Rapid7 Logo

Rapid7

US Public Sector Compliance Analyst

Posted 10 Days Ago
Remote or Hybrid
Hiring Remotely in Arlington, VA
Junior
Remote or Hybrid
Hiring Remotely in Arlington, VA
Junior
Support Rapid7's US Public Sector compliance programs mainly focusing on FedRAMP, maintaining compliance documentation, tracking controls, and managing risks.
The summary above was generated by AI
About the Role
Are you interested in helping shape how cybersecurity works across the US public sector while building a strong foundation in Trust, Risk, and Compliance (TRC)? This role offers the opportunity to grow your career while contributing directly to Rapid7's mission of making the digital world safer.
As a Trust, Risk, and Compliance Analyst, you will support Rapid7's expanding US Public Sector compliance programs, including FedRAMP, GovRAMP, TX-RAMP, and COV-RAMP. As part of the Trust, Risk, and Compliance team within the broader Information Security organization, you will help build, operate, and continuously improve scalable compliance and risk management programs that enable our Federal and SLED customers to succeed.
This role is based in Boston and/or Arlington and is part of a team that values collaboration, curiosity, balance, and continuous learning.
About the Team
Rapid7's Trust, Risk & Compliance team sits within Information Security and plays a critical role in building customer trust. We design and operate governance programs, manage security risk, and help teams across Rapid7 understand and meet regulatory and security expectations. Our work spans Engineering, Product, Platform, Legal, Procurement, Sales, and Customer Success - and we do it with a mindset that security should enable the business, not slow it down.
In This Role, You Will
  • Support day-to-day activities for Rapid7's US Public Sector compliance programs, with a primary focus on FedRAMP
  • Assist in maintaining compliance documentation, including policies, procedures, system security plans (SSPs), authorization artifacts, and supporting evidence
  • Support continuous monitoring (ConMon) activities, including ongoing evidence collection and reporting
  • Assist in managing Plans of Action & Milestones (POA&Ms), including tracking remediation progress, timelines, and risk ownership
  • Track and support control implementation aligned to NIST 800-53 rev. 5 and NIST 800-171
  • Use ATO-focused GRC platforms such as Paramify, ServiceNow GRC, Onspring, or RegScale to manage compliance status, risks, and findings
  • Partner with Engineering and Security teams to understand technical control implementations, vulnerabilities, and remediation plans
  • Support audit and assessment readiness activities, including ATO packages and regulatory reporting
  • Assist with vendor reviews, including Control Implementation Summaries (CIS) and Customer Responsibility Matrices (CRM)
  • Help identify opportunities to improve GRC, POA&M, and ConMon processes through standardization, automation, and improved data quality
  • Gain hands-on exposure to evolving requirements such as CMMC, new Executive Orders, and emerging US public sector cybersecurity initiatives

The Skills You'll Bring
  • 2-5 years of experience (or equivalent academic, internship, or early-career experience) in cybersecurity, risk, compliance, governance, or cloud security
    (Candidates with slightly more experience are welcome to apply)
  • Foundational knowledge of NIST 800-53 and/or NIST 800-171
  • Interest in US Government and SLED cybersecurity programs (FedRAMP, GovRAMP, StateRAMP)
  • Experience or familiarity with ATO-focused GRC platforms such as Paramify, ServiceNow GRC, Onspring, or RegScale
  • Ability to understand and document both policy-based and technical security controls
  • Strong analytical skills, attention to detail, and comfort working with structured documentation
  • Clear written and verbal communication skills
  • A curious, collaborative mindset and eagerness to learn

Nice to Have
  • Exposure to AWS or cloud-based environments
  • Familiarity with vulnerability management, security scanning, or cloud security concepts
  • Experience or interest in POA&M workflows, continuous monitoring, or risk remediation
  • Familiarity with frameworks such as FISMA, CMMC, StateRAMP, or ISO 27001
  • Interest in compliance automation, OSCAL, or policy-as-code approaches
  • Early-career certifications or coursework in cybersecurity, cloud security, or information assurance

We Know That...
The best ideas and solutions come from multi-dimensional teams. That's because these teams reflect a variety of backgrounds and professional experiences. If you're excited about this role and feel your experience can make an impact, we encourage you to apply.
#LI-WP1
About Rapid7
At Rapid7, our vision is to create a secure digital world for our customers, our industry, and our communities. We do this by harnessing our collective expertise and passion to challenge what's possible and drive extraordinary impact. We're building a dynamic and collaborative workplace where new ideas are welcome.
Protecting 11,000+ customers against bad actors and threats means we're continuing to push the envelope just like we' ve been doing for the past 20 years. If you 're ready to solve some of the toughest challenges in cybersecurity, we're ready to help you take command of your career. Join us.
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, protected veteran status or any other status protected by applicable national, federal, state or local law.

Top Skills

AWS
Fedramp
Govramp
Nist 800-171
Nist 800-53
Onspring
Paramify
Regscale
Servicenow Grc
HQ

Rapid7 Boston, Massachusetts, USA Office

Rapid7 Boston Office

Rapid7 is located next to TD Garden and North Station. The Garden is home to the Boston Bruins, Boston Celtics, and year round musical performances and entertainment events. North station provides easy access to public transportation through the T and Commuter Rail.

Similar Jobs at Rapid7

4 Days Ago
Remote or Hybrid
United States
89K-121K Annually
Senior level
89K-121K Annually
Senior level
Artificial Intelligence • Cloud • Information Technology • Sales • Security • Software • Cybersecurity
The Senior Product Security Consultant evaluates IT architecture, automates solutions, and communicates security best practices while working closely with clients to enhance their security programs using Rapid7 products.
Top Skills: Amazon Web ServicesGoogle Cloud PlatformAzurePowershellPythonSQL
4 Days Ago
Remote or Hybrid
United States
169K-229K Annually
Senior level
169K-229K Annually
Senior level
Artificial Intelligence • Cloud • Information Technology • Sales • Security • Software • Cybersecurity
Lead the Cloud Optimization Engineering team, influence engineering decisions around cost, and ensure efficient scaling of the SaaS platform.
Top Skills: AWSAzureGCPSaaS
6 Days Ago
Remote or Hybrid
United States
190K-257K Annually
Senior level
190K-257K Annually
Senior level
Artificial Intelligence • Cloud • Information Technology • Sales • Security • Software • Cybersecurity
Lead the Customer Success department to enhance retention and growth through strategic leadership, team development, and cross-functional collaboration, while managing complex account scenarios and key performance indicators.
Top Skills: CRMCsm Platforms

What you need to know about the Boston Tech Scene

Boston is a powerhouse for technology innovation thanks to world-class research universities like MIT and Harvard and a robust pipeline of venture capital investment. Host to the first telephone call and one of the first general-purpose computers ever put into use, Boston is now a hub for biotechnology, robotics and artificial intelligence — though it’s also home to several B2B software giants. So it’s no surprise that the city consistently ranks among the greatest startup ecosystems in the world.

Key Facts About Boston Tech

  • Number of Tech Workers: 269,000; 9.4% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Thermo Fisher Scientific, Toast, Klaviyo, HubSpot, DraftKings
  • Key Industries: Artificial intelligence, biotechnology, robotics, software, aerospace
  • Funding Landscape: $15.7 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Summit Partners, Volition Capital, Bain Capital Ventures, MassVentures, Highland Capital Partners
  • Research Centers and Universities: MIT, Harvard University, Boston College, Tufts University, Boston University, Northeastern University, Smithsonian Astrophysical Observatory, National Bureau of Economic Research, Broad Institute, Lowell Center for Space Science & Technology, National Emerging Infectious Diseases Laboratories

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account