Onebrief Logo

Onebrief

Compliance Analyst

Posted An Hour Ago
Be an Early Applicant
Remote
Hiring Remotely in United States
180K-210K Annually
Senior level
Remote
Hiring Remotely in United States
180K-210K Annually
Senior level
Lead and sustain Onebrief's governance, risk, and compliance program: manage NIST RMF lifecycle, maintain authorization packages, automate control testing and evidence collection, coordinate assessments and audits, advise on secure architecture, conduct risk and supply-chain assessments, and develop employee cybersecurity training.
The summary above was generated by AI
About Onebrief

Onebrief is collaboration and AI-powered workflow software designed specifically for military staffs. By transforming this work, Onebrief makes the staff as a whole superhuman - meaning faster, smarter, and more efficient.

We take ownership, seek excellence, and play to win with the seriousness and camaraderie of an Olympic team. Onebrief operates as an all-remote company, though many of our employees work alongside our customers at military commands around the world.

Founded in 2019 by a group of experienced planners, today, Onebrief’s team spans veterans from all forces and global organizations, and technologists from leading-edge software companies. We’ve raised $320m+ from top-tier investors, including Battery Ventures, General Catalyst, Sapphire Ventures, Insight Partners, and Human Capital, and today, Onebrief is valued at $2.15B. With this continued growth, Onebrief is able to make an impact where it matters most.

About the Role

You will play a critical role in building and sustaining Onebrief’s governance, risk and compliance program. Leveraging your expertise with NIST RMF and FedRAMP High, you will ensure compliance evidence is created, validated, and continuously organized in various GRC platforms. You will lead efforts to automate control testing, close gaps, and prepare for audits, directly contributing to Onebrief’s ability to obtain and maintain authorizations.

About You

You are a seasoned cybersecurity compliance professional with hands-on experience in federal frameworks and regulatory standards. You excel at translating complex compliance obligations into practical, cloud-native solutions. You thrive in remote, collaborative environments, enjoy solving compliance challenges with both precision and creativity, and are driven by continuous learning and professional growth. Most importantly, you are motivated by building secure, compliant IT ecosystems that enable organizations to scale with confidence.

What You’ll Do
  • Lead and support the full NIST RMF lifecycle for Onebrief deployments, on-prem or cloud-native, across multiple security boundaries

  • Maintain, and review authorization packages, including SSPs, SAPs, SARs, POA&Ms, STIGs, and supporting artifacts

  • Coordinate internal assessments and readiness checks ahead of external audits

  • Partner with Engineers, Product teams, and Security leadership to integrate compliance requirements into system design and operations

  • Provide guidance on secure architecture and control implementation

  • Track regulatory changes and advise leadership on compliance implications

  • Conduct periodic risk assessments and suggest appropriate risk treatment actions

  • Develop internal cybersecurity awareness and training presentations for employees

  • Conduct supply chain risk management assessments for current and future vendors

What We Look For

Basic qualifications
  • Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or a related field

  • Hands-on expertise with Risk Management Framework across multiple security domains

  • U.S. Citizen

  • 8+ years in Cybersecurity Compliance and related roles

  • Experience with Enterprise Mission Assurance Support Service (eMASS) and leveraging automated evidence collection and testing capabilities

  • Familiarity with cloud security standards (e.g., FedRAMP, ISO 27001, NIST 800-171, DoD Cloud Computing Security Requirements Guide)

  • Strong background in policy development, control testing, and evidence gathering

  • Excellent communication skills for working with both technical and non-technical stakeholders

Certifications (one or more required):
  • CISSP, CISM, CISSO, CPTE, CySA+, FITSP-A, GCSA, CISA, ISSEP, GSLC, or GSNA

Preferred qualifications
  • Proven ability to prioritize, adapt, and deliver under tight timelines in dynamic, compliance-driven environments

  • Experience in DoD environments and compliance frameworks (RMF and ICD 503)

  • Familiarity with agency-specific overlays (DoD, DHS, or civilian agencies)

  • Experience working with 3PAOs, Security Control Assessors, and Federal Customers


Notice to Third Party Recruitment Agencies

Please note that Onebrief does not accept unsolicited resumes from recruiters or employment agencies. In the absence of an executed Recruitment Services Agreement, there will be no obligation to any referral compensation or recruiter fee. In the event a recruiter or agency submits a resume or candidate without an agreement Onebrief explicitly reserves the right to pursue and hire those candidate(s) without any financial obligation to the recruiter or agency. Any unsolicited resumes, including those submitted to hiring managers, shall be deemed the property of Onebrief.

Top Skills

Automated Evidence Collection/Testing
Cloud-Native
Dod Cloud Computing Security Requirements Guide
Emass
Fedramp High
Grc Platforms
Iso 27001
Nist Rmf
Nist Sp 800-171
Stigs

Similar Jobs at Onebrief

An Hour Ago
Remote
United States
205K-230K Annually
Senior level
205K-230K Annually
Senior level
Software • Defense
Lead engineering integration of acquired software across infrastructure, security, and product. Own end-to-end delivery for multiple programs, build roadmaps, manage dependencies, drive risk mitigation, ensure compliance artifacts (STIGs, SBOMs, SSPs), communicate status to leadership/customers, and create reusable playbooks and process improvements.
Top Skills: AWSCi/CdContainersDisaFedrampGovcloudKubernetesLinearNist RmfNotionObservabilitySbomsSspStigsZero Trust
An Hour Ago
Remote
United States
210K-240K Annually
Senior level
210K-240K Annually
Senior level
Software • Defense
Lead corporate security monitoring and detection operations: own strategy and maturity roadmap, manage analysts and threat hunters, improve detection coverage and alert quality, support incident investigations, maintain audit-ready documentation, and provide actionable security metrics to leadership and compliance stakeholders.
Top Skills: Alert TuningCloud EnvironmentsDashboardsDetection EngineeringDfirEdrIdentity ProvidersLog ManagementSaas LogsSIEM
An Hour Ago
Remote
United States
210K-240K Annually
Senior level
210K-240K Annually
Senior level
Software • Defense
Lead corporate security engineering to define secure-by-default baselines, oversee vulnerability management, drive automation to prevent configuration drift, govern SaaS security, mentor engineers, and ensure alignment with CMMC 2.0 and NIST 800-53 while improving audit readiness.
Top Skills: Browser Enterprise ManagementCmmc 2.0Disa StigsGrcIdentity And Access Management (Iam)Mdm PlatformsNist 800-53Saas Configuration ManagementSecure Web GatewayVulnerability Management ToolsVulnerability ScannersZero-Trust InfrastructureZscaler

What you need to know about the Los Angeles Tech Scene

Los Angeles is a global leader in entertainment, so it’s no surprise that many of the biggest players in streaming, digital media and game development call the city home. But the city boasts plenty of non-entertainment innovation as well, with tech companies spanning verticals like AI, fintech, e-commerce and biotech. With major universities like Caltech, UCLA, USC and the nearby UC Irvine, the city has a steady supply of top-flight tech and engineering talent — not counting the graduates flocking to Los Angeles from across the world to enjoy its beaches, culture and year-round temperate climate.

Key Facts About Los Angeles Tech

  • Number of Tech Workers: 375,800; 5.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Snap, Netflix, SpaceX, Disney, Google
  • Key Industries: Artificial intelligence, adtech, media, software, game development
  • Funding Landscape: $11.6 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Strong Ventures, Fifth Wall, Upfront Ventures, Mucker Capital, Kittyhawk Ventures
  • Research Centers and Universities: California Institute of Technology, UCLA, University of Southern California, UC Irvine, Pepperdine, California Institute for Immunology and Immunotherapy, Center for Quantum Science and Engineering

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account