GRC Analyst, Federal Programs

New
United StatesFull-TimeMiddle
Salary101,500 - 159,500 USD per year
Apply NowOpens the employer's application page

Job Details

Experience
5+ years of hands-on experience in GRC, compliance, or security, with at least 3 of those years focused on federal compliance frameworks

Requirements

  • 5+ years of hands-on experience in GRC, compliance, or security
  • At least 3 years focused on federal compliance frameworks such as CMMC or FedRAMP
  • Demonstrated experience owning deliverables and driving remediation through a CMMC, FedRAMP, or equivalent federal compliance effort
  • Strong working knowledge of CMMC Level 2 practices, scoping methodology, and CUI handling requirements
  • Ability to produce compliance documentation including SSPs, POA&Ms, gap analyses, and control narratives
  • Proven ability to communicate technical compliance requirements to non-technical stakeholders
  • Experience engaging directly with external auditors and assessors
  • CMMC Certified Professional (CCP) credential, or active pursuit of it preferred
  • CMMC Certified Assessor (CCA) credential preferred

Responsibilities

  • Serve as a member of Sword's GRC team, contributing to security compliance across all products and services, with primary ownership of federal programs
  • Define and maintain the CMMC assessment boundary, working across infrastructure, engineering, and business teams to ensure the scope is accurate and defensible
  • Map NIST SP 800-171 practices to Sword's current environment and produce a clear, evidence-based gap analysis
  • Translate identified gaps into prioritized remediation tasks with clear ownership
  • Build and maintain the System Security Plan (SSP), Plan of Action and Milestones (POA&M), and all artifacts required for assessment
  • Serve as Sword's primary interface with the C3PAO and assessment team during formal CMMC assessments
  • Drive FedRAMP readiness in parallel, including control documentation, evidence collection, and continuous monitoring
  • Contribute to audits and compliance activities across other active frameworks, including SOC 2 and HITRUST
View Full Description & ApplyYou'll be redirected to the employer's site
101,500 - 159,500 USD per year
Apply Now