and compliance initiatives. This full-time, remote position will focus on risk assessments, developing compliance programs, and mentoring junior analysts. The ideal candidate has over 5 years...Full timeRemote work
- ...A security consulting company in the United States is looking for a GRC Analyst II to support governance programs for clients. In this role, you will onboard customers, perform gap assessments, and develop security policies. The ideal candidate will have 2-3 years in information...
$95k - $110k
...Blackkite is looking for a Senior GRC Analyst to oversee compliance efforts and support customer security assessments in the United States. This role requires expertise in compliance frameworks like SOC 2 and ISO 27001, along with strong communication skills. The successful...Flexible hours- ...are seeking a talented Senior Governance, Risk, and Compliance (GRC) Analyst / Engineer to join our innovative team focused on advancing... ...mitigation effortsEquity participation in a fast-growing, innovative public company (spun off from Uber and Postmates)Opportunity to grow...Remote workFlexible hours
- Senior Governance, Risk, Compliance (GRC) Analyst job at Oura. New York, NY. At Oura, our mission is to empower every person to own their inner potential. With our award-winning Oura Ring and app, we help over 2.5 million people turn insights about sleep, activity, and...Work at officeLocal areaRemote workFlexible hours
- Rogo in New York is seeking a GRC Analyst to enhance its customer trust, security, and compliance programs. You will work cross-functionally with teams in security, engineering, and legal to ensure clear communication of security practices. The role entails responding to...
- ...strong for 90 years, that encourages you to learn, grow, and pursue your dreams? If yes, then read on... The Information Security GRC Analyst III is responsible for analyzing and assessing the information security controls in an effort to protect the confidentiality,...Monday to Friday
- Radar is hiring a Senior GRC Analyst in New York City to enhance security and compliance programs, focusing on third-party risk and SaaS governance. You will work with various teams to evaluate vendors, shape security strategies, and improve workflows, reporting to the...
- A leading technology-driven financial services company in New York seeks an Information Security professional. The role involves governance, risk, and compliance activities pertinent to security within a hybrid work environment. Candidates should possess at least 2 years...Flexible hours
$76 per hour
The Cake is looking for an experienced cyber risk analyst to conduct assessments and support governance documentation in New York City. The role requires 5+ years in cyber risk or security governance and the ability to translate technical risks into business language. The...- PSECU Pennsylvania State Employees Credit Union is seeking an Information Security GRC Analyst III to ensure the integrity, confidentiality, and availability of information. You'll monitor compliance, conduct risk assessments, and manage security policies. The ideal candidate...
- Oura is seeking a Senior Governance, Risk, Compliance (GRC) Analyst to join the Security Team in New York City. This role involves leading GRC initiatives, managing compliance policies, and performing risk assessments. Candidates should have over 6 years of experience...Remote workFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to GRC Analyst - Public Sector. Be the first to apply!
Related searches

