All roles
Apply for this role →
FedRAMP Compliance Analyst
Posted 09/24/2026
As a Junior FedRAMP Analyst, you will support the organization’s federal compliance and authorization efforts by helping maintain FedRAMP documentation, evidence, control mappings, and remediation tracking. You will work across NIST 800-53 controls, SSPs, POA&Ms, continuous monitoring activities, and audit requests while collaborating with internal teams, 3PAOs, and compliance stakeholders. This role is ideal for an early-career GRC professional looking to build hands-on experience with FedRAMP, StateRAMP, OSCAL, and public sector security compliance.
What you will do
- Support the organization’s FedRAMP readiness and authorization activities across traditional Rev 5 and emerging FedRAMP 20x approaches.
- Assist with defining the authorization boundary, preparing SSP content, and maintaining control narratives and supporting documentation.
- Support NIST 800-53 control implementation, POA&M tracking, and continuous monitoring activities.
- Help collect and organize automated, machine-readable compliance evidence where possible.
- Work with internal teams to gather evidence, track remediation items, and support authorization timelines.
- Assist with StateRAMP and TX-RAMP compliance activities alongside federal requirements.
- Support day-to-day compliance operations, audit requests, and customer security engagements.
What we are looking for
- 0–2 years of experience in GRC, information security, compliance, IT audit, or a related field.
- Foundational knowledge of FedRAMP and NIST-based security frameworks.
- Familiarity with SOC 2, ISO 27001, or similar compliance programs.
- Basic understanding of risk assessments, security controls, evidence collection, and remediation tracking.
- Strong organizational and written communication skills.
- Ability to work across technical, security, and business teams.
- No degree, certification, or security clearance required.
Nice to have
- Vanta, Drata, or Secureframe.
- OSCAL and machine-readable SSP tooling.
- HIPAA or PCI background.
- Prior agency sponsorship relationship.Optional certification or exposure
Skills and expertise
FedRAMP Rev 5
FedRAMP 20x and Key Security Indicators
NIST SP 800-53 Rev 5
NIST 800-171
FIPS 199/200
OSCAL
StateRAMP
TX-RAMP
SOC 2
ISO 27001
SSP
SAP
SAR
POA&M
ATO
Authorization Boundary
Continuous Monitoring (ConMon)
3PAO
Sponsoring Agency
PMO