FREE ACCESS
5,000–10,000 jobs/day
See all jobs on JobTailor
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Corporate Governance, Risk and Compliance Analyst
OnebriefCorporate Governance, Risk, and Compliance Analyst at Onebrief managing RMF, CMMC, and SOC 2 compliance. Collaborating with various teams to ensure adherence to federal and corporate regulations.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates extensive expertise in cybersecurity compliance, particularly with RMF, CMMC 2.0, and SOC 2, while effectively collaborating with cross-functional teams to integrate compliance into system design and workflows. Holds relevant certifications and possesses a strong understanding of regulatory frameworks and risk assessment methodologies.
Highest-signal resume keywords
RMF ExpertiseCMMC 2.0 ComplianceSOC 2 ComplianceCybersecurity Compliance ExperienceGRC Platform Experience
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Cybersecurity ComplianceRisk AssessmentAuthorization MaintenanceAudit Evidence ManagementControl MappingSSP DevelopmentSAR DevelopmentPOA&M ManagementSTIG ImplementationCI/CD Workflow Integration
Soft Skills
CollaborationAdvisory SkillsCommunication
Tools & Technologies
GRC PlatformsEMASS
Certifications & Qualifications
CISSPCISMCISSOCPTECySA+FITSP-AGCSACISAISSEPGSLC
Industry Keywords
FedRAMP HighCMMC 2.0SOC 2Internal AssessmentsExternal Audit ReadinessRegulatory ChangesContractual ChangesVendor Risk ReviewsSupply Chain RiskDepartment of War Compliance
Tech Stack
Tools & technologiesCyber Security
About the role
Key responsibilities & impact- Own RMF authorizations across Department of War components and FedRAMP High, alongside CMMC 2.0 and SOC 2 compliance for corporate systems
- Maintain authorization and audit evidence, including SSPs, SARs, POA&Ms, STIGs, and control mappings
- Partner with Engineering, Product, and Security to embed compliance requirements into system design and CI/CD workflows, not bolt them on afterward
- Coordinate internal assessments and external audit readiness across all applicable frameworks
- Track regulatory and contractual changes and advise leadership on what they mean for Onebrief
- Run risk assessments and vendor/supply chain risk reviews across both federal and corporate environments
Requirements
What you’ll need- U.S. Citizen
- Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or related field
- 8+ years in cybersecurity compliance
- Hands-on expertise with RMF and at least one of CMMC 2.0 or SOC 2
- One or more of the following certifications: CISSP, CISM, CISSO, CPTE, CySA+, FITSP-A, GCSA, CISA, ISSEP, GSLC, or GSNA
- Experience with GRC platforms, including automated evidence collection and testing (eMASS experience a plus)
Benefits
Comp & perks- Equity: Share in the company's success.
- Flexible Work Environment: Remote-first organization with flexible work hours and unlimited PTO.
- Comprehensive Health Coverage: Health, dental, vision, and life insurance.
- Retirement Plan: 401(k) plan with company match to secure your future.
- Parental Leave: 8 weeks at 100% regardless of state.
- Company Retreats: Annual company summit trips.
- Home Office Budget: $1,000 per year for home office improvements.