About the Job
Onebrief builds collaboration and AI-powered workflow software for military planning and operational coordination.
Today, many critical planning workflows still rely on fragmented systems, static documents, and disconnected tools that make collaboration and decision-making unnecessarily difficult. Onebrief brings modern software, AI, and real-time collaboration into those environments, helping teams operate with greater clarity,...
We are a distributed team of builders from military, operational, and technology backgrounds who care deeply about improving how important work gets done. Some team members work remotely, while others work directly alongside customers in operational environments around the world.
Key Responsibilities
Own the design and implementation of Onebrief's GRC framework across RMF, FedRAMP, CMMC, SOC 2, and other applicable standards.
Build and manage the control environment, including policies, procedures, and evidence collection systems.
Design and implement technical security controls in partnership with Product, Engineering, Infrastructure and Corporate IT including access management, logging, encryption, and vulnerability management practices.
Partner with Engineering, Infrastructure, and Corporate IT to translate compliance requirements into working technical controls, not just documented ones.
Required Skills & Abilities
5+ years of experience in GRC, security engineering, or a combined compliance and technical security role
Direct experience with RMF, FedRAMP, CMMC, or equivalent federal compliance frameworks
Hands-on experience implementing technical security controls, such as IAM, logging and monitoring, network segmentation, or encryption
Working knowledge of security control frameworks such as NIST 800-53 or NIST 800-171
Experience managing third-party audits and assessor relationships
Strong written communication skills, with the ability to translate regulatory language into clear technical and internal guidance
Experience in a startup or scaling company environment
Background in military, defense, or government contracting
Relevant certifications, such as CISSP, CISA, CRISC, or a technical security certification (AWS Solutions Architect)
Experience building GRC automation using infrastructure-as-code or scripting
This role will evolve as priorities change, but the outcomes below reflect what success typically looks like in the first six months.
A successful GRC Program Architect will:
Identify and remediate at least one significant security control gap before it surfaces in an external audit
Serve as the trusted point of contact for customer security questionnaires and compliance inquiries
Be recognized by engineering and security teams as a partner who makes compliance workable and technically sound, not just another gate to pass
Win buy-in from engineering leads who previously treated compliance requests as low priority
Get through a customer or third-party security review without escalations or fire drills
Experience with GRC platforms (such as RegScale, eMASS, or similar), cloud security tooling relevant to Federal environments, logging systems, CI/CD pipelines, and infrastructure-as-code for control automation is a plus.
Notice to Third Party Recruitment Agencies
Please note that Onebrief does not accept unsolicited resumes from recruiters or employment agencies. In the absence of an executed Recruitment Services Agreement, there will be no obligation to any referral compensation or recruiter fee. In the event a recruiter or agency submits a resume or candidate without an agreement Onebrief explicitly reserves the right to pursue and hire those candidate(s) without any financial obligation to the recruiter or agency. Any unsolicited resumes, including those submitted to hiring managers, shall be deemed the property of Onebrief.
Qualifications
Experience:
5 years experience