USA remote
GRC Analyst - Public Sector
About this role
WHY SOCURE? Socure is building the identity trust infrastructure for the digital economy — verifying 100% of good identities in real time and stopping fraud before it starts. The mission is big, the problems are complex, and the impact is felt by businesses, governments, and millions of people every day. We hire people who want that level of responsibility. People who move fast, think critically, act like owners, and care deeply about solving customer problems with precision.
If you want predictability or narrow scope, this won’t be your place. If you want to help build the future of identity with a team that holds a high bar for itself — keep reading. OVERVIEW Socure is seeking an Analyst, GRC – Public Sector to own the hands-on execution of the company’s governance, risk, and compliance operations for its public sector business. Reporting to the Director of GRC – Public Sector, this role is responsible day-to-day for running FedRAMP/GovRAMP continuous monitoring, building and maintaining the POA&M and compliance trackers that keep the program audit-ready, and coordinating access reviews, vulnerability remediation, and evidence collection with Security, Engineering, IT, DevOps, Product, Legal, and other teams.
As the Analyst builds fluency in these operational fundamentals, the role grows to include drafting customer-facing compliance and RFP response content that makes Socure’s security posture compelling to public sector buyers, and pursuing automation-first, system-driven improvements, including machine-readable formats like OSCAL and AI-enabled workflows, that reduce manual effort and challenge how the team has traditionally done this work.
ROLE AND RESPONSIBILITIES COMPLIANCE & CERTIFICATION MANAGEMENT - Day-to-day coordination and execution of externalThird Party Assessment Organization (3PAO) assessments and responding to auditor requests for evidence and documentation. - Maintain and update FedRAMP and GovRAMP controls and documentation in alignment with organizational and regulatory requirements, including controls aligned with NIST SP 800-53 rev 5 and other related frameworks.
- Prepare certification and authorization packages and maintain related documentation such as the System Security Plan (SSP) and associated appendices. - Replace manual evidence collection with system-generated, API-driven, or continuously validated evidence where possible. Build and maintain the trackers, procedures, and status-reporting artifacts that operationalize this work, structured so other stakeholders can use them directly.