Salary
💰 $170,000 - $210,000 per year
Tech Stack
CloudCyber Security
About the role
- Build and sustain Onebrief’s cybersecurity compliance program
- Ensure compliance evidence is created, validated, and continuously organized in the GRC platform
- Lead efforts to automate control testing, close gaps, and prepare for audits
- Maintain compliance documentation and evidence in the GRC platform
- Coordinate internal assessments and readiness checks ahead of external audits
- Partner with engineering and IT to design compliant cloud-native solutions
- Track regulatory changes and advise leadership on compliance implications
- Conduct periodic risk assessments and suggest appropriate risk treatment actions
- Develop internal cybersecurity awareness and training presentations for employees
- Conduct supply chain risk management assessments for current and future vendors
Requirements
- 7+ years in Cybersecurity Compliance and related roles
- Experience with GRC platforms and leveraging automated evidence collection and testing capabilities
- Familiarity with cloud security standards (e.g., FedRAMP, ISO 27001, NIST 800-171)
- Strong background in policy development, control testing, and evidence gathering
- Excellent communication skills for working with both technical and non-technical stakeholders
- Certifications (one or more required): CISSP, CISM, CISSO, CPTE, CySA+, FITSP-A, GCSA, CISA, ISSEP, GSLC, GSNA
- Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or a related field
- Hands-on expertise with CMMC 2.0 and SOC 2 frameworks