Remote
FedRamp Compliance Analyst
About this role
About the Role Abnormal AI is looking for a Federal Security and Compliance Analyst who wants to help build how modern federal compliance operates inside a fast-moving cybersecurity company. You will work at the intersection of security engineering, cloud operations, security, and federal compliance, helping Abnormal Gov scale its FedRAMP High/Class D security and compliance program. You will own security requirement implementation and evidence, work directly with technical teams to drive risk and remediation to closure, and help build our compliance as code capabilities in alignment with FedRAMP 20x.
You'll have meaningful ownership early, with the opportunity to improve processes rather than simply inherit them. The strongest candidate will be technically curious, highly organized, comfortable navigating ambiguity, and motivated by making compliance more accurate, automated, measurable, and operationally useful. What you will do Own assigned federal security and compliance workstreams from requirement interpretation through implementation, evidence collection, remediation, and review readiness.
Drive recurring continuous monitoring and evidence workflows , coordinating across Security, FedOps, Engineering, IT, People Operations, GRC, and other control performers to ensure evidence is current, complete, traceable, and retained correctly. Support vulnerability detection and response , including reconciling findings from tools such as Wiz, Nessus, and Burp; risk-based triage; Jira routing; SLA tracking; remediation follow-through; validation; and audit-ready evidence.
Partner with technical teams on security and compliance impact , supporting Security Impact Assessments, Significant Change Requests, control implementation decisions, and other change-management activities before changes reach production. Help build Abnormal's compliance-as-code program , including structured control content, JSON/YAML or other machine-readable artifacts, schema validation, evidence indexing, automation, deterministic document generation, and reusable workflows.
Maintain accurate control, evidence, remediation, risk, and ownership records , proactively identifying gaps, aging items, dependencies, and decisions requiring escalation. Contribute to federal authorization and assessment artifacts , including control documentation, Security Decision Records, certification-package content, assessor requests, and continuous monitoring deliverables. Support federal customer assurance by providing clear, accurate compliance guidance and artifacts for customer onboarding, POVs, DDQs, RFPs, and other government or regulated customer requests.