Find your dream job faster with JobLogr
AI-powered job search, resume help, and more.
Try for Free
OB

Optimal Business Solutions

via SimplyHired

All our jobs are verified from trusted employers and sources. We connect to legitimate platforms only.

GRC Engineer/ISSO

Anywhere
Full-time
Posted 7/23/2026
Verified Source
Key Skills:
Governance Risk Compliance
NIST Framework
Cloud Security
FedRAMP
Security Program Management

Compensation

Salary Range

$150K - 170K a year

Responsibilities

Lead and support federal cybersecurity governance, risk, and compliance activities including RMF, FedRAMP, and cloud security controls.

Requirements

7-10+ years cybersecurity experience with strong knowledge of federal RMF, NIST controls, FedRAMP, Azure, Microsoft 365, and cloud security compliance.

Full Description

We are seeking a highly experienced Senior GRC Engineer / Information System Security Officer (ISSO) to support a long-term federal cybersecurity program. This is not a traditional, documentation-only ISSO or checkbox-compliance position. The ideal candidate will operate at the intersection of governance, risk, and compliance, cloud security, and enterprise engineering. The Senior GRC Engineer / ISSO will apply deep knowledge of the Risk Management Framework, FedRAMP, and NIST security requirements while partnering with cloud, platform, security, and engineering teams to turn regulatory requirements into practical, scalable security controls. The successful candidate will help accelerate Authority to Operate activities, improve continuous monitoring, reduce audit friction, and embed security into cloud platforms and enterprise technology environments. Key Responsibilities • Serve as a senior cybersecurity and compliance advisor to system owners, engineers, technical teams, and federal stakeholders. • Lead and support Risk Management Framework activities throughout the system development lifecycle. • Translate NIST, FedRAMP, and federal security requirements into practical technical guidance, cloud security guardrails, and repeatable implementation patterns. • Support the development, review, and maintenance of security authorization documentation, including System Security Plans, Security Assessment Reports, Plans of Action and Milestones, control implementation statements, and supporting evidence. • Help accelerate ATO and ongoing authorization efforts by identifying security requirements and implementation gaps early in the development process. • Partner with Azure, Microsoft 365, platform engineering, cloud security, and DevSecOps teams to design secure and compliant solutions. • Evaluate the implementation and effectiveness of security and privacy controls. • Support continuous monitoring through automated evidence collection, vulnerability management, metrics, dashboards, and control validation. • Analyze control inheritance, shared-service dependencies, and cloud shared-responsibility models. • Prepare teams for independent security assessments, audits, and regulatory reviews. • Track cybersecurity risks, vulnerabilities, findings, and remediation activities. • Provide clear status updates, risk assessments, and recommendations to technical and nontechnical stakeholders. • Manage multiple priorities, deadlines, and client requirements in a fast-paced federal consulting environment. • Identify opportunities to improve GRC, ATO, continuous monitoring, and security engineering processes. Required Qualifications • 7–10 or more years of experience in cybersecurity, governance, risk, compliance, security engineering, information assurance, or ISSO functions. • Strong experience applying the Federal Risk Management Framework. • Strong knowledge of NIST SP 800-53 security and privacy controls. • Experience supporting federal ATO, ongoing authorization, or continuous authorization activities. • Experience with FedRAMP requirements and cloud security compliance. • Required professional experience with Microsoft Azure, including Azure security, governance, compliance, or cloud control implementation. • Required professional experience with Microsoft 365, including Microsoft 365 security, compliance, identity, governance, or enterprise administration. • Experience working with Microsoft Entra ID, formerly Azure Active Directory, and identity and access management concepts. • Understanding of cloud control inheritance, shared-responsibility models, and enterprise cloud governance. • Experience working within the software development lifecycle and familiarity with CI/CD, DevSecOps, or enterprise engineering practices. • Experience partnering with cloud engineers, architects, developers, system owners, and security teams. • Demonstrated ability to translate regulatory and security requirements into practical technical recommendations. • Strong client-facing communication, consulting, and stakeholder-management skills. • Demonstrated success managing competing priorities and delivering results in a demanding environment. • Ability to work independently, exercise sound judgment, and communicate risks clearly. • Experience supporting federal agencies, regulated industries, financial services organizations, or large enterprise environments. Equal Opportunity Employer We are an equal opportunity employer and consider qualified applicants without regard to race, color, religion, sex, national origin, age, disability, veteran status, genetic information, or any other status protected by applicable law. Pay: $150,000.00 - $170,000.00 per year Benefits: • 401(k) • Dental insurance • Paid time off • Tuition reimbursement • Vision insurance Work Location: Remote

This job posting was last updated on 7/26/2026

Ready to have AI work for you in your job search?

Sign-up for free and start using JobLogr today!

Get Started »
JobLogr badgeTinyLaunch BadgeJobLogr - AI Job Search Tools to Land Your Next Job Faster than Ever | Product Hunt