587,360open jobs
26,166companies
82,433added this week
Browse all
Salary
$120k – $145k per year
Location
Remote/Hybrid (Washington, United States)
Seniority
Middle · 4+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Socure is a leading digital identity verification and fraud prevention platform that uses artificial intelligence and machine learning to verify consumer identities in real time. The company analyzes thousands of predictive data points - including biometrics, device intelligence, and email or phone attributes - to accurately authenticate individuals during online onboarding. By providing high accuracy rates across demographic groups, it enables financial institutions, digital healthcare providers, and online platforms to reduce fraud while streamlining user conversion.

Why Socure?

Socure is building the identity trust infrastructure for the digital economy - verifying 100% of good identities in real time and stopping fraud before it starts. The mission is big, the problems are complex, and the impact is felt by businesses, governments, and millions of people every day.

We hire people who want that level of responsibility. People who move fast, think critically, act like owners, and care deeply about solving customer problems with precision. If you want predictability or narrow scope, this won’t be your place. If you want to help build the future of identity with a team that holds a high bar for itself - keep reading.

Overview

Socure is seeking an Analyst, GRC - Public Sector to own the hands-on execution of the company’s governance, risk, and compliance operations for its public sector business. Reporting to the Director of GRC - Public Sector, this role is responsible day-to-day for running FedRAMP/GovRAMP continuous monitoring, building and maintaining the POA&M and compliance trackers that keep the program audit-ready, and coordinating access reviews, vulnerability remediation, and evidence collection with Security, Engineering, IT, DevOps, Product, Legal, and other teams. As the Analyst builds fluency in these operational fundamentals, the role grows to include drafting customer-facing compliance and RFP response content that makes Socure’s security posture compelling to public sector buyers, and pursuing automation-first, system-driven improvements, including machine-readable formats like OSCAL and AI-enabled workflows, that reduce manual effort and challenge how the team has traditionally done this work.

Role and Responsibilities

Compliance & Certification Management

  • Day-to-day coordination and execution of externalThird Party Assessment Organization (3PAO) assessments and responding to auditor requests for evidence and documentation.

  • Maintain and update FedRAMP and GovRAMP controls and documentation in alignment with organizational and regulatory requirements, including controls aligned with NIST SP 800-53 rev 5 and other related frameworks.

  • Prepare certification and authorization packages and maintain related documentation such as the System Security Plan (SSP) and associated appendices.

  • Replace manual evidence collection with system-generated, API-driven, or continuously validated evidence where possible. Build and maintain the trackers, procedures, and status-reporting artifacts that operationalize this work, structured so other stakeholders can use them directly.

Continuous Monitoring & Vulnerability Management

  • Design and evolve an automation-first continuous monitoring program leveraging system integrations, telemetry, and real-time data pipelines

  • Lead the day-to-day FedRAMP continuous monitoring process including vulnerability management lifecycle, from identification through remediation and verification, coordinating with Security, Engineering, and DevOps teams to address issues identified with tools such as Wiz, Burp Suite, AWS native services, and other platforms and resolve issues within FedRAMP and GovRAMP timelines.

  • Coordinate recurring continuous monitoring compliance activities such as access reviews, incident response exercises, and contingency plan testing.

Access Management & Training

  • Design scalable and automated access validation mechanisms integrated with identity and infrastructure systems

  • Design, implement and deliver FedRAMP training programs to promote compliance awareness

  • Create and manage automated workflows to improve efficiency.

Audit & Assessment Readiness

  • Transform compliance evidence from static repositories into dynamic, system-driven evidence models supporting real-time audit readiness

  • Conduct internal reviews of logged events and control activities, escalating issues or gaps to the Director of GRC and provide status updates and reports highlighting trends, risks, and remediation progress.

Process Improvement & Collaboration

  • Collaborate with the Director of GRC to design automation-first and AI-enabled workflows that reduce manual effort and enable scalable compliance operations

  • Support the development, rollout, and maintenance of machine-readable compliance documentation (e.g., OSCAL or comparable structured formats) to facilitate interoperability

  • Partner with automation and engineering teams to integrate structured compliance data into Socure’s broader risk management and monitoring ecosystem including vulnerability remediation, access requests, and compliance reporting.

  • Monitor regulatory and industry trends for potential impacts to compliance strategy.

Public Sector Sales & Customer Engagement

  • Serve as a security subject matter expert for public sector sales activities, translating compliance controls and system capabilities into clear, accurate, and compelling customer-facing narratives. The Analyst is expected to learn the difference between writing that confirms Socure meets a requirement and writing that persuades a public sector buyer that Socure’s approach is comfortable and superior to competitors’, with the Director retaining final review and approval given the contractual and sales stakes.

  • Support development of external communications such as press releases and customer-facing materials related to security certifications and authorizations.

  • Build and maintain scalable response frameworks (e.g., answer libraries, structured content, or AI-assisted tools) to provide consistency, accuracy, and speed across RFP and RFx responses

Monitor Evolving Requirements

  • Monitor new and evolving requirements and perform gap analyses including

    • Updates to applicable NIST Special Publications and other government standards

    • Contract security requirements from new customers

    • Updates to the FedRAMP Program requirements and processes as the program evolves

  • Provide input to standards bodies on evolving standards when applicable

Required Qualifications

  • 4+ years of hands-on cybersecurity, compliance, or identity-management experience, including demonstrated personal execution of FedRAMP, GovRAMP, or comparable continuous-monitoring work - running scans, building or maintaining a POA&M, and preparing deviation requests. Public sector experience is a plus but not required.

  • Direct experience with FedRAMP, GovRAMP, and NIST frameworks (800-53, 800-63, 800-171).

  • Proven ability to personally execute continuous monitoring, vulnerability remediation, and compliance reporting.

  • Proven ability to design and improve repeatable compliance processes - identifying inefficiencies, defining clear steps, and building structure where none exists; experience using AI tools (e.g., ChatGPT, Glean, Gemini) and machine-readable formats (e.g., OSCAL) to accelerate that work is a strong plus.

  • Strong communication, organization, and collaboration skills with the ability to manage multiple priorities, including strong written communication and the ability to write persuasively for a customer audience - distinct from writing that is merely compliance-accurate.

  • Ability to adapt to changing requirements

  • Demonstrated customer-facing experience and enough exposure to product or sales positioning to distinguish compliance-accurate writing from writing that persuades a buyer; prior RFP-specific experience is not required.

  • Must be a U.S. Person (U.S. Citizens or U.S. Permanent Residents) residing in the United States and be able to obtain a U.S. OPM NACI clearance.

Preferred Qualifications

  • Experience in regulated industries (e.g., financial services, healthcare) and knowledge of privacy and compliance frameworks such as GDPR, CCPA, and key NIST standards.

  • Professional certifications preferred (CISSP, CISM, CISA, IAPP).

  • Proven hands-on contribution to certification and compliance initiatives (FedRAMP, GovRAMP, NIST 800-63/171).

  • Skilled in continuous monitoring, vulnerability management, policy updates, and audit coordination across cross-functional teams. Also valued: a demonstrated track record of identifying and closing process gaps proactively, without waiting for direction.

  • Strong understanding of evolving cybersecurity standards and digital identity regulations, with the ability to translate them into practical risk and compliance improvements.

Socure is an equal opportunity employer that values diversity in all its forms within our company. We do not discriminate based on race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.

If you need an accommodation during any stage of the application or hiring process-including interview or onboarding support-please reach out to your Socure recruiting partner directly.

Follow Us!

YouTube | LinkedIn | X (Twitter) | Facebook

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
587,360 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Washington
Vulnerability Manager 6 hours ago
$109k – $223k per year (Estimated) • Remote • 5+ years exp
Python
AI/ML
AI Agents
DevOps
GCP
Azure
CI/CD
AWS
Kubernetes
SLI/SLO/SLA
Cybersecurity
FedRAMP
CVSS
EPSS
KEV
BeyondTrust
Apply
$130k – $196k per year • Equity • In office • Full-Time • 5+ years exp • Bachelor's Degree • Boulder • Atlanta
Python
Java
TypeScript
Java
Spring Boot
AI/ML
Cursor
Claude Code
AI Agents
DevOps
GCP
Azure
CI/CD
AWS
Docker
Kubernetes
Management
Agile
Apply
$59k – $128k per year (Estimated) • Remote
Python
Databases
Databricks
Amazon Redshift
AI/ML
Spark
DevOps
GCP
Azure
AWS
Analytics
Tableau
Looker
Apply
$71k – $162k per year (Estimated) • Equity • Remote • 2+ years exp
Python
JavaScript
PHP
Ruby
PowerShell
Bash
AI/ML
Red Teaming
DevOps
GCP
Azure
AWS
Cybersecurity
OWASP Top 10
Apply
$69k – $125k per year (Estimated) • Remote/Hybrid • Glasgow
SQL
DevOps
Azure
AWS
Analytics
Master Data Management
Management
Agile
Scrum
Apply
$80k – $95k per year • In office • Full-Time • San Francisco
Management
Slack
Google Workspace
Zapier
Apply
$210k – $230k per year • Remote/Hybrid • Full-Time • 5+ years exp • New York • San Francisco • Seattle
AI/ML
Cursor
Claude
ChatGPT
LLM Guardrails
DevOps
Platform Engineering
Management
Slack
Confluence
Notion
Jira
Apply
$17k – $50k per year (Estimated) • In office • Full-Time • 2+ years exp • Bengaluru
Python
Bash
DevOps
Terraform
GitHub Actions
Datadog
Prometheus
GitLab CI
CI/CD
GitOps
ArgoCD
Jenkins
AWS
Kubernetes
Grafana
Platform Engineering
Amazon EKS
Amazon CloudWatch
Apply
$190k – $225k per year • Remote • Full-Time • 7+ years exp
AI/ML
AI Agents
LLM Guardrails
Cybersecurity
GDPR
Apply
$170k – $185k per year • Remote • Full-Time • 7+ years exp • Master's Degree • San Francisco • Seattle • New York • Miami • Washington
Marketing
Salesforce
YouTube
X (Twitter)
LinkedIn
Apply
$54k – $80k per year • In office • Internship • Bachelor's Degree • Washington
Apply
Remote • Full-Time • Associate's Degree • Washington • New York
Management
Agile
Apply
$57k – $110k per year (Estimated) • Remote/Hybrid • Full-Time • Associate's Degree • Washington
Marketing
Salesforce
Apply
$121k – $338k per year • In office • Full-Time • 8+ years exp • Washington • Atlanta • Hartford • Boston • Miami
SQL
Management
Confluence
Jira
Agile
Scrum
Apply
$103k – $202k per year (Estimated) • Remote • Full-Time • 8+ years exp • Bachelor's Degree • Washington
AI/ML
LLM
Apply
See all jobs
This is one of many
587,360 more open roles from verified company boards, updated every day.