Summary
Abnormal AI is a cybersecurity company seeking a Security & Compliance Analyst, Public Sector to help scale its federal security and compliance program. The role owns security requirement implementation, evidence collection, risk remediation, continuous monitoring, compliance-as-code development, and federal authorization support for Abnormal Gov.
Responsibilities
- Own assigned federal security and compliance workstreams from requirement interpretation through implementation, evidence collection, remediation, and review readiness
- Drive recurring continuous monitoring and evidence workflows, coordinating across Security, FedOps, Engineering, IT, People Operations, GRC, and other control performers to ensure evidence is current, complete, traceable, and retained correctly
- Support vulnerability detection and response, including reconciling findings from tools such as Wiz, Nessus, and Burp; risk-based triage; Jira routing; SLA tracking; remediation follow-through; validation; and audit-ready evidence
- Partner with technical teams on security and compliance impact, supporting Security Impact Assessments, Significant Change Requests, control implementation decisions, and other change-management activities before changes reach production
- Help build Abnormal's compliance-as-code program, including structured control content, JSON/YAML or other machine-readable artifacts, schema validation, evidence indexing, automation, deterministic document generation, and reusable workflows
- Maintain accurate control, evidence, remediation, risk, and ownership records, proactively identifying gaps, aging items, dependencies, and decisions requiring escalation
- Contribute to federal authorization and assessment artifacts, including control documentation, Security Decision Records, certification-package content, assessor requests, and continuous monitoring deliverables
- Support federal customer assurance by providing clear, accurate compliance guidance and artifacts for customer onboarding, POVs, DDQs, RFPs, and other government or regulated customer requests
Skills
- 2+ years of experience in security, compliance, GRC, risk, audit, security operations, or a related discipline, preferably in a cloud, SaaS, government, or highly regulated environment
- Working knowledge of NIST SP 800-53 and an understanding of how security controls translate into technical implementation, operational processes, and audit evidence
- Experience with one or more core compliance operations such as evidence collection, control documentation, vulnerability remediation, risk tracking, audit support, or continuous monitoring
- Technical curiosity and the ability to read architecture diagrams, security documentation, vulnerability findings, Jira tickets, logs, or engineering materials and turn them into clear compliance actions
- Ability to work effectively with Security, Engineering, Infrastructure/Operations, IT, and other technical teams without needing every problem or requirement to be fully defined in advance
- Strong written communication skills and the ability to produce documentation that is precise enough for assessors and technical teams while remaining understandable to non-technical stakeholders
- Strong operational discipline: you can manage multiple workstreams, dependencies, owners, and deadlines while identifying problems and escalating risk early
- A demonstrated tendency to improve the way work gets done through automation, better processes, clearer documentation, reusable templates, better data, or simpler workflows
- Experience with FedRAMP High, FedRAMP Moderate, FISMA, CMMC, GovRAMP, or other U.S. government security frameworks
- Exposure to compliance-as-code, OSCAL, JSON/YAML schemas, Git-based workflows, automated validation, Markdown/PDF generation, or machine-readable authorization artifacts
- Familiarity with tools or environments such as AWS GovCloud, Wiz, Splunk, Okta, Jira, GitLab, Nessus, Burp, or cloud-native vulnerability-management platforms
- Experience supporting Security Impact Assessments, Significant Change Requests, POA&M/ConMon workflows, 3PAO assessments, or federal authorization packages
- Basic scripting or automation experience—such as Python, APIs, CI/CD workflows, or data transformation—or a strong interest in developing those skills
Qualifications
Must Haves
- 2+ years of experience in security, compliance, GRC, risk, audit, security operations, or a related discipline, preferably in a cloud, SaaS, government, or highly regulated environment
- Working knowledge of NIST SP 800-53 and an understanding of how security controls translate into technical implementation, operational processes, and audit evidence
- Experience with one or more core compliance operations such as evidence collection, control documentation, vulnerability remediation, risk tracking, audit support, or continuous monitoring
- Technical curiosity and the ability to read architecture diagrams, security documentation, vulnerability findings, Jira tickets, logs, or engineering materials and turn them into clear compliance actions
- Ability to work effectively with Security, Engineering, Infrastructure/Operations, IT, and other technical teams without needing every problem or requirement to be fully defined in advance
- Strong written communication skills and the ability to produce documentation that is precise enough for assessors and technical teams while remaining understandable to non-technical stakeholders
- Strong operational discipline: you can manage multiple workstreams, dependencies, owners, and deadlines while identifying problems and escalating risk early
- A demonstrated tendency to improve the way work gets done through automation, better processes, clearer documentation, reusable templates, better data, or simpler workflows
Nice to Haves
- Experience with FedRAMP High, FedRAMP Moderate, FISMA, CMMC, GovRAMP, or other U.S. government security frameworks
- Exposure to compliance-as-code, OSCAL, JSON/YAML schemas, Git-based workflows, automated validation, Markdown/PDF generation, or machine-readable authorization artifacts
- Familiarity with tools or environments such as AWS GovCloud, Wiz, Splunk, Okta, Jira, GitLab, Nessus, Burp, or cloud-native vulnerability-management platforms
- Experience supporting Security Impact Assessments, Significant Change Requests, POA&M/ConMon workflows, 3PAO assessments, or federal authorization packages
- Basic scripting or automation experience—such as Python, APIs, CI/CD workflows, or data transformation—or a strong interest in developing those skills
Benefits
- This role may be eligible for bonus or incentive compensation
- This role may be eligible for equity
- A comprehensive benefits package