FedRamp Compliance Analyst

Abnormal AI
United States
Workplace: RemoteFull timeUSD 114,800 - 173,250 annuallyFunction: Legal, Risk & ComplianceExperience: 2+ yearsSkills: ["Technical curiosity","Organizational skills","Risk management","Written communication","Operational discipline"]

Own FedRAMP High/Class D security and compliance workstreams end-to-end: interpret requirements, implement controls, collect and validate evidence, and drive remediation to readiness for assessments. Coordinate continuous monitoring and evidence workflows across Security, Engineering, IT, and GRC teams. Support vulnerability detection and response using tools like Wiz/Nessus/Burp, reconcile findings, and maintain audit-ready control and risk records. Help build compliance-as-code aligned to FedRAMP 20x and produce federal authorization artifacts.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Abnormal AI
Abnormal AI
3 days ago

FedRamp Compliance Analyst

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 13 hours agoStatus: Live

Job Summary

Own FedRAMP High/Class D security and compliance workstreams end-to-end: interpret requirements, implement controls, collect and validate evidence, and drive remediation to readiness for assessments. Coordinate continuous monitoring and evidence workflows across Security, Engineering, IT, and GRC teams. Support vulnerability detection and response using tools like Wiz/Nessus/Burp, reconcile findings, and maintain audit-ready control and risk records. Help build compliance-as-code aligned to FedRAMP 20x and produce federal authorization artifacts.
Location: United States
Workplace: Remote
Employment Type: Full time
Job Function: Legal, Risk & Compliance
Seniority: Mid level

Key Responsibilities

  • •Own FedRAMP federal security and compliance workstreams from requirement interpretation through implementation, evidence collection, remediation, and review readiness.
  • •Drive continuous monitoring and evidence workflows by coordinating across Security, FedOps, Engineering, IT, People Operations, GRC, and other control performers to keep evidence current and traceable.
  • •Support vulnerability detection and response by reconciling findings from Wiz, Nessus, and Burp; perform risk-based triage; route in Jira; track SLAs; and validate remediation.
  • •Partner with technical teams on security and compliance impact, including Security Impact Assessments and Significant Change Requests before production changes.
  • •Build compliance-as-code capabilities and maintain accurate records for controls, evidence, remediation, risk, and ownership; produce federal authorization and assessment artifacts and customer assurance guidance.

Pay and Benefits

Salary: USD 114,800 - 173,250 annually

Key Requirements

  • •2+ years in security, compliance, GRC, risk, audit, security operations, or a related discipline, preferably in cloud, SaaS, government, or highly regulated environments.
  • •Working knowledge of NIST SP 800-53 and how security controls translate into technical implementation, operations, and audit evidence.
  • •Experience with compliance operations such as evidence collection, control documentation, vulnerability remediation, risk tracking, audit support, or continuous monitoring.
  • •Ability to read architecture diagrams and security documentation, and turn vulnerabilities, Jira tickets, or logs into clear compliance actions.
  • •Strong written communication and operational discipline to manage multiple workstreams, dependencies, owners, and deadlines while escalating risk early.
Experience:2+ yearsSaaSGovernmentHighly regulated
Skills:Technical curiosityOrganizational skillsRisk managementWritten communicationOperational discipline
Languages:English
Tech Stack:NIST SP 800-53FedRAMPFedRAMP 20xOSCALJSONYAMLGit-based workflowsMarkdownPDF generationAWS GovCloudWizSplunkOktaJiraGitLabNessusBurpPythonAPIsCI/CD

Company Brief

Abnormal AI
Provides AI-powered email security and human behavior analysis to detect phishing, business email compromise, and account takeover attacks. The platform helps organizations protect employees and communications across cloud email and collaboration tools.
Industry: Cybersecurity
Company Size: Large (251 to 1,000 employees)
Growth: Scaleup
Headquarters: San Francisco, United States
Founded: 2018
WebsiteLinkedIn