onebrief - Technical Program Manager, Governance Risk & Compliance - Platform
Upload My Resume
Drop here or click to browse · Tap to choose · PDF, DOCX, DOC, RTF, TXT
Requirements
• PMP or equivalent program management certification • Security+ or equivalent • Proven ability to drive complex, compliance-focused technical programs across multiple stakeholders • Experience operating within DoD or federal compliance frameworks (e.g., RMF, FedRAMP) • Experience supporting Security Control Assessments, external audits, and Federal Customers • Experience managing POA&Ms and remediation efforts in dynamic, cloud-based environments • Excellent communication skills with the ability to brief engineers, leadership, and federal stakeholders • Secret Clearance, TS/SCI Eligible • Notice to Third Party Recruitment Agencies • Please note that Onebrief does not accept unsolicited resumes from recruiters or employment agencies. In the absence of an executed Recruitment Services Agreement, there will be no obligation to any referral compensation or recruiter fee. In the event a recruiter or agency submits a resume or candidate without an agreement Onebrief explicitly reserves the right to pursue and hire those candidate(s) without any financial obligation to the recruiter or agency. Any unsolicited resumes, including those submitted to hiring managers, shall be deemed the property of Onebrief.
Responsibilities
• Accelerate Onebrief’s execution of GRC programs supporting NIST RMF, FedRAMP High, CMMC, and SOC2 authorizations • Develop and manage integrated project plans for control implementation, remediation, and continuous monitoring • Coordinate cross-functional teams (Infrastructure, Engineering, Product) to ensure timely delivery of compliance requirements • Track control implementation status, POA&Ms, and remediation efforts to closure • Support preparation and coordination of Security Control Assessments (SCAs), 3PAOs, and Federal Customer audits • Coordinate and track development of SSP updates, control narratives, and authorization artifacts in partnership with GRC Architects • Track risk assessment outputs and ensure identified risks are translated into actionable remediation plans • Drive the implementation of secure CI/CD practices that meet evolving compliance requirements without blocking velocity. • Support the development and operationalization of scalable governance processes defined by GRC leadership • Ensure configuration management, vulnerability management, and change control activities align with compliance requirements • Identify program risks, dependencies, and blockers, and proactively escalate when necessary • Coach teams on security best practices and contribute to a culture of secure product development. • WHAT WE LOOK FOR • Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, or related field • 8+ years of experience in cybersecurity, compliance, or technical program management roles • Demonstrated experience supporting systems under NIST RMF, FedRAMP, or DoD RMF • Experience managing cross-functional technical programs in cloud-native environments and technologies • Familiarity with eMASS or similar authorization management systems • Experience maintaining or coordinating SSPs, POA&Ms, and authorization packages • Strong understanding of: • AWS Cloud Technologies • NIST SP 800-53 control families • Risk management and continuous monitoring practices • CI/CD and modern DevSecOps workflows • Experience supporting Security Control Assessments or 3PAO audits
Benefits
• Equity: Share in the company's success. • Equity • Flexible Work Environment: Remote-first organization* with flexible work hours and unlimited PTO.(*note that some roles are in-person, on-site with customers) • Flexible Work Environment • Comprehensive Health Coverage: Health, dental, vision, and life insurance. • Comprehensive Health Coverage • Retirement Plan: 401(k) plan with company match to secure your future. • Retirement Plan • Parental Leave: 8 weeks at 100% regardless of state. • Parental Leave • Company Retreats: Annual company summit trips. • Company Retreats • Upload your resume here to autofill key application fields. • Drop your resume here! • Parsing your resume. Autofilling key fields... • Please Note: we have set up limits for applications for this role. It is in the Infrastructure & Security group. The following limits apply to applications for all jobs within this group: • Infrastructure & Security • Candidates may not apply more than 3 times in any 120 day span for any job in the Infrastructure & Security Group. • Candidates may not re-apply to the same role within 180 days if not presented with an offer • or drag and drop here • Due to the nature of this role and access to classified information, an active U.S. security clearance is a strict requirement for employment. • Yes, I currently hold an active security clearance • No, I do not currently hold a clearance • Select the highest level of clearance currently active. • Decline to self-identify • Hispanic or Latino - A person of Cuban, Mexican, Puerto Rican, South or Central American, or other Spanish culture or origin regardless of race. • Hispanic or Latino • White (Not Hispanic or Latino) - A person having origins in any of the original peoples of Europe, the Middle East, or North Africa. • White • Black or African American (Not Hispanic or Latino) - A person having origins in any of the black racial groups of Africa. • Black or African American • Native Hawaiian or Other Pacific Islander (Not Hispanic or Latino) - A person having origins in any of the peoples of Hawaii, Guam, Samoa, or other Pacific Islands. • Native Hawaiian or Other Pacific Islander • Asian (Not Hispanic or Latino) - A person having origins in any of the original peoples of the Far East, Southeast Asia, or the Indian Subcontinent, including, for example, Cambodia, China, India, Japan, Korea, Malaysia, Pakistan, the Philippine Islands, Thailand, and Vietnam. • Asian • American Indian or Alaska Native (Not Hispanic or Latino) - A person having origins in any of the original peoples of North and South America (including Central America), and who maintain tribal affiliation or community attachment. • American Indian or Alaska Native • Two or More Races (Not Hispanic or Latino) - All persons who identify with more than one of the above five races. • Two or More Races • Hispanic or Latino • White (Not Hispanic or Latino) • Black or African American (Not Hispanic or Latino) • Native Hawaiian or Other Pacific Islander (Not Hispanic or Latino) • Asian (Not Hispanic or Latino) • American Indian or Alaska Native (Not Hispanic or Latino) • Two or More Races (Not Hispanic or Latino) • I identify as one or more of the classifications of protected veteran listed above • I am not a protected veteran
No credit card. Takes 10 seconds.