远程工作雷达

FedRAMP合规分析师

FedRamp Compliance Analyst

开发工程限定地区(需当地身份)
公司Abnormal
薪资未公开
工作地点Remote - USA
地域资格限定地区(需当地身份)
时区要求无特别要求
用工类型未标注
发布时间14 天前
数据来源Greenhouse
前往企业招聘页投递 →
注意地域限制:该职位明确限定在 Remote - USA 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。

职位描述

Abnormal AI 正在寻找一位联邦安全与合规分析师,希望帮助构建现代联邦合规性在快速发展的网络安全公司中的运作方式。

您将处于安全工程、云运维、安全和联邦合规的交汇点,帮助 Abnormal Gov 扩展其 FedRAMP High/Class D 安全和合规计划。您将负责安全需求的实施和证据,直接与技术团队合作推动风险和修复至关闭,并帮助我们建立符合 FedRAMP 20x 的合规即代码能力。

您将早期就拥有重要的责任,有机会改进流程而非仅仅继承现有流程。最优秀的候选人应具备技术好奇心,高度组织性,能够自如应对不确定性,并且有动力让合规性更加准确、自动化、可衡量并具有操作性。

您将负责的工作包括:

  • 从需求解读到实施、证据收集、修复和审查准备,负责指定的联邦安全和合规工作流。
  • 推动持续监控和证据工作流,协调安全、FedOps、工程、IT、人力资源运营、GRC 和其他控制执行者,确保证据保持最新、完整、可追溯并正确保存。
  • 支持漏洞检测和响应,包括整合 Wiz、Nessus 和 Burp 等工具的发现结果;基于风险的优先级排序;Jira 路由;SLA 跟踪;修复跟进;验证;以及审计准备的证据。
  • 与技术团队合作处理安全和合规影响,支持安全影响评估、重大变更请求、控制实施决策和其他变更管理活动,在变更进入生产环境之前进行支持。
  • 帮助构建 Abnormal 的合规即代码计划,包括结构化的控制内容、JSON/YAML 或其他机器可读的工件、模式验证、证据索引、自动化、确定性文档生成和可重用的工作流。
  • 维护准确的控制、证据、修复、风险和所有权记录,主动识别差距、过期项、依赖关系和需要升级的决策。
  • 为联邦授权和评估文件做出贡献,包括控制文档、安全决策记录、认证包内容、评估员请求和持续监控交付物。
  • 支持联邦相关工作
查看英文原文

About the Role

Abnormal AI is looking for a Federal Security and Compliance Analyst who wants to help build how modern federal compliance operates inside a fast-moving cybersecurity company.

You will work at the intersection of security engineering, cloud operations, security, and federal compliance, helping Abnormal Gov scale its FedRAMP High/Class D security and compliance program. You will own security requirement implementation and evidence, work directly with technical teams to drive risk and remediation to closure, and help build our compliance as code capabilities in alignment with FedRAMP 20x.

You'll have meaningful ownership early, with the opportunity to improve processes rather than simply inherit them. The strongest candidate will be technically curious, highly organized, comfortable navigating ambiguity, and motivated by making compliance more accurate, automated, measurable, and operationally useful.

What you will do

  • Own assigned federal security and compliance workstreams from requirement interpretation through implementation, evidence collection, remediation, and review readiness.
  • Drive recurring continuous monitoring and evidence workflows, coordinating across Security, FedOps, Engineering, IT, People Operations, GRC, and other control performers to ensure evidence is current, complete, traceable, and retained correctly.
  • Support vulnerability detection and response, including reconciling findings from tools such as Wiz, Nessus, and Burp; risk-based triage; Jira routing; SLA tracking; remediation follow-through; validation; and audit-ready evidence.
  • Partner with technical teams on security and compliance impact, supporting Security Impact Assessments, Significant Change Requests, control implementation decisions, and other change-management activities before changes reach production.
  • Help build Abnormal's compliance-as-code program, including structured control content, JSON/YAML or other machine-readable artifacts, schema validation, evidence indexing, automation, deterministic document generation, and reusable workflows.
  • Maintain accurate control, evidence, remediation, risk, and ownership records, proactively identifying gaps, aging items, dependencies, and decisions requiring escalation.
  • Contribute to federal authorization and assessment artifacts, including control documentation, Security Decision Records, certification-package content, assessor requests, and continuous monitoring deliverables.
  • Support federal customer assurance by providing clear, accurate compliance guidance and artifacts for customer onboarding, POVs, DDQs, RFPs, and other government or regulated customer requests.

Must Haves

  • 2+ years of experience in security, compliance, GRC, risk, audit, security operations, or a related discipline, preferably in a cloud, SaaS, government, or highly regulated environment.
  • Working knowledge of NIST SP 800-53 and an understanding of how security controls translate into technical implementation, operational processes, and audit evidence.
  • Experience with one or more core compliance operations such as evidence collection, control documentation, vulnerability remediation, risk tracking, audit support, or continuous monitoring.
  • Technical curiosity and the ability to read architecture diagrams, security documentation, vulnerability findings, Jira tickets, logs, or engineering materials and turn them into clear compliance actions.
  • Ability to work effectively with Security, Engineering, Infrastructure/Operations, IT, and other technical teams without needing every problem or requirement to be fully defined in advance.
  • Strong written communication skills and the ability to produce documentation that is precise enough for assessors and technical teams while remaining understandable to non-technical stakeholders.
  • Strong operational discipline: you can manage multiple workstreams, dependencies, owners, and deadlines while identifying problems and escalating risk early.
  • A demonstrated tendency to improve the way work gets done through automation, better processes, clearer documentation, reusable templates, better data, or simpler workflows.

.

Nice to Have

  • Experience with FedRAMP High, FedRAMP Moderate, FISMA, CMMC, GovRAMP, or other U.S. government security frameworks.
  • Exposure to compliance-as-code, OSCAL, JSON/YAML schemas, Git-based workflows, automated validation, Markdown/PDF generation, or machine-readable authorization artifacts.
  • Familiarity with tools or environments such as AWS GovCloud, Wiz, Splunk, Okta, Jira, GitLab, Nessus, Burp, or cloud-native vulnerability-management platforms.
  • Experience supporting Security Impact Assessments, Significant Change Requests, POA&M/ConMon workflows, 3PAO assessments, or federal authorization packages.
  • Basic scripting or automation experience—such as Python, APIs, CI/CD workflows, or data transformation—or a strong interest in developing those skills.

#LI-PP1
Actual compensation will be determined based on several non-discriminatory factors including skills, experience, qualifications, and geographic location.
In addition to base salary, this role may be eligible for bonus or incentive compensation, equity, and a comprehensive benefits package.

Base salary range:
$114,800—$173,250 USD

A note on AI in our process: 
Abnormal AI uses AI-assisted tools to help our recruiting team prepare for candidate interviews. These tools analyze resume content and role requirements to suggest interview questions and areas for the interviewer to explore.They do not make hiring decisions or screen candidates automatically. Every decision about a candidacy is made by a person. Further, if your application is successful and Abnormal AI makes a conditional offer of employment, we will carry out pre-employment checks which must be successfully completed to progress to a final offer. All processes and pre-employment checks are in line with prevailing legislation and Abnormal AI's policies relevant to our security and privacy standards.

Abnormal AI is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, protected veteran status or other characteristics protected by law. For our EEO policy statement please click here. If you would like more information on your EEO rights under the law, please click here.

本页面信息整理自 Greenhouse,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

← 返回全部职位