Socure Logo

Socure

Analyst, GRC – Public Sector

Posted Yesterday
Remote
Hiring Remotely in USA
95K-115K Annually
Senior level
Remote
Hiring Remotely in USA
95K-115K Annually
Senior level
The Analyst, GRC - Public Sector will manage compliance operations, oversee vulnerability remediation, and streamline processes for FedRAMP and GovRAMP standards.
The summary above was generated by AI
Why Socure?

At Socure, we’re on a mission—to verify 100% of good identities in real time and eliminate identity fraud from the internet.

Using predictive analytics and advanced machine learning trained on billions of signals to power RiskOS™, Socure has created the most accurate identity verification and fraud prevention platform in the world. Trusted by thousands of leading organizations—from top banks and fintechs to government agencies—we solve real, high-impact problems at scale. Come join us!

About the role

Socure is seeking an Analyst, GRC – Public Sector to execute and enhance the company’s governance, risk, and compliance operations for its public sector business. Reporting to the Director of GRC – Public Sector, this role drives measurable improvements in compliance efficiency and audit readiness by managing vulnerability remediation, continuous monitoring, access oversight, and evidence preparation that allow Socure to meet the rigorous standards of FedRAMP, GovRAMP, and related frameworks. The Analyst collaborates across Security, Engineering, IT, DevOps, Product, Legal, and other teams to operationalize regulatory requirements, automate workflows, and offers the opportunity to shape the GRC strategy for Socure’s fast-growing public sector business.

What you'll doCompliance & Certification Management
  • Day-to-day coordination and execution of external Third Party Assessment Organization (3PAO) assessments and responding to auditor requests for evidence and documentation.

  • Maintain and update FedRAMP and GovRAMP controls and documentation in alignment with organizational and regulatory requirements, including controls aligned with NIST SP 800-53 rev 5 and other related frameworks.

  • Prepare certification and authorization packages and maintain related documentation such as the System Security Plan (SSP) and associated appendices.

Continuous Monitoring & Vulnerability Management
  • Lead the day-to-day FedRAMP continuous monitoring process including vulnerability management lifecycle, from identification through remediation and verification, coordinating with Security, Engineering, and DevOps teams to address issues identified with tools such as Wiz, Burp Suite, AWS native services, and other platforms and resolve issues within FedRAMP and GovRAMP timelines.

  • Coordinate recurring continuous monitoring compliance activities such as access reviews, incident response exercises, and contingency plan testing.

Access Management & Training
  • Oversee access controls for FedRAMP environments, including access requests, least privilege reviews and role-based access control validation and quarterly access certifications.

  • Design, implement and deliver FedRAMP training programs to promote compliance awareness

  • Create and manage automated workflows to improve efficiency.

Audit & Assessment Readiness
  • Maintain compliance evidence repositories. audit preparation materials, and reporting artifacts.

  • Conduct internal reviews of logged events and control activities, escalating issues or gaps to the Director of GRC and provide status updates and reports highlighting trends, risks, and remediation progress.

Process Improvement & Collaboration
  • Collaborate with the Director of GRC to design and implement AI-enabled compliance workflows, leveraging automation tools to streamline evidence generation, reporting, and audit readiness

  • Support the development, rollout, and maintenance of machine-readable compliance documentation (e.g., OSCAL or comparable structured formats) to facilitate interoperability

  • Partner with automation and engineering teams to integrate structured compliance data into Socure’s broader risk management and monitoring ecosystem including vulnerability remediation, access requests, and compliance reporting.

  • Monitor regulatory and industry trends for potential impacts to compliance strategy.

Public Sector Sales & Customer Engagement
  • Serve as a security subject matter expert for public sector sales activities, including prospect briefings, RFP/RFQ responses, contract negotiations, and integration discussions.

  • Support development of external communications such as press releases and customer-facing materials related to security certifications and authorizations.

Monitor Evolving Requirements
  • Monitor new and evolving requirements and perform gap analyses including

    • Updates to applicable NIST Special Publications and other government standards

    • Contract security requirements from new customers

    • Updates to the FedRAMP Program requirements and processes as the program evolves

  • Provide input to standards bodies on evolving standards when applicable

What you'll bring
  • 5+ years of cybersecurity or identity management experience, including 1+ year in the public sector.

  • Direct experience with FedRAMP, GovRAMP, and NIST frameworks (800-53, 800-63, 800-171).

  • Proven ability to manage continuous monitoring, vulnerability remediation, and compliance reporting.

  • Experience using AI tools (e.g., ChatGPT, Glean, Gemini) and machine-readable formats (e.g., OSCAL) to automate and streamline compliance processes.

  • Strong communication, organization, and collaboration skills with the ability to manage multiple priorities.

  • Ability to adapt to changing requirements

  • Must be a U.S. Person (U.S. Citizens or U.S. Permanent Residents) residing in the United States and be able to obtain a U.S. OPM NACI clearance.

Preferred Qualifications
  • Experience in regulated industries (e.g., financial services, healthcare) and knowledge of privacy and compliance frameworks such as GDPR, CCPA, and key NIST standards.

  • Professional certifications preferred (CISSP, CISM, CISA, IAPP).

  • Proven success leading certification and compliance initiatives (FedRAMP, GovRAMP, NIST 800-63/171)

  • Skilled in continuous monitoring, vulnerability management, policy updates, and audit coordination across cross-functional teams.

  • Strong understanding of evolving cybersecurity standards and digital identity regulations, with the ability to translate them into practical risk and compliance improvements.

Socure is an equal opportunity employer that values diversity in all its forms within our company. We do not discriminate based on race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.
If you need an accommodation during any stage of the application or hiring process—including interview or onboarding support—please reach out to your Socure recruiting partner directly.

Follow Us!

YouTube | LinkedIn | X (Twitter) | Facebook

Top Skills

Artificial Intelligence
AWS
Burp Suite
Fedramp
Govramp
Nist Sp 800-53
Oscal
Wiz

Similar Jobs

Yesterday
Easy Apply
Remote
United States
Easy Apply
76K-116K Annually
Mid level
76K-116K Annually
Mid level
Artificial Intelligence • Fintech • Hardware • Information Technology • Sales • Software • Transportation
Manage Motive's global gifting and direct mail programs, partnering with cross-functional teams to enhance customer engagement and pipeline conversion.
Top Skills: Postal.IoReachdeskSalesforceSendoso
Yesterday
Easy Apply
Remote or Hybrid
USA
Easy Apply
185K-230K Annually
Senior level
185K-230K Annually
Senior level
Marketing Tech • Real Estate • Software • PropTech • SEO
Lead design initiatives from discovery to launch, collaborating with product and engineering teams to shape product strategy and enhance user experiences. Mentor designers and improve usability through iterative design.
Top Skills: Figma
Yesterday
Easy Apply
Remote
United States
Easy Apply
150K-195K Annually
Senior level
150K-195K Annually
Senior level
Healthtech • Software
Lead the Customer-Facing Actuarial Team, providing actuarial support and insights to customers, managing a team of actuaries, and collaborating across departments to enhance financial impact evaluations.
Top Skills: ExcelPythonRSQL

What you need to know about the Boston Tech Scene

Boston is a powerhouse for technology innovation thanks to world-class research universities like MIT and Harvard and a robust pipeline of venture capital investment. Host to the first telephone call and one of the first general-purpose computers ever put into use, Boston is now a hub for biotechnology, robotics and artificial intelligence — though it’s also home to several B2B software giants. So it’s no surprise that the city consistently ranks among the greatest startup ecosystems in the world.

Key Facts About Boston Tech

  • Number of Tech Workers: 269,000; 9.4% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Thermo Fisher Scientific, Toast, Klaviyo, HubSpot, DraftKings
  • Key Industries: Artificial intelligence, biotechnology, robotics, software, aerospace
  • Funding Landscape: $15.7 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Summit Partners, Volition Capital, Bain Capital Ventures, MassVentures, Highland Capital Partners
  • Research Centers and Universities: MIT, Harvard University, Boston College, Tufts University, Boston University, Northeastern University, Smithsonian Astrophysical Observatory, National Bureau of Economic Research, Broad Institute, Lowell Center for Space Science & Technology, National Emerging Infectious Diseases Laboratories

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account