RED SKY Consulting logo
RED SKY Consulting
Posted 34 days agoVerified live 1d ago

GRC Analyst - FedRAMP

Brief overview

Remote
$120k/yrStated minimum
2+ yrsMinimum
FedRAMP GovernanceFedRAMP Continuous Monitoring (ConMon)POA&M ManagementNIST SP 800-53Third-Party Audit Support (3PAO)Document Request List (DRL) ManagementSecurity Control AssessmentVulnerability ManagementCloud Security ComplianceAWSMicrosoft AzureServiceNowPower BIOrganizational Coordination

About the company

RED SKY Consulting logo
RED SKY Consultingredsky-consulting.com

Red Sky Consulting is an IT company providing cybersecurity solutions.

Job description

Summary

RED SKY Consulting is seeking a GRC Analyst to support cloud security and compliance for public sector standards, including FedRAMP. The role supports authorization, audits, continuous monitoring, vulnerability remediation, governance, documentation, and cross-functional compliance activities.

Responsibilities

  • Support authorization, compliance, and continuous monitoring activities
  • Interpret and apply security controls and control enhancements
  • Keep key documentation up to date, including system security plans, policies, and control descriptions
  • Track compliance against established baselines (Low / Moderate / High)
  • Coordinate and support third-party audits (including 3PAO assessments)
  • Gather and review evidence from engineering, infrastructure, and operations teams
  • Respond to auditor questions and information requests
  • Help track remediation efforts and support closure of identified gaps
  • Contribute to annual assessments, penetration test reviews, and vulnerability reporting
  • Supporting monthly FedRAMP continuous monitoring activities
  • Reviewing vulnerability scans and tracking remediation progress
  • Coordinating incident reporting and change management impacts
  • Ensuring changes follow approved compliance processes
  • Identifying and escalating potential compliance risks
  • Partner with Cloud Engineering, DevOps, Security Operations, Legal, and Product teams
  • Translate technical controls into clear, audit-ready documentation
  • Support internal reporting and briefings on compliance status and risk
  • Maintain organized compliance evidence repositories
  • Assist with internal audits and readiness assessments
  • Contribute to updates of policies and standards aligned to federal requirements
  • Support responses to customer and government security questionnaires

Skills

  • FedRAMP Governance Experience: Specific experience and understanding of the ConMon and POA&M processes are critical
  • NIST 800-53 Framework Knowledge: Must be familiar with the framework and be able to identify control families (e.g., IA - Identity Access)
  • Audit Support Experience: Experience working with third-party auditors (3PAO), understanding a Document Request List (DRL), and collating evidence for controls
  • Strong Organizational & Coordination Skills: The role requires managing the vulnerability process across dozens of internal groups, involving heavy spreadsheet work and tracking
  • US Citizenship: This is a mandatory, non-negotiable requirement for the position
  • Experience in GRC, cybersecurity compliance, or audit support (typically 2+ years)
  • Familiarity with frameworks such as FedRAMP, NIST SP 800-53, or similar compliance programs
  • The FedRAMP lifecycle and continuous monitoring processes
  • NIST 800-53 control families
  • POA&M management and risk tracking
  • Analyzing technical controls and clearly documenting compliance
  • Working with compliance or GRC tools, ticketing systems, or evidence repositories
  • Experience with ServiceNow and Power BI are a plus
  • Familiarity with cloud environments such as AWS or Microsoft Azure a plus
  • Experience working with auditors or assessment organizations (e.g., 3PAOs) is a plus
  • Exposure to cloud environments such as AWS or Azure

Qualifications

Must Haves

  • FedRAMP Governance Experience: Specific experience and understanding of the ConMon and POA&M processes are critical
  • NIST 800-53 Framework Knowledge: Must be familiar with the framework and be able to identify control families (e.g., IA - Identity Access)
  • Audit Support Experience: Experience working with third-party auditors (3PAO), understanding a Document Request List (DRL), and collating evidence for controls
  • Strong Organizational & Coordination Skills: The role requires managing the vulnerability process across dozens of internal groups, involving heavy spreadsheet work and tracking
  • US Citizenship: This is a mandatory, non-negotiable requirement for the position
  • Experience in GRC, cybersecurity compliance, or audit support (typically 2+ years)
  • Familiarity with frameworks such as FedRAMP, NIST SP 800-53, or similar compliance programs
  • The FedRAMP lifecycle and continuous monitoring processes
  • NIST 800-53 control families
  • POA&M management and risk tracking
  • Analyzing technical controls and clearly documenting compliance
  • Working with compliance or GRC tools, ticketing systems, or evidence repositories

Nice to Haves

  • Experience with ServiceNow and Power BI are a plus
  • Familiarity with cloud environments such as AWS or Microsoft Azure a plus
  • Experience working with auditors or assessment organizations (e.g., 3PAOs) is a plus
  • Exposure to cloud environments such as AWS or Azure

Benefits

  • RED SKY Consulting Candidate and Client Referral Program offering $2,500 for referring qualified IT professionals who are employed or placed through the referral.

More jobs like this