Aquia Inc. Logo

Aquia Inc.

Senior GRC Specialist

Posted Yesterday
Be an Early Applicant
Remote
Hiring Remotely in United States
125K-150K Annually
Senior level
Remote
Hiring Remotely in United States
125K-150K Annually
Senior level
Own GRC activities across federal IT and cybersecurity programs: manage POA&M lifecycle, support FISMA and RMF/ATO processes, prepare audit readiness, track SLAs and availability metrics, produce operational reporting, identify control gaps, and support continuous monitoring and ATO sustainment.
The summary above was generated by AI

About Aquia

Aquia is a Veteran-founded digital services firm that helps the government modernize and secure its systems and processes. Named the “#1 Best Remote Startup to Work For in 2025” by Built In and a certified “Great Place to Work” for five years in a row, we prioritize outcomes over outputs- supporting work that benefits millions of Americans.

The systems we modernize help Veterans access their earned benefits in days instead of weeks, enable investigators to double their health care fraud investigations, and help civil servants achieve system authorizations in roughly a quarter of the time. Our contributions earned us recognition as the Department of Health and Human Services (HHS) Service-Disabled Veteran-Owned Small Business of the Year in 2024.

We hire people who take ownership, raise the bar, and lift up those around them while they do it.


About the Role

All applicants must have an active Top Secret clearance to be considered for this role. Please do not apply if you do not have active Top Secret clearance.

We are seeking a Senior GRC Specialist to own governance, risk, and compliance activities across federal IT and cybersecurity programs. This role sits at the intersection of policy, operations, and accountability, requiring someone who can manage the rigor of FISMA compliance and RMF-driven authorization programs while also keeping a sharp eye on service delivery metrics, SLA performance, and audit readiness.

This is a senior individual contributor role for a practitioner who is equally comfortable drafting POA&M responses, engaging with auditors, and producing operational reporting that gives leadership clear visibility into risk and program health.


What You'll Do
  • Own and manage POA&M lifecycle activities: tracking findings, coordinating remediation, validating closure, and maintaining accurate, audit-ready documentation
  • Support FISMA compliance programs, including evidence collection, continuous monitoring, and coordination with system owners and ISSOs/ISSMs
  • Apply NIST SP 800-53 and NIST SP 800-37 (RMF) to assess control implementation, support authorization activities, and maintain system security postures
  • Manage and report on SLAs and availability metrics for IT and cybersecurity operations; surface trends, flag risks, and drive accountability against commitments
  • Develop and maintain operational reporting for internal leadership and government stakeholders — translating compliance and operational data into clear, actionable insight
  • Lead audit readiness activities: preparing teams and documentation for internal reviews, independent assessments (3PAO/IA), and government audits
  • Identify gaps in control implementation or operational processes and recommend practical, risk-informed mitigation strategies
  • Support continuous monitoring programs and contribute to ongoing ATO/cATO sustainment

Required Qualifications
  • Bachelor's degree in Information Technology, Cybersecurity, Information Systems, or a related field, with 6+ years of relevant experience; equivalent combination of education and demonstrated experience considered
  • Active Top Secret (TS) clearance required: candidates without an active TS clearance will not be considered; sponsorship is not available for this role
  • U.S. citizenship required, must be located in the US.
  • Demonstrated experience supporting FISMA compliance programs in federal environments
  • Working knowledge of NIST SP 800-53 (control families, implementation, and assessment)
  • Working knowledge of NIST SP 800-37 (Risk Management Framework) and the ATO/authorization process
  • Hands-on experience managing POA&M lifecycle: tracking, remediation coordination, evidence validation, and closure
  • Experience preparing for and supporting federal audits and security assessments, including evidence packaging, stakeholder coordination, and finding response
  • Experience managing SLAs and availability metrics in IT service delivery or cybersecurity operations environments
  • Ability to develop and maintain operational reporting that communicates performance and risk posture to technical and executive audiences
  • Experience producing clear, accurate reporting on cybersecurity operations, compliance status, and service health for government and internal stakeholders

Desired Qualifications
  • Experience with eMASS or similar GRC/authorization tracking platforms
  • Familiarity with continuous monitoring (ConMon) program management and reporting
  • Experience working alongside ISSOs, ISSMs, and Authorizing Officials in the RMF process
  • Knowledge of FedRAMP, DoD CC SRG, or agency-specific overlays (e.g., HHS, DoD, DHS)
  • Experience with ITSM platforms (ServiceNow, Jira) for tracking findings and operational workflows
  • Relevant certifications: CISSP, CISM, CAP/CGRC, Security+, or equivalent

Remote - USA
$125,000$150,000 USD

Benefits

  • Premium health care plans (90% employer-paid)
  • Employee stock plan
  • 100% 401k match (up to IRS annual max)
  • Generous PTO package
  • Personal training and development budget

Stay in touch

Sign up for our newsletter to receive updates on cloud and cybersecurity in the public sector and what's new at Aquia.

Aquia Inc. is an equal opportunity employer. We do not discriminate against any employee or applicant for employment because of race, color, sex, age, religion, sexual orientation, gender identity, status as a veteran, and basis of disability or any federal, state, or local protected class.

Similar Jobs

8 Days Ago
In-Office or Remote
Senior level
Senior level
Artificial Intelligence • Machine Learning • Natural Language Processing • Software • Generative AI
This role involves building and scaling compliance programs, translating security and regulatory requirements into scalable solutions, and collaborating across teams, specifically in AI governance and technical compliance automation.
Top Skills: DodFedrampHipaaIso 27001Iso 42001PythonSoc 2
A Minute Ago
Remote or Hybrid
118K-201K Annually
Senior level
118K-201K Annually
Senior level
Aerospace • Hardware • Information Technology • Security • Software • Cybersecurity • Defense
Lead supplier quality for printed wiring boards (PWBs): audit and assess suppliers, conduct source and first-article inspections, drive root-cause analysis and corrective actions, review PPAP/FAI, implement improvement programs, and support PWB commodity team with metrics, failure analysis, and process optimization.
Top Skills: ApqpAs9100As9102Asme Y14.5Asme Y15.1Black BeltControl PlanGreen BeltIpc-6012Ipc-6013Ipc-6018Ipc-A-600Ipc-A-610Ipc-Tm-650Lean Six SigmaMil-Prf-31032Mil-Prf-38534Mil-Prf-55110Mil-Std-883PfmeaPpap
6 Minutes Ago
Remote
United States
115K-150K Annually
Senior level
115K-150K Annually
Senior level
Artificial Intelligence • Fintech • Software
Pre-sales SAP technical consultant supporting late-stage sales: advise on SAP (S/4HANA, ECC) integrations, design/validate integration workflows, map financial data to SAP structures, demonstrate integration requirements, deliver POCs, and relay product gaps to engineering.
Top Skills: AcdocaCloud StorageFloqastJSONOdataOn-Premise ConnectorPublic Api EndpointsPythonRegexRestful ApisSAMLSap Business Technology Platform (Btp)Sap EccSap Integration SuiteSap S/4HanaSftpSQLSso

What you need to know about the Los Angeles Tech Scene

Los Angeles is a global leader in entertainment, so it’s no surprise that many of the biggest players in streaming, digital media and game development call the city home. But the city boasts plenty of non-entertainment innovation as well, with tech companies spanning verticals like AI, fintech, e-commerce and biotech. With major universities like Caltech, UCLA, USC and the nearby UC Irvine, the city has a steady supply of top-flight tech and engineering talent — not counting the graduates flocking to Los Angeles from across the world to enjoy its beaches, culture and year-round temperate climate.

Key Facts About Los Angeles Tech

  • Number of Tech Workers: 375,800; 5.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Snap, Netflix, SpaceX, Disney, Google
  • Key Industries: Artificial intelligence, adtech, media, software, game development
  • Funding Landscape: $11.6 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Strong Ventures, Fifth Wall, Upfront Ventures, Mucker Capital, Kittyhawk Ventures
  • Research Centers and Universities: California Institute of Technology, UCLA, University of Southern California, UC Irvine, Pepperdine, California Institute for Immunology and Immunotherapy, Center for Quantum Science and Engineering

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account