Support continuous monitoring and compliance for Rapid7's US Public Sector programs, manage POA&Ms, analyze security findings, and enhance processes.
About the Role
Are you interested in helping strengthen how cybersecurity risk is managed across the US public sector while building hands-on experience in Trust, Risk, and Compliance (TRC)? This role offers the opportunity to grow your career while contributing directly to Rapid7's mission of making the digital world safer.
As a Trust, Risk, and Compliance Analyst - Continuous Monitoring & POA&M, you will support Rapid7's expanding US Public Sector compliance programs, including FedRAMP, GovRAMP, TX-RAMP, and COV-RAMP, with a strong focus on continuous monitoring, POA&M management, and technical risk tracking. As part of the Trust, Risk, and Compliance team within the broader Information Security organization, you will help ensure security risks are identified, tracked, and remediated in a way that scales with Rapid7's cloud-based products and services.
This role is based in Boston and/or Arlington and is part of a team that values collaboration, curiosity, balance, and continuous learning.
About the Team
Rapid7's Trust, Risk & Compliance team sits within Information Security and plays a critical role in building customer trust. We design and operate governance programs, manage security risk, and help teams across Rapid7 understand and meet regulatory and security expectations. Our work spans Engineering, Product, Platform, Legal, Procurement, Sales, and Customer Success - and we do it with a mindset that security should enable the business, not slow it down.
In This Role, You Will
The Skills You'll Bring
Nice to Have
We Know That...
The best ideas and solutions come from multi-dimensional teams. That's because these teams reflect a variety of backgrounds and professional experiences. If you're excited about this role and feel your experience can make an impact, we encourage you to apply.
LI-WP1
About Rapid7
At Rapid7, our vision is to create a secure digital world for our customers, our industry, and our communities. We do this by harnessing our collective expertise and passion to challenge what's possible and drive extraordinary impact. We're building a dynamic and collaborative workplace where new ideas are welcome.
Protecting 11,000+ customers against bad actors and threats means we're continuing to push the envelope just like we' ve been doing for the past 20 years. If you 're ready to solve some of the toughest challenges in cybersecurity, we're ready to help you take command of your career. Join us.
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, protected veteran status or any other status protected by applicable national, federal, state or local law.
Are you interested in helping strengthen how cybersecurity risk is managed across the US public sector while building hands-on experience in Trust, Risk, and Compliance (TRC)? This role offers the opportunity to grow your career while contributing directly to Rapid7's mission of making the digital world safer.
As a Trust, Risk, and Compliance Analyst - Continuous Monitoring & POA&M, you will support Rapid7's expanding US Public Sector compliance programs, including FedRAMP, GovRAMP, TX-RAMP, and COV-RAMP, with a strong focus on continuous monitoring, POA&M management, and technical risk tracking. As part of the Trust, Risk, and Compliance team within the broader Information Security organization, you will help ensure security risks are identified, tracked, and remediated in a way that scales with Rapid7's cloud-based products and services.
This role is based in Boston and/or Arlington and is part of a team that values collaboration, curiosity, balance, and continuous learning.
About the Team
Rapid7's Trust, Risk & Compliance team sits within Information Security and plays a critical role in building customer trust. We design and operate governance programs, manage security risk, and help teams across Rapid7 understand and meet regulatory and security expectations. Our work spans Engineering, Product, Platform, Legal, Procurement, Sales, and Customer Success - and we do it with a mindset that security should enable the business, not slow it down.
In This Role, You Will
- Support continuous monitoring (ConMon) activities for Rapid7's US Public Sector compliance programs, with a primary focus on FedRAMP and GovRAMP
- Assist in managing Plans of Action & Milestones (POA&Ms), including tracking remediation progress, timelines, and risk ownership
- Help analyze security findings, vulnerability results, and control deficiencies in partnership with Engineering and Security teams
- Support technical evidence collection aligned to NIST 800-53 rev. 5 and NIST 800-171
- Use ATO-focused GRC platforms such as Paramify, ServiceNow GRC, Onspring, RegScale, and DefectDojo to track findings, risks, and compliance status
- Participate in discussions with engineers to understand control implementations, technical risks, and remediation approaches
- Assist with preparation of ConMon deliverables (POA&M, deviation requests, inventory workbook)
- Help improve POA&M and ConMon processes through standardization, automation, and improved data quality
- Gain hands-on exposure to evolving requirements such as CMMC, new Executive Orders, and other US public sector cybersecurity initiatives
The Skills You'll Bring
- 2-5 years of experience (or equivalent academic/internship experience) in cybersecurity, cloud security, compliance, or risk management
- Foundational knowledge of NIST 800-53 and/or NIST 800-171
- Interest in vulnerability management, risk remediation, and continuous monitoring
- Experience or familiarity with ATO-focused GRC platforms such as Paramify, ServiceNow GRC, Onspring, or RegScale
- Ability to understand and document technical security issues and risks
- Strong analytical skills and attention to detail
- Clear written and verbal communication skills
- A curious, collaborative mindset and eagerness to learn
Nice to Have
- Exposure to AWS or cloud-based environments
- Familiarity with vulnerability management tools or security scanning concepts
- Experience or interest in POA&M workflows, risk tracking, or control remediation
- Interest in compliance automation, OSCAL, or data-driven compliance approaches
- Early-career certifications or coursework in cybersecurity, cloud security, or information assurance
We Know That...
The best ideas and solutions come from multi-dimensional teams. That's because these teams reflect a variety of backgrounds and professional experiences. If you're excited about this role and feel your experience can make an impact, we encourage you to apply.
LI-WP1
About Rapid7
At Rapid7, our vision is to create a secure digital world for our customers, our industry, and our communities. We do this by harnessing our collective expertise and passion to challenge what's possible and drive extraordinary impact. We're building a dynamic and collaborative workplace where new ideas are welcome.
Protecting 11,000+ customers against bad actors and threats means we're continuing to push the envelope just like we' ve been doing for the past 20 years. If you 're ready to solve some of the toughest challenges in cybersecurity, we're ready to help you take command of your career. Join us.
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, protected veteran status or any other status protected by applicable national, federal, state or local law.
Top Skills
AWS
Defectdojo
Nist 800-171
Nist 800-53
Onspring
Paramify
Regscale
Servicenow Grc
Similar Jobs at Rapid7
Artificial Intelligence • Cloud • Information Technology • Sales • Security • Software • Cybersecurity
Support Rapid7's US Public Sector compliance programs mainly focusing on FedRAMP, maintaining compliance documentation, tracking controls, and managing risks.
Top Skills:
AWSFedrampGovrampNist 800-171Nist 800-53OnspringParamifyRegscaleServicenow Grc
Artificial Intelligence • Cloud • Information Technology • Sales • Security • Software • Cybersecurity
The Director of North America Channel Sales leads the channel sales strategy, develops partnerships, and manages the sales team to achieve revenue goals.
Top Skills:
Security Saas Solutions
Artificial Intelligence • Cloud • Information Technology • Sales • Security • Software • Cybersecurity
The Vector Command Specialist supports customers by analyzing attack surfaces, coordinating security consulting operations, and providing reports and communication on security posture improvements.
Top Skills:
Attack Surface Management StrategiesOsint TechniquesPenetration Testing ToolsPowershellPython
What you need to know about the Los Angeles Tech Scene
Los Angeles is a global leader in entertainment, so it’s no surprise that many of the biggest players in streaming, digital media and game development call the city home. But the city boasts plenty of non-entertainment innovation as well, with tech companies spanning verticals like AI, fintech, e-commerce and biotech. With major universities like Caltech, UCLA, USC and the nearby UC Irvine, the city has a steady supply of top-flight tech and engineering talent — not counting the graduates flocking to Los Angeles from across the world to enjoy its beaches, culture and year-round temperate climate.
Key Facts About Los Angeles Tech
- Number of Tech Workers: 375,800; 5.5% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Snap, Netflix, SpaceX, Disney, Google
- Key Industries: Artificial intelligence, adtech, media, software, game development
- Funding Landscape: $11.6 billion in venture capital funding in 2024 (Pitchbook)
- Notable Investors: Strong Ventures, Fifth Wall, Upfront Ventures, Mucker Capital, Kittyhawk Ventures
- Research Centers and Universities: California Institute of Technology, UCLA, University of Southern California, UC Irvine, Pepperdine, California Institute for Immunology and Immunotherapy, Center for Quantum Science and Engineering

