Program Architect - Governance, Risk, and Compliance
OnebriefDefense Technology company
RemoteSenior
General Catalyst
Insight Partners
Caffeinated Capital
Human Capital
Battery Ventures
9Yards Capital
Legal & Compliance
About the role
TL;DR
Owns the architecture and implementation of Onebrief's GRC framework for defense and government customers.
- •Onebrief is seeking a GRC Program Architect to build and maintain the company's compliance posture for defense and government customers.
- •This role is critical for translating complex compliance requirements into actionable systems, processes, and evidence.
- •Key Responsibilities Own the design and implementation of Onebrief's GRC framework across RMF, FedRAMP, CMMC, SOC 2, and other applicable standards.
- •Build and manage the control environment, including policies, procedures, and evidence collection systems.
- •Design and implement technical security controls in partnership with Product, Engineering, Infrastructure and Corporate IT.
- •Translate compliance requirements into working technical controls, not just documented ones.
- •Requirements 5+ years of experience in GRC, security engineering, or a combined compliance and technical security role.
- •Direct experience with RMF, FedRAMP, CMMC, or equivalent federal compliance frameworks.
- •Hands-on experience implementing technical security controls, such as IAM, logging and monitoring, network segmentation, or encryption.
- •Working knowledge of security control frameworks such as NIST 800-53 or NIST 800-171.
- •Experience managing third-party audits and assessor relationships.
Required skills
SOC 2IAMCompliance ManagementRisk Management
Nice-to-have skills
CI/CD
Domain expertise
defensegovernment
Tech stack
SOC 2IAMCI/CD