GRC Analyst - Public Sector
Socure Inc
Why Socure? Socure is building the identity trust infrastructure for the digital economy - verifying 100% of good identities in real time and stopping fraud before it starts. The mission is big, the problems are complex, and the impact is felt by businesses, governments, and millions of people every day. We hire people who want that level of responsibility. People who move fast, think critically, act like owners, and care deeply about solving customer problems with precision. If you want predictability or narrow scope, this won't be your place. If you want to help build the future of identity with a team that holds a high bar for itself - keep reading. Overview Socure is seeking an Analyst, GRC - Public Sector to own the hands-on execution of the company's governance, risk, and compliance operations for its public sector business. Reporting to the Director of GRC - Public Sector, this role is responsible day-to-day for running FedRAMP/GovRAMP continuous monitoring, building and maintaining the POA&M and compliance trackers that keep the program audit-ready, and coordinating access reviews, vulnerability remediation, and evidence collection with Security, Engineering, IT, DevOps, Product, Legal, and other teams. As the Analyst builds fluency in these operational fundamentals, the role grows to include drafting customer-facing compliance and RFP response content that makes Socure's security posture compelling to public sector buyers, and pursuing automation-first, system-driven improvements, including machine-readable formats like OSCAL and AI-enabled workflows, that reduce manual effort and challenge how the team has traditionally done this work. Role and Responsibilities Compliance & Certification Management Day-to-day coordination and execution of externalThird Party Assessment Organization (3PAO) assessments and responding to auditor requests for evidence and documentation. Maintain and update FedRAMP and GovRAMP controls and documentation in alignment with organizational and regulatory requirements, including controls aligned with NIST SP 800-53 rev 5 and other related frameworks. Prepare certification and authorization packages and maintain related documentation such as the System Security Plan (SSP) and associated appendices. Replace manual evidence collection with system-generated, API-driven, or continuously validated evidence where possible. Build and maintain the trackers, procedures, and status-reporting artifacts that operationalize this work, structured so other stakeholders can use them directly. Continuous Monitoring & Vulnerability Management Design and evolve an automation-first continuous monitoring program leveraging system integrations, telemetry, and real-time data pipelines Lead the day-to-day FedRAMP continuous monitoring process including vulnerability management lifecycle, from identification through remediation and verification, coordinating with Security, Engineering, and DevOps teams to address issues identified with tools such as Wiz, Burp Suite, AWS native services, and other platforms and resolve issues within FedRAMP and GovRAMP timelines. Coordinate recurring continuous monitoring compliance activities such as access reviews, incident response exercises, and contingency plan testing. Access Management & Training Design scalable and automated access validation mechanisms integrated with identity and infrastructure systems Design, implement and deliver FedRAMP training programs to promote compliance awareness Create and manage automated workflows to improve efficiency. Audit & Assessment Readiness Transform compliance evidence from static repositories into dynamic, system-driven evidence models supporting real-time audit readiness Conduct internal reviews of logged events and control activities, escalating issues or gaps to the Director of GRC and provide status updates and reports highlighting trends, risks, and remediation progress. Process Improvement & Collaboration Collaborate with the Director of GRC to design automation-first and AI-enabled workflows that reduce manual effort and enable scalable compliance operations Support the development, rollout, and maintenance of machine-readable compliance documentation (e.g., OSCAL or comparable structured formats) to facilitate interoperability Partner with automation and engineering teams to integrate structured compliance data into Socure's broader risk management and monitoring ecosystem including vulnerability remediation, access requests, and compliance reporting. Monitor regulatory and industry trends for potential impacts to compliance strategy. Public Sector Sales & Customer Engagement Serve as a security subject matter expert for public sector sales activities, translating compliance controls and system capabilities into clear, accurate, and compelling customer-facing narratives. The Analyst is expected to learn the difference between writing that confirms Socure meets a requirement and writing that persuades a public sector buyer that Socure's approach is comfortable and superior to competitors', with the Director retaining final review and approval given the contractual and sales stakes. Support development of external communications such as press releases and customer-facing materials related to security certifications and authorizations. Build and maintain scalable response frameworks (e.g., answer libraries, structured content, or AI-assisted tools) to provide consistency, accuracy, and speed across RFP and RFx responses Monitor Evolving Requirements Monitor new and evolving requirements and perform gap analyses including Updates to applicable NIST Special Publications and other government standards Contract security requirements from new customers Updates to the FedRAMP Program requirements and processes as the program evolves Provide input to standards bodies on evolving standards when applicable Required Qualifications 4+ years of hands-on cybersecurity, compliance, or identity-management experience, including demonstrated personal execution of FedRAMP, GovRAMP, or comparable continuous-monitoring work - running scans, building or maintaining a POA&M, and preparing deviation requests. Public sector experience is a plus but not required. Direct experience with FedRAMP, GovRAMP, and NIST frameworks (800-53, 800-63, 800-171). Proven ability to personally execute continuous monitoring, vulnerability remediation, and compliance reporting. Proven ability to design and improve repeatable compliance processes - identifying inefficiencies, defining clear steps, and building structure where none exists; experience using AI tools (e.g., ChatGPT, Glean, Gemini) and machine-readable formats (e.g., OSCAL) to accelerate that work is a strong plus. Strong communication, organization, and collaboration skills with the ability to manage multiple priorities, including strong written communication and the ability to write persuasively for a customer audience - distinct from writing that is merely compliance-accurate. Ability to adapt to changing requirements Demonstrated customer-facing experience and enough exposure to product or sales positioning to distinguish compliance-accurate writing from writing that persuades a buyer; prior RFP-specific experience is not required. Must be a U.S. Person (U.S. Citizens or U.S. Permanent Residents) residing in the United States and be able to obtain a U.S. OPM NACI clearance. Preferred Qualifications Experience in regulated industries (e.g., financial services, healthcare) and knowledge of privacy and compliance frameworks such as GDPR, CCPA, and key NIST standards. Professional certifications preferred (CISSP, CISM, CISA, IAPP). Proven hands-on contribution to certification and compliance initiatives (FedRAMP, GovRAMP, NIST 800-63/171). Skilled in continuous monitoring, vulnerability management, policy updates, and audit coordination across cross-functional teams. Also valued: a demonstrated track record of identifying and closing process gaps proactively, without waiting for direction. Strong understanding of evolving cybersecurity standards and digital identity regulations, with the ability to translate them into practical risk and compliance improvements. Socure is an equal opportunity employer that values diversity in all its forms within our company. We do not discriminate based on race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. If you need an accommodation during any stage of the application or hiring process-including interview or onboarding support-please reach out to your Socure recruiting partner directly. Follow Us! YouTube | LinkedIn | X (Twitter) | Facebook Socure Inc
- ...global professionals to complete a wide range of engagements for public and private, defense and civilian government, and non-profit... ...082082] candidates with relevant Government And Public Services Sector Experience (functional and technical area expertise also ideal)...SuggestedFull timeContract workTemporary workFor contractorsH1bWork at officeFlexible hours
- ...complete a wide range of engagements for public and private, defense and civilian government... ...Seeks a Risk & Controls Analyst | Human Capital Programmatic Evaluation &... ...relevant Government And Public Services Sector Experience (functional and technical area...SuggestedFull timeContract workTemporary workFor contractorsH1bWork at officeFlexible hours
- ...complete a wide range of engagements for public and private, defense and civilian government... ...Seeks a Governance & Risk Analyst | Human Capital Programmatic Evaluation &... ...relevant Government And Public Services Sector Experience (functional and technical area...SuggestedFull timeContract workTemporary workFor contractorsH1bWork at officeFlexible hours
- ...Governance, Risk & Compliance (GRC) Analyst Washington D.C. CHAOS Industries is redefining modern defense with a multi-product portfolio that gives the ultimate advantage—domain dominance. The company's products are powered by Coherent Distributed Networks (CDN™...SuggestedContract workFor subcontractorCasual workRelocation package
- ...Governance, Risk, & Compliance (GRC) Analyst Washington, DC Remote Full-Time About This Role As a GRC Analyst, you will help organizations navigate the complex landscape of cybersecurity compliance and risk management. You will work directly with clients to assess their...SuggestedFull timeRemote work
- ...Risk & Controls Analyst ProSidian is a Management And Operations Consulting Services firm... ...complete a wide range of engagements for public and private, defense and civilian... ...relevant Government And Public Services Sector Experience (functional and technical area...Full timeContract workWork at office
- ...Role: GRC Analyst Location: Mount Laurel, NJ/ Fort Lauderdale, FL/ Charlotte, NC - Hybrid: 2 days onsite, 3 days work from home Duration: 12 Months Must-have hard skills: 1.) 10+ years of regulatory exam findings, internal audits, technology issues management, or tech...Work from home
- ...complete a wide range of engagements for public and private, defense and civilian government... ...Seeks a Compliance Reporting Analyst | Human Capital Programmatic Evaluation &... ...relevant Government And Public Services Sector Experience (functional and technical area...Full timeContract workTemporary workFor contractorsH1bWork at officeFlexible hours
- A cybersecurity compliance consulting firm is looking for a GRC Analyst to help organizations manage cybersecurity compliance and risk. This fully remote position involves conducting assessments, developing security policies, supporting compliance audits, and collaborating...Remote job
- ...experience with full cycle Risk Management processes, including cATO, Risk Analysis, Risk Register functional application via Service Now IRM/GRC environment. Significant experience with Service Now ecosystem (concentrate on IRM), including cross-functional deployments,...
- Ruleset Security is offering an exciting internship opportunity for a Governance, Risk, and Compliance (GRC) Analyst. This role is perfect for students or recent graduates looking to gain hands‑on experience in cybersecurity, compliance, and risk management. The internship...Remote jobFull timeInternship
$74.2k - $129.8k
We are seeking a Compliance Specialist to join our Global Public Sector Legal Compliance team. In this role, you will support the attorneys on our team who advise on compliance matters related to Amazon's public sector business worldwide, including government contracting...Local areaWorldwideFlexible hoursShift work- Ruleset Security is offering an exciting internship opportunity for a Governance, Risk, and Compliance (GRC) Analyst. This role is perfect for students or recent graduates looking to gain hands-on experience in cybersecurity, compliance, and risk management. The internship...Full timeInternship
- ..., endpoint detection and response tools, vulnerability management suites, and various security solutions. Experience in working with GRC systems/modules. Experience in working across enterprises with various teams beyond security (infrastructure/IT, privacy, compliance,...
$117.2k - $176.7k
To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you are not duplicating efforts.Job CategoryEnterprise Technology & InfrastructureJob DetailsAbout SalesforceSalesforce is the #1 AI CRM, where humans with...Full time$117.2k - $176.7k
...does not hold dual citizenship and agrees to complete a U.S. federal government Minimum Background Investigation (MBI) for a Moderate Public Trust position.Unleash Your PotentialWhen you join Salesforce, you’ll be limitless in all areas of your life. Our benefits and...Full time- ...Analyst Position at M&C Saatchi World Services M&C Saatchi World Services is a full-service marketing company renowned for using... ...strategic communications, behavior change, and marketing support to Public Sector clients with special emphasis on the US Federal Government and...Contract workLive inWork at officeLocal areaImmediate startFlexible hours
$99k - $225k
Enterprise Cybersecurity GRC Governance AnalystThe Opportunity: The Enterprise Cybersecurity (ECS) Governance, Risk, and Compliance... ...National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53 revision 4 and 5, NIST SP 800-60, NIST SP 800-171,...Full timeContract workPart timeLocal areaRemote work- PBS is seeking a Security Analyst II to mature PBS’s governance, risk, and compliance programs, including risk management, policy development, GRC tooling, and AI governance, while providing hands-on security operations support across cloud and on-prem environments. The...
$99k - $232k
...Industry/Sector Not Applicable Specialism Fraud, Investigations & Regulatory Enforcement (FIRE) Management Level Manager Job... ...regulatory requirements and strengthen internal controls across complex public sector engagements. As a Manager you will motivate and develop...Full timeContract workH1b- ...focused on delivering end-to-end solutions and products. Since 1998, we have successfully serviced enterprises across the public and private sectors, and the Department of Defense. Our services span all aspects of business, providing a holistic approach for managing an...
$184k - $230k
Scale's Data Analytics team is centralized, embedding data analysts across delivery, operations, finance, and engineering to turn ambiguous... ...clear, actionable insights. As a Senior Data Analyst for Public Sector, you'll build analytics solutions from the ground up -...Full time- ...complete a wide range of engagements for public and private, defense and civilian government... ...Seeks a Learning Data Analyst | Learning Management System (LMS) & Training... ...relevant Government And Public Services Sector Experience (functional and technical area...Full timeContract workTemporary workFor contractorsH1bWork at officeFlexible hours
- ...complete a wide range of engagements for public and private, defense and civilian government... ...at DescriptionProSidian Seeks a Data Analyst (HR Analytics) | Data Management & Business... ...relevant Government And Public Services Sector Experience (functional and technical area...Full timeContract workTemporary workFor contractorsH1bWork at officeFlexible hours
- ...focused on delivering end-to-end solutions and products. Since 1998, we have successfully serviced enterprises across the public and private sectors, and the Department of Defense. Our services span all aspects of business, providing a holistic approach for managing an...
- ...Job Title Resource Management Analyst Why IDS? IDS believes in resolving conflict and building innovative approaches to do... ...solutions for a diverse range of government, military, nonprofit, and public-sector clients. Locations Gov Site (NCR) Please note,...Local areaFlexible hours
- ...complete a wide range of engagements for public and private, defense and civilian government... ...Seeks a Reporting & Insights Analyst | Human Capital Programmatic Evaluation &... ...relevant Government And Public Services Sector Experience (functional and technical area...Full timeContract workTemporary workFor contractorsH1bWork at officeFlexible hours
- ...complete a wide range of engagements for public and private, defense and civilian government... ...Seeks a Business Process Automation Analyst | Human Capital Technology Support - Intelligent... ...relevant Government And Public Services Sector Experience (functional and technical area...Full timeContract workTemporary workFor contractorsH1bWork at officeFlexible hours
$145.46k - $193.94k
Lumen is the trusted network for the AI‑powered world, connecting people, data, and applications through our expansive fiber network and connected ecosystem. We enable secure, high‑performance connectivity across cloud, edge, and AI workloads for enterprises, governments...Full timeTemporary workWork at officeMonday to Friday- ...complete a wide range of engagements for public and private, defense and civilian government... ...Seeks a Business Process Analyst (Portal Enablement) | Human Capital Technology... ...relevant Government And Public Services Sector Experience (functional and technical area...Full timeContract workTemporary workFor contractorsH1bWork at officeFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to GRC Analyst - Public Sector. Be the first to apply!
- public sector account manager Washington DC
- public service Washington DC
- public sector business analyst Washington DC
- public service officer Washington DC
- public sector consultant Washington DC
- public sector Washington DC
- grc analyst
- public sector account manager
- public service
- public sector business analyst


