Startups

GRC Analyst - Public Sector

Socure · Hub - Washington DC · Remote

← All jobs
About Socure

Socure is the leading AI-powered identity verification platform trusted by 3,000+ customers to verify consumers, businesses, & employees with confidence. Backed by Accel.

About the role

Socure is seeking an Analyst, GRC – Public Sector to own the hands-on execution of the company’s governance, risk, and compliance operations for its public sector business. Reporting to the Director of GRC – Public Sector, this role is responsible day-to-day for running FedRAMP/GovRAMP continuous monitoring, building and maintaining the POA&M and compliance trackers that keep the program audit-ready, and coordinating access reviews, vulnerability remediation, and evidence collection with Security, Engineering, IT,...

What they're looking for

  • Monitor new and evolving requirements and perform gap analyses including
  • Updates to applicable NIST Special Publications and other government standards
  • Contract security requirements from new customers
  • Updates to the FedRAMP Program requirements and processes as the program evolves
  • Provide input to standards bodies on evolving standards when applicable
  • Direct experience with FedRAMP, GovRAMP, and NIST frameworks (800-53, 800-63, 800-171)
More about this role

Socure is building the identity trust infrastructure for the digital economy — verifying 100% of good identities in real time and stopping fraud before it starts. The mission is big, the problems are complex, and the impact is felt by businesses, governments, and millions of people every day.

We hire people who want that level of responsibility. People who move fast, think critically, act like owners, and care deeply about solving customer problems with precision. If you want predictability or narrow scope, this won’t be your place. If you want to help build the future of identity with a team that holds a high bar for itself — keep reading.

Socure is seeking an Analyst, GRC – Public Sector to own the hands-on execution of the company’s governance, risk, and compliance operations for its public sector business. Reporting to the Director of GRC – Public Sector, this role is responsible day-to-day for running FedRAMP/GovRAMP continuous monitoring, building and maintaining the POA&M and compliance trackers that keep the program audit-ready, and coordinating access reviews, vulnerability remediation, and evidence collection with Security, Engineering, IT, DevOps, Product, Legal, and...

Read the full posting on Socure's site ↗

Commercial

Build your edge while you search

Free tools for founders and investors, plus VC Unfiltered, our take on startups, venture and the people who build them.