CronJobs

security jobs

FedRamp Compliance Analyst

Abnormal Security · Remote - USA

remoteunknown$114,800–$114,800Posted Sep 1, 2026PythonAWSNIST SP 800-53FedRAMPOSCALJSONYAMLSplunk

Apply on the employer site

About this role

**About the Role** Abnormal AI is looking for a **Federal Security and Compliance Analyst** who wants to help build how modern federal compliance operates inside a fast-moving cybersecurity company. You’ll work at the intersection of **security engineering, cloud operations, security, and federal compliance**, helping Abnormal Gov scale its **FedRAMP High / Class D** security and compliance program. You’ll own **security requirement implementation and evidence**, partner with technical teams to drive **risk and remediation to closure**, and help build **compliance-as-code** capabilities aligned with **FedRAMP 20x**. You’ll have meaningful ownership early—improving processes rather than simply inheriting them. The strongest candidate is **technically curious**, **highly organized**, comfortable navigating **ambiguity**, and motivated by making compliance **more accurate, automated, measurable, and operationally useful**. --- **What you will do** - **Own assigned federal security and compliance workstreams** from requirement interpretation through implementation, evidence collection, remediation, and review readiness. - **Drive continuous monitoring and evidence workflows**, coordinating across Security, FedOps, Engineering, IT, People Operations, GRC, and other control performers to ensure evidence is **current, complete, traceable, and retained correctly**. - **Support vulnerability detection and response**, including reconciling findings from tools such as **Wiz, Nessus, and Burp**; risk-based triage; **Jira routing**; SLA tracking; remediation follow-through; validation; and **audit-ready evidence**. - **Partner with technical teams** on security and compliance impact—supporting **Security Impact Assessments**, **Significant Change Requests**, control implementation decisions, and other change-management activities before changes reach production. - **Help build Abnormal’s compliance-as-code program**, including structured control content, **JSON/YAML (or other machine-readable artifacts)**, schema validation, evidence indexing, automation, deterministic document generation, and reusable workflows. - **Maintain accurate control, evidence, remediation, risk, and ownership records**, proactively identifying gaps, aging items, dependencies, and decisions requiring escalation. - **Contribute to federal authorization and assessment artifacts**, including control documentation, Security Decision Records, certification-package content, assessor requests, and continuous monitoring deliverables. - **Support federal customer assurance** by providing clear compliance guidance and artifacts for customer onboarding, POVs, DDQs, RFPs, and other government/regulatory requests. --- **Must Haves** - **2+ years** of experience in security, compliance, GRC, risk, audit, security operations, or a related discipline—preferably in a **cloud, SaaS, government, or highly regulated** environment. - Working knowledge of **NIST SP 800-53** and understanding how security controls translate into **technical implementation, operational processes, and audit evidence**. - Experience with one or more core compliance operations such as **evidence collection, control documentation, vulnerability remediation, risk tracking, audit support, or continuous monitoring**. - Technical curiosity and the ability to read **architecture diagrams, security documentation, vulnerability findings, Jira tickets, logs, and engineering materials** and turn them into clear complianc

Listing freshness

CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.

Browse all software engineering jobs →

Follow fresh jobs in Discord