We are seeking a Technical Customer Support Representative (REMOTE) for a full-time and direct hire role for one of our amazing partners. This role is remote, but you MUST be living in the United States and be a US Citizen or Green Card Holder. This role does NOT offer sponsorship, it's NOT a consulting role, and we do NOT work with 3rd parties!
Overview
We are seeking a GRC Analyst to help build and expand a formal Governance, Risk, and Compliance program within a growing technology organization that serves government and other highly regulated customers. You will play a key part in supporting SOC 2 and GovRAMP initiatives, maintaining the controls and evidence required for audits, managing compliance-related documentation, and helping communicate the organization's security posture to customers and government agencies. This is an opportunity to build and improve processes, rather than simply maintain an established program. You will work across engineering, compliance, sales, and product teams to turn security and regulatory requirements into practical, well-documented processes.
This is an opportunity to join a growing organization at an important stage of its compliance journey. You will have the opportunity to help establish scalable GRC processes, strengthen audit readiness, support government contracting opportunities, and work directly with technical and business leaders to build a mature security and compliance function.
Responsibilities:
- Governance, Risk & Compliance
- Support the ongoing development and administration of the organization's GRC program. Help maintain compliance with frameworks and requirements including NIST SP 800-53, CJIS Security Policy, SOC 2, and GovRAMP.
- Maintain the enterprise risk register and assist with periodic risk assessments.
- Monitor control performance and identify areas requiring remediation or improvement.
- Develop, update, organize, and maintain security and compliance policies and procedures.
- Manage policy version control, approvals, annual reviews, and employee attestations.
- Audit & Authorization Support
- Provide hands-on support for SOC 2 and GovRAMP audit and authorization activities.
- Assist with gap assessments and track remediation efforts through completion.
- Collect, organize, validate, and maintain audit evidence.
- Work closely with engineering and other technical teams to identify and complete compliance-related requirements.
- Help ensure controls are consistently documented and supported by appropriate evidence.
- Customer Security & Compliance
- Act as a primary point of contact for customer security questionnaires, vendor assessments, and compliance reviews.
- Develop and maintain a centralized library of approved responses and supporting documentation.
- Improve the efficiency and consistency of questionnaire responses while reducing duplicate work.
- Maintain customer-facing materials that accurately describe the organization's security, privacy, and compliance posture.
- Coordinate responses to recurring customer and third-party risk assessments.
- Contract Compliance
- Monitor contractual requirements related to security, privacy, compliance, reporting, and service obligations.
- Maintain a centralized calendar of recurring contractual deliverables and deadlines.
- Coordinate items such as monthly and quarterly reports, SLA documentation, insurance certificates, certifications, and other required compliance materials.
- Ensure commitments made to government and commercial customers are tracked through completion.
- RFPs & Government Proposals
- Partner with the Growth team on government and public-sector RFPs, solicitations, and proposal opportunities.
- Develop and edit security, technical, compliance, and management sections of proposals.
- Support proposal amendments, customer questions, formal responses, and post-award activities.
- Create reusable proposal content and maintain a library of approved security and compliance language.
- Translate technical security capabilities into clear, compelling information that can be evaluated by procurement and government stakeholders.
Requirements:
- 3–5+ years of experience in GRC, security compliance, information security, internal audit, or a related discipline.
- Experience working within a federal, regulated, or cloud-based technology environment.
- Hands-on participation in at least one complete audit or authorization cycle involving SOC 2, FedRAMP, StateRAMP/GovRAMP, ISO 27001, CMMC, or a comparable framework.
- Working knowledge of NIST SP 800-53, SOC 2, and GovRAMP requirements.
- Technical understanding of cloud and/or on-premises environments, including areas such as
- Identity and access management, Encryption, Security logging and monitoring, Network architecture, Software development lifecycle and change management.
- Practical experience using AI tools for research, drafting, documentation, analysis, or evidence-management activities.
- Strong cross-functional communication skills to move comfortably between technical and business environments. You will take complex engineering concepts and turn them into clear documentation for auditors, customers, and procurement teams, and then translate compliance requirements into actionable tasks for technical teams.
- An evidence-first mindset to understand that saying a control is in place isn't enough. You know how to identify, collect, organize, and validate the evidence necessary to demonstrate that a control is operating effectively.
- Builder mentality where you are comfortable creating structure where processes are still evolving. You don't need an established playbook to get started and can develop practical workflows that scale as the organization grows.
- Organization & execution skills to manage multiple priorities, stakeholders, and deadlines simultaneously, particularly when working toward externally driven audit, certification, or proposal deadlines.
- Strategic thinking with hands-on execution skills. You should be comfortable balancing immediate compliance needs with longer-term improvements to systems, documentation, and processes.
- Adaptability to thrive in an environment where priorities can change quickly and are comfortable taking ownership, solving problems independently, and creating new approaches when necessary.
- Strong written and verbal communication skills.
- Demonstrated ability to coordinate several concurrent initiatives while meeting firm external deadlines.
- Ability to work independently and establish processes without extensive direction.
Preferred Experience
- Experience with the CJIS Security Policy, FBI NGI, or criminal justice information systems.
- Experience supporting government or public-sector RFPs and proposal development.
- Familiarity with compliance automation platforms such as Vanta, Drata, or similar tools.
- Experience working directly with government agencies or organizations subject to federal security requirements.
All qualified applicants will receive consideration for employment without regard to race, color, national origin, age, ancestry, religion, sex, sexual orientation, gender identity, gender expression, marital status, disability, medical condition, genetic information, pregnancy, or military or veteran status.