Jobgether
Jobgether

GRC Engineer (NIST)

engineeringfull-timeUS
SALARY
Not listed
WORK TYPE
remote
JOB TYPE
full-time
INDUSTRY
general
Apply for this position
✦ AutoApply Let us apply to roles like this on your behalf.
Learn more

About the role

Accountabilities:

    • Execute NIST SP 800-53 control mappings and apply applicable security and privacy baselines to client architectures and environments.
    • Create, update, and maintain System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), security narratives, and other authorization documentation.
    • Conduct technical gap assessments, readiness reviews, and compliance analyses to prepare clients for federal ATO and FedRAMP authorization activities.
    • Support continuous monitoring activities, including vulnerability tracking, POA&M maintenance, monthly reporting, and change management.
    • Coordinate Assessment and Authorization activities with clients, third-party assessment organizations (3PAOs), and independent assessors.
    • Partner with technical teams to identify and remediate control deficiencies across Low, Moderate, and High security baselines.
    • Assist with documenting authorization boundaries, system interconnections, shared-responsibility models, and cloud security architectures.
    • Monitor updates to NIST SP 800-53, FedRAMP requirements, and other federal cybersecurity policies, translating changes into actionable client guidance.
    • Manage multiple compliance workstreams simultaneously while maintaining accuracy, documentation quality, deadlines, and clear stakeholder communication.
    • Contribute to a collaborative team culture through knowledge sharing, mentoring, proactive problem-solving, and ownership of assigned deliverables.
    • Requirements:

      • 2+ years of direct experience delivering GRC activities involving NIST SP 800-53, FedRAMP, NIST Risk Management Framework (RMF), or comparable federal compliance programs.
      • Hands-on experience developing, reviewing, and maintaining SSPs, POA&Ms, technical security narratives, and related authorization artifacts.
      • Foundational knowledge of NIST SP 800-53 controls and FedRAMP Moderate and High baselines.
      • Experience supporting ATO processes, 3PAO assessments, or federal authorization activities is highly valuable.
      • Familiarity with government cloud environments such as AWS GovCloud or Azure Government and their security configurations.
      • Understanding of continuous monitoring processes, including vulnerability management, POA&M updates, and compliance reporting.
      • Exposure to CMMC 2.0 or NIST SP 800-171 and defense-industry compliance requirements is an advantage.
      • Relevant certifications such as CGRC, CAP, CISSP, or CompTIA Security+ are preferred.
      • Strong written and verbal English communication skills, with the ability to explain complex compliance requirements clearly to technical and non-technical stakeholders.
      • Excellent organization and attention to detail, with the ability to manage multiple projects and competing priorities without compromising quality.
      • Comfortable working independently in a dynamic consulting or startup environment, taking initiative and ownership while collaborating effectively with distributed teams.
      • Must be authorized to work in the United States without current or future visa sponsorship.
      • Able to work a standard schedule of 8:00 AM–5:00 PM US Eastern Time, with occasional flexibility when business priorities require it.
      • Requires a reliable high-speed internet connection and professional home-office environment suitable for confidential client discussions and uninterrupted remote collaboration.
      • Willingness to travel locally on occasion for onsite meetings, team gatherings, or business activities.
      • Benefits:

        • Competitive base salary with regular performance reviews and merit-based compensation opportunities.
        • Bonus opportunities tied to performance.
        • Remote-first work culture with flexibility to work from anywhere in the United States.
        • Career development opportunities with mentorship and professional growth pathways.
        • Reimbursement for approved role-related training and certification courses.
        • Opportunity to grow with an early-stage company and take on increasing responsibility.
        • Collaborative environment with exposure to federal cybersecurity, compliance, cloud security, and authorization programs.
✦ Let us apply for you
We find roles like this and apply on your behalf. Cover letter written for each one. Plans from $15/mo. Cancel anytime.
Get AutoApply
Apply now
GRC Engineer (NIST) at Jobgether — Remote