Qualifications U.S. citizenship (required for FedRAMP program access and federal customer engagements) 3-5 years of hands-on GRC experience, with direct, demonstrable work on NIST control implementation and assessment Direct experience supporting or owning a FedRAMP authorization (Moderate or High baseline) - SSP authorship, POA&M management, or ConMon deliverables Solid understanding of the FedRAMP process, including 3PAO coordination Working knowledge of SOC 2 and ISO 27001 frameworks Excellent written English - you will be authoring SSPs, policies, and customer- and agency-facing documentation Strong cross-team communication skills and comfort working directly with auditors and assessors Ability to work independently and manage multiple compliance workstreams in a fast-paced environment Experience with GRC platforms (e.g., Vanta, Drata, Scytale, or similar)