See all roles

GRC Analyst - Public Sector

Work from home Full-time role Hiring

Why Socure? Socure is building the identity trust infrastructure for the digital economy - verifying 100% of good identities in real time and stopping fraud before it starts. The mission is big, the problems are complex, and the impact is felt by businesses, governments, and millions of people every day. We hire people who want that level of responsibility. People who move fast, think critically, act like owners, and care deeply about solving customer problems with precision. If you want predictability or narrow scope, this won't be your place. If you want to help build the future of identity with a team that holds a high bar for itself - keep reading. About the role Socure is seeking an Analyst, GRC - Public Sector to execute and enhance the company's governance, risk, and compliance operations for its public sector business. Reporting to the Director of GRC - Public Sector, this role drives measurable improvements in compliance efficiency and audit readiness by managing vulnerability remediation, continuous monitoring, access oversight, and evidence preparation that allow Socure to meet the rigorous standards of FedRAMP, GovRAMP, and related frameworks. The Analyst collaborates across Security, Engineering, IT, DevOps, Product, Legal, and other teams to operationalize regulatory requirements, automate workflows, and offers the opportunity to shape the GRC strategy for Socure's fast-growing public sector business. This role is expected to challenge traditional GRC approaches and build automation-first, system-driven solutions that reduce manual effort and enable continuous compliance. The role also translates internal compliance systems into scalable, customer-facing outputs including RFP responses, audit artifacts, and public sector communications. What you'll do Compliance & Certification Management

  • Day-to-day coordination and execution of externalThird Party Assessment Organization (3PAO) assessments and responding to auditor requests for evidence and documentation.
  • Maintain and update FedRAMP and GovRAMP controls and documentation in alignment with organizational and regulatory requirements, including controls aligned with NIST SP 800-53 rev 5 and other related frameworks.
  • Prepare certification and authorization packages and maintain related documentation such as the System Security Plan (SSP) and associated appendices.
  • Replace manual evidence collection with system-generated, API-driven, or continuously validated evidence where possible.

Continuous Monitoring & Vulnerability Management

  • Design and evolve an automation-first continuous monitoring program leveraging system integrations, telemetry, and real-time data pipelines
  • Lead the day-to-day FedRAMP continuous monitoring process including vulnerability management lifecycle, from identification through remediation and verification, coordinating with Security, Engineering, and DevOps teams to address issues identified with tools such as Wiz, Burp Suite, AWS native services, and other platforms and resolve issues within FedRAMP and GovRAMP timelines.
  • Coordinate recurring continuous monitoring compliance activities such as access reviews, incident response exercises, and contingency plan testing.

Access Management & Training

  • Design scalable and automated access validation mechanisms integrated with identity and infrastructure systems
  • Design, implement and deliver FedRAMP training programs to promote compliance awareness
  • Create and manage automated workflows to improve efficiency.

Audit & Assessment Readiness

  • Transform compliance evidence from static repositories into dynamic, system-driven evidence models supporting real-time audit readiness
  • Conduct internal reviews of logged events and control activities, escalating issues or gaps to the Director of GRC and provide status updates and reports highlighting trends, risks, and remediation progress.

Process Improvement & Collaboration

  • Collaborate with the Director of GRC to design automation-first and AI-enabled workflows that reduce manual effort and enable scalable compliance operations
  • Support the development, rollout, and maintenance of machine-readable compliance documentation (e.g., OSCAL or comparable structured formats) to facilitate interoperability
  • Partner with automation and engineering teams to integrate structured compliance data into Socure's broader risk management and monitoring ecosystem including vulnerability remediation, access requests, and compliance reporting.
  • Monitor regulatory and industry trends for potential impacts to compliance strategy.

Public Sector Sales & Customer Engagement

  • Serve as a security subject matter expert for public sector sales activities, translating compliance controls and system capabilities into clear, accurate, and compelling customer-facing narratives.
  • Support development of external communications such as press releases and customer-facing materials related to security certifications and authorizations.
  • Build and

Apply tot his job Apply To this Job

You might like

SAP GRC and Internal Control

Work from home Full-time role

SAP Security Engineer (GRC – Technical)

Work from home Full-time role

Director, Governance, Risk, and Compliance (GRC)

Work from home Full-time role

Open Source Investigations Analyst

Work from home Full-time role

SOC Analyst, Information Security Operations (Remote – United States)

Work from home Full-time role

Global Intelligence Analyst (Days/Hours TBD)

Work from home Full-time role

SOC Analyst

Work from home Full-time role

Environmental Health and Safety (EHS) Professional II-Remote (Oklahoma, OK, US,

Work from home Full-time role

Director, Environmental, Health & Safety (EHS)

Work from home Full-time role

[Hiring] EHS Site Specialist @GE Vernova

Work from home Full-time role

Staff Software Engineer

Work from home Full-time role

Experienced Full Stack Software Engineer – Web & Cloud Application Development at arenaflex

Work from home Full-time role

Sr Software Engineer (Java)

Work from home Full-time role

Senior Accountant

Work from home Full-time role

Experienced Customer Service Representative – Remote Position at arenaflex

Work from home Full-time role

Staff Software Engineer, AI

Work from home Full-time role

Process Controls Manager

Work from home Full-time role

Experienced Work from Home Customer Service Representative – Delivering Exceptional Amazon Customer Experience

Work from home Full-time role

Experienced Customer Service Representative – Missouri Medicaid Support

Work from home Full-time role

Experienced Part-Time Data Entry Specialist – Remote Opportunity at arenaflex

Work from home Full-time role